Policy Attribute Changes
The attributes of a Policy may be modified at anytime using the File System Factory™
web interface; after which any eDirectory events on objects that use that policy will result
in the new values being applied. No policy attribute change will be automatically
retroactive against files systems affected by the policy. Backfill operations may be used to
retroactively apply certain policy changes.
Policy Assignment Changes
Policy assignments to objects in the tree may be set and changed at any time. However,
the policy is only immediately applied against existing user objects if the policy is applied
directly to the user. Changes in policy assignments to groups and containers require a
backfill operation. The following table describes operation in these cases:
New Policy Assigned
Via
Previous Policy
Assigned Via
None
User
Group
Container
None
No action.
Apply
Immediate
Apply via
Backfill
Apply via
Backfill
User
No action.
Apply
Immediate
Apply via
Backfill
Apply via
Backfill
Group
No action.
Apply
Immediate
Apply via
Backfill
Apply via
Backfill
Container
No action.
Apply
Immediate
Apply via
Backfill
Apply via
Backfill
Policy changes against groups and containers require a backfill as a safety precaution.
Inadvertent changes in policy assignments at these levels have the capability of triggering
data movement for hundreds or even thousands of users which could be gigabytes or even
terabytes of data. Backfill operations constitute a direct request from the administrator to
take these actions.
See the chapter on Data Migration for more information about data movement after a
policy change.
Policy Re-Evaluation and Group Membership Changes
Because an individual user may inherit a policy from a group, changes in membership
may affect the policy that needs to be applied. If a user object is added or removed from a
group in the Directory, and that group has a policy associated with it, the user object is re-
evaluated by the File System Factory™ Engine. If it is determined that a new policy
applies to the user as a result, the new policy is applied immediately.
As with any immediate policy change, data movement may result. See the chapter on Data
Migration for more information about data movement.
Policy Re-Evaluation and Object Moves
If a user object is moved in the Directory, the object is re-evaluated by the File System
Factory™ Engine. If it is determined that a new policy applies to the user as a result of
the move, the new policy is applied immediately. A new policy will only apply if policies
are assigned to containers. In other words, if a policy was assigned directly to a user or to
a group the user was in, there would be no effective policy change as a result of a user
move since the group memberships and policy assignment attribute would move with the
user.
Novell File System Factory™ Administrator’s Guide
© 2002-2005 Condrey Consulting Corporation. All Rights Reserved.
41