Administrative Roles
This feature enables you to configure administrative roles.
While configuring an administrative group member, the primary administrator has to explicitly assign an administrative role to the member. The roles that can be assigned to an administrative member are as follows:
- Audit administrator (AuditAdmin) – Members of the administrative
group, who are assigned the Audit Administrator role have unrestricted
access to the following logs and settings:
- Audit log
- Admin Audit log
- All other server logs
- Audit log settings (cn=Audit, cn=Log Management, cn=Configuration)
- Admin Audit log settings (cn=Admin Audit, cn=Log Management, cn=Configuration)
- Default log management settings (cn=Default, cn=Log Management, cn=Configuration)
- Directory Data Administrator (DirDataAdmin) – Members of the administrative group who are assigned this role gain unrestricted access to all the entries in the RDBM back-end. However, for setting the password attribute of RDBM entries, members have to follow the usual password policy rules.
- No administrator (NoAdmin) – If the primary administrator assigns No Administrator role to the configuration file users, then the users will not have any administrative privileges. By defining this role the primary administrator can revoke all the administrative privileges of an administrative group member.
- Password administrator (PasswordAdmin) – Members of the administrative group, who are assigned the Password Administrator role are authorized to unlock other user’s accounts or change passwords of users in RDBM back-end. However, they are not authorized to change passwords of Global Administrative Group Member accounts. Also, they are not restrained by password policy constraints that are set on the server. They can also add and delete the user password field of entries in RDBM back-end but are not allowed to make changes to users defined in the configuration file. The password changes made by users who are assigned this role are not affected by ACLs. However, when users change their own password, the usual user password policy rules apply.
- Replication administrator (ReplicationAdmin) – Members of the administrative group, who are assigned the Replication Administrator role are authorized to update replication topology objects. The changes made by members with this role are not affected by ACLs or any other configuration file settings.
- Schema administrator (SchemaAdmin) – Members of the administrative group who are assigned the Schema Administrator role have unrestricted access to schema back-end only.
- Server configuration group member (ServerConfigGroupMember) – Members of the administrator group who are assigned the Server Configuration Group Member role have restricted update access to the configuration back-end. This means that Server configuration group members have restricted update access to entries under cn=Configuration. Users with this role are unable to perform certain tasks, particularly those related to other local and primary administrators or tasks related to security. For instance, they are unable to change the primary administrator and the Admin Group credentials and add or remove members from the administrative group. Also, they are unable to modify the DN, password, Kerberos ID, or Digest-MD5 ID of any administrative group member entry under cn=AdminGroup, cn=Configuration. They are also not authorized to modify their own DN,Kerberos ID, or Digest-MD5 ID. They are not authorized to add, delete or modify the administrative roles assigned to any of the administrative group members. However, users are able to modify their own password. In addition, users with this role will be are unable to view the password of any other administrative group member or the primary administrator and they are not authorized to add, delete, or modify the audit log setting and admin audit log settings (the entire cn=Audit, cn=Log Management, cn=Configuration and cn=Admin Audit, cn=Log Management, cn=Configuration entries) or clear the audit log and admin audit log. However, they are allowed to modify default log settings (the cn=Default, cn=Log Management, cn=Configuration entry) and clear all other server logs. Also, users with this role are unable to add or delete the cn=Kerberos, cn=Configuration or cn=Digest, cn=Configuration entries. However, they are allowed to search all attributes under these entries. The users are able to modify all attributes under these entries except the Kerberos and Digest-MD5 root administrator bind attributes. They are unable to search or modify the ibm-slapdAdminDN,ibm-slapdAdminGroupEnabled, or ibm-slapdAdminPW attributes under the cn=Configuration entry. The user can issue dynamic configuration updates.
- Server start/stop administrator (ServerStartStopAdmin) – Members of the administrative group who are assigned the Server Start/Stop Administrator role are authorized to start or stop the server and the administrator daemon.
Note: See Global administration group for
information on how administrative rights are delegated for the database
backend in a distributed directory environment.
The following table gives cross references of various extended
operations that administrative group members are allowed to issue.
The following table gives cross references of various objects
that different administrative group members are allowed to access.
| Extended Operations | Audit Admin | Directory Data Admin | Replication Admin | Schema Admin | Server Configuration Group Member | Server Start/Stop Admin | Password Admin | No Admin |
|---|---|---|---|---|---|---|---|---|
| Start TLS - This operation is used to request to start Transport Layer Security. OID = 1.3.6.1.4.1.1466.20037 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Event Registration - This operation is used to request registration for events in SecureWay™ V3.2 Event support. OID = 1.3.18.0.2.12.1 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Event Unregister - This operation is used to request Unregister for events that were registered for using an Event Registration Request. OID = 1.3.18.0.2.12.3 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Begin Transaction - This operation is used to request to Begin a Transactional context for SecureWay V3.2. OID = 1.3.18.0.2.12.5 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| End Transaction - This operation is used to request to End Transactional context (commit/rollback) for SecureWay V3.2. OID = 1.3.18.0.2.12.6 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Enable and Disable Tracing Dynamically. OID = 1.3.18.0.2.32.14 | No | No | No | No | No | No | No | No |
| Cascading Control Replication - This operation performs the requested action on the server it is issued to and cascades the call to all consumers beneath it in the replication topology. OID = 1.3.18.0.2.12.15 | No | Yes | Yes | No | No | No | No | No |
| Control Replication - This operation is used to force immediate replication, suspend replication, or resume replication by a supplier. This operation is allowed only when the client has update authority to the replication agreement. OID = 1.3.18.0.2.12.16 | No | Yes | Yes | No | No | No | No | No |
| Control Replication Queue - This operation marks items as "already replicated" for a specified agreement. This operation is allowed only when the client has update authority to the replication agreement. OID = 1.3.18.0.2.12.17 | No | Yes | Yes | No | No | No | No | No |
| Quiesce or Unquiesce Server - This operation puts the subtree into a state where it does not accept client updates (or terminates this state), except for updates from clients authenticated as directory administrators where the Server Administration control is present. OID = 1.3.18.0.2.12.19 | No | Yes | Yes | No | No | No | No | No |
| Clear Log Request – This operation is used to request to Clear log file. OID = 1.3.18.0.2.12.20 | Yes | No | No | No | Yes | No | No | No |
| Get Lines Request - This operation is used to request to get lines from a log file. OID = 1.3.18.0.2.12.22 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| Number of Lines Request - This operation is used to request number of lines in a log file. OID = 1.3.18.0.2.12.24 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| Start, Stop Server Request - This operation is used to request to start, stop or restart an LDAP server. OID = 1.3.18.0.2.12.26 | No | No | No | No | No | Yes | No | No |
| Update Configuration Request - This operation is used to request to update server configuration for IBM® Security Verify Directory. OID = 1.3.18.0.2.12.28 | Yes | No | Yes | No | Yes | No | No | No |
| DN Normalization Request - This operation is used to request to normalize a DN or a sequence of DNs. OID = 1.3.18.0.2.12.30 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Kill Connection Request - This operation is used to request to stop connections on the server. The request can be to kill all connections or kill connections by bound DN, IP, or a bound DN from a particular IP. OID = 1.3.18.0.2.12.35 | No | Yes | No | No | No | No | No | No |
| User Type Request - This operation is used to request to get the User Type of the bound user. OID = 1.3.18.0.2.12.37 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Control Server Tracing - This operation is used to request to Activate or deactivate tracing in IBM Security Verify Directory. OID = 1.3.18.0.2.12.40 | No | Yes | No | No | No | No | No | No |
| Group Evaluation – This operation is used in a distributed directory environment to determine all groups that a particular DN is a member of. OID = 1.3.18.0.2.12.50 | No | Yes | No | No | No | No | No | No |
| Topology Replication – This operation is used to replicate the objects that define the topology of a particular replication context, such as the replication agreements for that context. Any user with update rights to the Replication Group Entry of the context is allowed to issue this extended operation. OID = 1.3.18.0.2.12.54 | No | Yes | Yes | No | No | No | No | No |
| Event Update – This operation is used to request to reinitialize the event notification configuration (this operation can only be initiated by the server, not any user). OID = 1.3.18.0.2.12.31 | No | No | No | No | No | No | No | No |
| Log Access Update – This operation is used to request to reinitialize the log access plug-in configuration (this operation can only be initiated by the server, not any user). OID = 1.3.18.0.2.12.32 | No | No | No | No | No | No | No | No |
| Unique Attributes – This operation is used to request duplicate values for an attribute. OID = 1.3.18.0.2.12.44 | No | Yes | No | No | No | No | No | No |
| Account Status – This operation is used to determine if an account is locked by password policy. OID = 1.3.18.0.2.12.58 | No | Yes | No | No | No | No | No | No |
| Locate Entry – This operation is used locate details of a given set of DN(s). OID = 1.3.18.0.2.12.71 | No | Yes | No | No | No | No | No | No |
| Proxy Resume Role – This operation is used to request that a backend server's role is resumed. OID = 1.3.18.0.2.12.65 | No | Yes | No | No | No | No | No | No |
| Get Attributes Type – This operation is used to request the attributes types. OID = 1.3.18.0.2.12.46 | No | Yes | No | Yes | No | No | No | No |
| ServerBackupRestore- This operation is used to request that the admin server either perform a backup of a directory server’s data and configuration or restore a directory server’s data and configuration from an existing backup. OID = 1.3.18.0.2.12.81 | No | Yes | No | Yes | Yes | Yes | No | No |
| Audit Settings / Audit logs | RDBM Backend | Replication Objects | Schema Backend | Configuration Backend | Proxy Backend | Server Start/Stop | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Read | Write | Read | Write | Read | Write | Read | Write | Read | Write | |||
| Audit Administrator | Yes | Yes | No** | No | No** | No | Yes | No | Yes | No | Note1 | No |
| Directory Data Administrator | No | No | Yes | Yes | Yes | Yes | Yes | No | Yes | No | Note1 | No |
| Replication Administrator | No | No | No** | No** | Yes | Yes | Yes | No | Yes | No | Note1 | No |
| Schema Administrator | No | No | No** | No | No** | No | Yes | Yes | Yes | No | Note1 | No |
| Server Configuration Group Member | Yes | No | No** | No | No** | No | Yes | No | Yes | Yes* | Note1 | No |
| Server Start/Stop Administrator | No | No | No** | No | No** | No | Yes | No | Yes | No | Note1 | Yes |
| Password Administrator | No | No | No** | Yes** | No** | No | Yes | No | Yes | No | Note1 | No |
| No Administrator | No | No | No** | No | No** | No | Yes | No | Yes | No | Note1 | No |
- * - Server Configuration Group Member have restricted update access to configuration backend.
- ** - For access to these objects the administrative roles give no special authority, but the user may still have access through normal ACL evaluation.
- Note1 - Proxy treats the admin group members having any administrative role as anonymous and accordingly apply access rules.