Understanding Novell eDirectory
67
no
vd
ocx
(e
n)
6 Ap
ril 20
07
Controlling Access to Novell eDirectory by Trustee
1
In Novell iManager, click the
Roles and Tasks
button
.
2
Click
Rights
>
Rights to Other Objects
.
3
Enter the name and context of the trustee (the object that possesses, or will possess, the rights)
whose rights you want to modify.
4
In the
Context to Search From
field, specify the part of the eDirectory tree to be searched for
eDirectory objects that the trustee currently has rights assignments to.
5
Click
OK
.
A screen appears showing the progress of the search. When the search is done, the Rights to
Other Objects page appears with the results of the search filled in.
6
Edit the trustee's eDirectory rights assignments as needed.
6a
To add a rights assignment, click
Add Object
, select the object to control access to, click
OK
, click
Assigned Rights
, assign the trustee's rights, then click
Done
.
6b
To modify a rights assignment, select the object you want to control access to, click
Assigned Rights
, modify the trustee's rights assignment as needed, then click
Done
.
When creating or modifying a rights assignment, you can grant or deny access to the
object as a whole, to all the properties of the object, and to individual properties.
6c
To remove a rights assignment, select the object you want to control access to, then click
Delete Object
.
The trustee no longer has explicit rights to the object or its properties but might still have
effective rights through inheritance or security equivalence.
7
Click
OK
.
Granting Equivalence
A user who is security equivalent to another eDirectory object effectively has all the rights of that
object. A user is automatically security equivalent to the groups and roles that they belong to. All
users are implicitly security equivalent to the [Public] trustee and to each container above their User
objects in the eDirectory tree, including the Tree object. You can also explicitly grant a user security
equivalence to any eDirectory object.
NOTE:
The tasks in this section allow you to delegate administrative authority through eDirectory
rights. If you have administration applications that use Role-Based Services (RBS) roles, you can
also delegate administrative authority by assigning users membership in those roles.
“Granting Security Equivalence by Membership” on page 67
“Granting Security Equivalence Explicitly” on page 68
“Setting Up an Administrator For an Object's Specific eDirectory Properties” on page 68
Granting Security Equivalence by Membership
1
If you haven't already done so, create the group or role object that you want the users to be
security equivalent to.
See
“Creating an Object” on page 94
for details.
2
Grant the group or role the eDirectory rights that you want the users to have.
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...