Using Access Control Files; Configuring The Acl User Cache - Netscape ENTREPRISE SERVER 6.1 - 08-2002 ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

What Is Access Control?
Host-IP authentication does not require DNS to be configured on your server. If
you choose to use Host-IP authentication, you must have DNS running in your
network and your server must be configured to use it. You can enable DNS on your
server through the Performance Tuning page in the Preferences tab on your Server
Manager.
Enabling DNS degrades the performance of Enterprise Server since the server is
forced to do DNS look-ups. To reduce the effects of DNS look-ups on your server's
performance, resolve IP addresses only for access control and CGI instead of
resolving the IP address for every request. To do this,
obj.conf
AddLog fn="flex-log" name="access" iponly=1

Using Access Control Files

When you use access control on the Administration Server or the files or directories
on your web site, the settings are stored in a file with the extension
control files are stored in the directory server_root
The main ACL file name is
working file is called
Administration Server to configure access, you'll have these two files. However, if
you want more complex restrictions, you can create multiple files, and reference
them from the
editing the files such as restricting access to the server based on the time of day or
day of the week.
You can manually create and edit
For more information on using access control APIs, see the Netscape Enterprise
Server Programmer's Guide.
For more information on access control files and their syntax, see Appendix C,
"ACL File Syntax".

Configuring the ACL User Cache

Enterprise Server caches user and group authentication results in the ACL user
cache. You can control the amount of time that ACL user cache is valid by using the
ACLCacheLifetime
cache is referenced, its age is calculated and checked against
The entry is not used if its age is greater than or equal to the
The default value is 120 seconds. Setting the value to 0 (zero) turns the cache off. If
170
Netscape Enterprise Server Administrator's Guide • August 2002
file:
generated-https-
genwork-https-
file. There are also a few features available only by
server.xml
directive in the
iponly=1
/httpacl.
server-id
server-id.
. If you use Netscape
acl
files to customize access control using APIs.
.acl
file. Each time an entry in the
magnus.conf
to
in your
AddLog
. Access
.acl
; the temporary
.acl
ACLCacheLifetime
ACLCacheLifetime
.
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Entreprise server 6.1

Table of Contents