Administrative Roles

This feature enables you to configure administrative roles.

While configuring an administrative group member, the primary administrator has to explicitly assign an administrative role to the member. The roles that can be assigned to an administrative member are as follows:

  • Audit administrator (AuditAdmin) – Members of the administrative group, who are assigned the Audit Administrator role have unrestricted access to the following logs and settings:
    • Audit log
    • Admin Audit log
    • All other server logs
    • Audit log settings (cn=Audit, cn=Log Management, cn=Configuration)
    • Admin Audit log settings (cn=Admin Audit, cn=Log Management, cn=Configuration)
    • Default log management settings (cn=Default, cn=Log Management, cn=Configuration)
  • Directory Data Administrator (DirDataAdmin) – Members of the administrative group who are assigned this role gain unrestricted access to all the entries in the RDBM back-end. However, for setting the password attribute of RDBM entries, members have to follow the usual password policy rules.
  • No administrator (NoAdmin) – If the primary administrator assigns No Administrator role to the configuration file users, then the users will not have any administrative privileges. By defining this role the primary administrator can revoke all the administrative privileges of an administrative group member.
  • Password administrator (PasswordAdmin) – Members of the administrative group, who are assigned the Password Administrator role are authorized to unlock other user’s accounts or change passwords of users in RDBM back-end. However, they are not authorized to change passwords of Global Administrative Group Member accounts. Also, they are not restrained by password policy constraints that are set on the server. They can also add and delete the user password field of entries in RDBM back-end but are not allowed to make changes to users defined in the configuration file. The password changes made by users who are assigned this role are not affected by ACLs. However, when users change their own password, the usual user password policy rules apply.
  • Replication administrator (ReplicationAdmin) – Members of the administrative group, who are assigned the Replication Administrator role are authorized to update replication topology objects. The changes made by members with this role are not affected by ACLs or any other configuration file settings.
  • Schema administrator (SchemaAdmin) – Members of the administrative group who are assigned the Schema Administrator role have unrestricted access to schema back-end only.
  • Server configuration group member (ServerConfigGroupMember) – Members of the administrator group who are assigned the Server Configuration Group Member role have restricted update access to the configuration back-end. This means that Server configuration group members have restricted update access to entries under cn=Configuration. Users with this role are unable to perform certain tasks, particularly those related to other local and primary administrators or tasks related to security. For instance, they are unable to change the primary administrator and the Admin Group credentials and add or remove members from the administrative group. Also, they are unable to modify the DN, password, Kerberos ID, or Digest-MD5 ID of any administrative group member entry under cn=AdminGroup, cn=Configuration. They are also not authorized to modify their own DN,Kerberos ID, or Digest-MD5 ID. They are not authorized to add, delete or modify the administrative roles assigned to any of the administrative group members. However, users are able to modify their own password. In addition, users with this role will be are unable to view the password of any other administrative group member or the primary administrator and they are not authorized to add, delete, or modify the audit log setting and admin audit log settings (the entire cn=Audit, cn=Log Management, cn=Configuration and cn=Admin Audit, cn=Log Management, cn=Configuration entries) or clear the audit log and admin audit log. However, they are allowed to modify default log settings (the cn=Default, cn=Log Management, cn=Configuration entry) and clear all other server logs. Also, users with this role are unable to add or delete the cn=Kerberos, cn=Configuration or cn=Digest, cn=Configuration entries. However, they are allowed to search all attributes under these entries. The users are able to modify all attributes under these entries except the Kerberos and Digest-MD5 root administrator bind attributes. They are unable to search or modify the ibm-slapdAdminDN,ibm-slapdAdminGroupEnabled, or ibm-slapdAdminPW attributes under the cn=Configuration entry. The user can issue dynamic configuration updates.
  • Server start/stop administrator (ServerStartStopAdmin) – Members of the administrative group who are assigned the Server Start/Stop Administrator role are authorized to start or stop the server and the administrator daemon.
Note: See Global administration group for information on how administrative rights are delegated for the database backend in a distributed directory environment.
The following table gives cross references of various extended operations that administrative group members are allowed to issue.
Table 1. Administrative roles authorized to issue various extended operations
Extended Operations Audit Admin Directory Data Admin Replication Admin Schema Admin Server Configuration Group Member Server Start/Stop Admin Password Admin No Admin
Start TLS - This operation is used to request to start Transport Layer Security. OID = 1.3.6.1.4.1.1466.20037 Yes Yes Yes Yes Yes Yes Yes Yes
Event Registration - This operation is used to request registration for events in SecureWay™ V3.2 Event support. OID = 1.3.18.0.2.12.1 Yes Yes Yes Yes Yes Yes Yes Yes
Event Unregister - This operation is used to request Unregister for events that were registered for using an Event Registration Request. OID = 1.3.18.0.2.12.3 Yes Yes Yes Yes Yes Yes Yes Yes
Begin Transaction - This operation is used to request to Begin a Transactional context for SecureWay V3.2. OID = 1.3.18.0.2.12.5 Yes Yes Yes Yes Yes Yes Yes Yes
End Transaction - This operation is used to request to End Transactional context (commit/rollback) for SecureWay V3.2. OID = 1.3.18.0.2.12.6 Yes Yes Yes Yes Yes Yes Yes Yes
Enable and Disable Tracing Dynamically. OID = 1.3.18.0.2.32.14 No No No No No No No No
Cascading Control Replication - This operation performs the requested action on the server it is issued to and cascades the call to all consumers beneath it in the replication topology. OID = 1.3.18.0.2.12.15 No Yes Yes No No No No No
Control Replication - This operation is used to force immediate replication, suspend replication, or resume replication by a supplier. This operation is allowed only when the client has update authority to the replication agreement. OID = 1.3.18.0.2.12.16 No Yes Yes No No No No No
Control Replication Queue - This operation marks items as "already replicated" for a specified agreement. This operation is allowed only when the client has update authority to the replication agreement. OID = 1.3.18.0.2.12.17 No Yes Yes No No No No No
Quiesce or Unquiesce Server - This operation puts the subtree into a state where it does not accept client updates (or terminates this state), except for updates from clients authenticated as directory administrators where the Server Administration control is present. OID = 1.3.18.0.2.12.19 No Yes Yes No No No No No
Clear Log Request – This operation is used to request to Clear log file. OID = 1.3.18.0.2.12.20 Yes No No No Yes No No No
Get Lines Request - This operation is used to request to get lines from a log file. OID = 1.3.18.0.2.12.22 Yes Yes Yes Yes Yes Yes Yes No
Number of Lines Request - This operation is used to request number of lines in a log file. OID = 1.3.18.0.2.12.24 Yes Yes Yes Yes Yes Yes Yes No
Start, Stop Server Request - This operation is used to request to start, stop or restart an LDAP server. OID = 1.3.18.0.2.12.26 No No No No No Yes No No
Update Configuration Request - This operation is used to request to update server configuration for IBM® Security Verify Directory. OID = 1.3.18.0.2.12.28 Yes No Yes No Yes No No No
DN Normalization Request - This operation is used to request to normalize a DN or a sequence of DNs. OID = 1.3.18.0.2.12.30 Yes Yes Yes Yes Yes Yes Yes Yes
Kill Connection Request - This operation is used to request to stop connections on the server. The request can be to kill all connections or kill connections by bound DN, IP, or a bound DN from a particular IP. OID = 1.3.18.0.2.12.35 No Yes No No No No No No
User Type Request - This operation is used to request to get the User Type of the bound user. OID = 1.3.18.0.2.12.37 Yes Yes Yes Yes Yes Yes Yes Yes
Control Server Tracing - This operation is used to request to Activate or deactivate tracing in IBM Security Verify Directory. OID = 1.3.18.0.2.12.40 No Yes No No No No No No
Group Evaluation – This operation is used in a distributed directory environment to determine all groups that a particular DN is a member of. OID = 1.3.18.0.2.12.50 No Yes No No No No No No
Topology Replication – This operation is used to replicate the objects that define the topology of a particular replication context, such as the replication agreements for that context. Any user with update rights to the Replication Group Entry of the context is allowed to issue this extended operation. OID = 1.3.18.0.2.12.54 No Yes Yes No No No No No
Event Update – This operation is used to request to reinitialize the event notification configuration (this operation can only be initiated by the server, not any user). OID = 1.3.18.0.2.12.31 No No No No No No No No
Log Access Update – This operation is used to request to reinitialize the log access plug-in configuration (this operation can only be initiated by the server, not any user). OID = 1.3.18.0.2.12.32 No No No No No No No No
Unique Attributes – This operation is used to request duplicate values for an attribute. OID = 1.3.18.0.2.12.44 No Yes No No No No No No
Account Status – This operation is used to determine if an account is locked by password policy. OID = 1.3.18.0.2.12.58 No Yes No No No No No No
Locate Entry – This operation is used locate details of a given set of DN(s). OID = 1.3.18.0.2.12.71 No Yes No No No No No No
Proxy Resume Role – This operation is used to request that a backend server's role is resumed. OID = 1.3.18.0.2.12.65 No Yes No No No No No No
Get Attributes Type – This operation is used to request the attributes types. OID = 1.3.18.0.2.12.46 No Yes No Yes No No No No
ServerBackupRestore- This operation is used to request that the admin server either perform a backup of a directory server’s data and configuration or restore a directory server’s data and configuration from an existing backup. OID = 1.3.18.0.2.12.81 No Yes No Yes Yes Yes No No
The following table gives cross references of various objects that different administrative group members are allowed to access.
Table 2. Permissions assigned to Administrative roles for accessing various objects

Audit Settings / Audit logs RDBM Backend Replication Objects Schema Backend Configuration Backend Proxy Backend Server Start/Stop
Read Write Read Write Read Write Read Write Read Write
Audit Administrator Yes Yes No** No No** No Yes No Yes No Note1 No
Directory Data Administrator No No Yes Yes Yes Yes Yes No Yes No Note1 No
Replication Administrator No No No** No** Yes Yes Yes No Yes No Note1 No
Schema Administrator No No No** No No** No Yes Yes Yes No Note1 No
Server Configuration Group Member Yes No No** No No** No Yes No Yes Yes* Note1 No
Server Start/Stop Administrator No No No** No No** No Yes No Yes No Note1 Yes
Password Administrator No No No** Yes** No** No Yes No Yes No Note1 No
No Administrator No No No** No No** No Yes No Yes No Note1 No
  • * - Server Configuration Group Member have restricted update access to configuration backend.
  • ** - For access to these objects the administrative roles give no special authority, but the user may still have access through normal ACL evaluation.
  • Note1 - Proxy treats the admin group members having any administrative role as anonymous and accordingly apply access rules.