How Authorization Works; Default Groups - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

About Authorization
authorization check before allowing an operation to be performed in that area.
Access Control Instructions (ACI s) in each of the ACLs are created that specifically
allow or deny one or more possible operations for that ACL to specified users,
groups, or IP addresses.
The ACLs contain a default set of ACIs for the default groups that are created. You
can change those ACIs to change the privileges of those predefined groups, or
create groups of your own assigning the new group privileges by adding or
modifying ACI's for the new group in the ACLs.

How Authorization Works

The following is the process that defines authorization:
Users authenticates to the interface they are trying to access either using their
1.
CMS user ID and password or with a certificate.
The server authenticates them either by matching their user ID and password
2.
with the one stored in the database, or by checking their certificate against one
stored in the database. With certificate-based authentication, the server also
checks that the certificate is valid, and finds the group membership of the user
by associating the DN of the certificate with a user and determining the user's
group membership. With password based authentication, the server checks the
password against the user ID, and then finds the group membership of the user
by associating that user ID with the user ID contained in the group.
When the user tries to perform an operation, the authorization mechanism
3.
checks that the user ID of the user, the group in which the user belongs, or the
IP address of the user is allowed to perform that operation by checking the
ACLs for this process to determine if an ACI exists that allows this operation to
be performed by this user, group, or IP address.

Default Groups

A user's privileges are determined by the group membership of the user. When
you install the subsystem you are given the choice of whether to allow membership
of users in more than one group. The default setting allows users to belong to more
than one group. If you changed this setting in the install wizard, users are not
allowed to belong to more than one group.
The following groups are created by default:
326
Netscape Certificate Management System Administrator's Guide • February 2003

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents