How Acis Are Formed - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Authorization for CMS Users

How ACIs are Formed

You change the access for a user, group, or IP address by editing the ACI entries in
the ACLs. You can change who is allowed or denied access by adding a user,
group, or IP address to the ACIs in an ACL entry. In the ACL interface, each ACI is
shown on a line of its own. In this interface window, the ACI has the following
syntax:
allow|deny (operator) user|group|IP="name"
For example, the following is an ACI that allows Administrators to perform the
read operation for the tasks associated with this ACL:
allow (read) group="Administrators"
An ACI can have more than one operator. The operators are separated with a
comma with no space on either side. For example:
allow (read,modify) group="Administrators"
An ACI can have more than one group, user, or IP address by separating them with
two pipe symbols (||) with a space on either side. For example:
allow (read) group="Administrators" || group="Auditors"
In the CMS console interface, you create or modify ACIs in an editor that allows
you to do this in a graphical environment. You choose from allow or deny in the
Allow and Deny field, then you choose one of the operations that are possible for
this ACL in the Operations field, and then you list those groups, users, or IP
addresses that are being granted or denied this access in the Syntax field.
Allow and Deny
An ACI can either allow an operation for the specified group, user ID, or IP
address, or deny the operation for the specified group, user ID, or IP address.
Generally, you do not have to create ACIs to deny access. If a group, user ID, or IP
address is not allowed access to an operation—that is, there are no allow ACIs that
when evaluated, would include the user ID, group, or IP address—the group, user
ID, or IP address is denied access.
If a user is not allowed access to any of the operations for a resource, then this user
is considered denied; they do not specifically need to be denied access. For
example, user
the following ACI,
of the allow ACIs:
Allow (read,modify) group="Auditors" || user="BrianC"
348
Netscape Certificate Management System Administrator's Guide • February 2003
is a member of the group Administrators. If an ACL has only
JohnB
would be denied any access since he does not match any
JohnB

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents