60
Novell eDirectory 8.8 Administration Guide
no
vd
ocx
(e
n)
6 Ap
ril 20
07
1.10.1 Trustee Assignments and Targets
The assignment of rights involves a trustee and a target object. The trustee represents the user or set
of users that are receiving the authority. The target represents those network resources the users have
authority over.
If you make an Alias a trustee, the rights apply only to the object the alias represents. The Alias
object can be an explicit target, however.
A file or directory in the NetWare file system can also be a target, although file system rights
are stored in the file system itself, not in eDirectory.
NOTE:
The [Public] trustee is not an object. It is a specialized trustee that represents any network
user, logged in or not, for rights assignment purposes.
[This] is a special type of trustee, that is defined to be an authenticated object, when its name
matches the entry being accessed. This helps the administrator to easily specify rights such as, every
user manages his own telephone number, with a single ACL at the top of the tree with [This] as a
trustee.
1.10.2 eDirectory Rights Concepts
The following concepts can help you better understand eDirectory rights.
“Object (Entry) Rights” on page 60
“Property Rights” on page 61
“Effective Rights” on page 61
“How Effective Rights Are Calculated” on page 61
“Security Equivalence” on page 63
“Access Control List (ACL)” on page 64
“Inherited Rights Filter (IRF)” on page 64
Object (Entry) Rights
When you make a trustee assignment, you can grant object rights and property rights. Object rights
apply to manipulation of the entire object, while property rights apply only to certain object
properties. An object right is described as an entry right because it provides an entry into the
eDirectory database.
A description of each object right follows:
Supervisor
includes all rights to the object and all of its properties.
Browse
lets the trustee see the object in the tree. It does not include the right to see an object’s
properties.
Create
applies only when the target object is a container. It allows the trustee to create new
objects below the container and also includes the Browse right.
Delete
lets the trustee delete the target from the directory.
Rename
lets the trustee change the name of the target.
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...