Adding or editing non-flitered ACLs
You can add non-filtered ACLs to an entry or edit existing non-filtered ACLs. Non-filtered ACLs can be propagated. The access control information that is defined for one entry can be applied to all of its subordinate entries.
Procedure
- Select the Non-filtered ACLs tab.
Note: If no non-filtered ACLs exist for the entry, the Propagate ACLs check box is preselected and cannot be modified.
- Select the Propagate check box to allow descendants without an explicitly defined ACL to inherit from this entry. If the check box is selected, the descendant inherits ACLs from this entry and if the ACL is explicitly defined for the child entry. Then, the ACL, which was inherited from parent is replaced with the new ACL that was added. If the check box is not selected, descendant entries without an explicitly defined ACL inherit ACLs from a parent of this entry that has this enabled option.
- Click Add to create new access rights
for the entry or select an existing Subject DN and click Edit to
modify existing ACLs.
- Specify Subject DN. Type the
DN of the entity that request access to run operations on the selected
entry.For example,
cn=Ricardo Garcia,ou=austin,o=sample. If you are editing the ACL, you cannot modify this field. - Specify the Subject type. Select
the type of ACL. For example, select access-id if the DN is a user. If you are editing the ACL, you cannot modify this field.
- From the Add child menu, select whether to grant or deny the subject the right to add a directory entry beneath the selected entry. In this example, if you select grant, Ricardo Garcia is able to add child entries under ou=Widget Division.
- From the Delete entry menu, select
whether to grant or deny the subject the right to delete the selected
entry. In this example, it grants or denies
cn=Ricardo Garciathe ability to deleteou=Widget Divisionand any of its child entries. - Set the permissions for the Security class
access rights for each of the security classes. You can
grant the permissions individually or click Grant all or Deny
all to grant or deny permissions globally. Ricardo Garcia
is given the permissions that you set here to all of the attributes
of each security class. See Viewing access rights for
more information.Note: If you select Grant all, it gives Ricardo Garcia access to the restricted attributes that include the ACLs themselves. Ricardo Garcia can grant himself extra permissions on the entry.For example, if the administrator denied Delete entry permission to Ricardo Garcia on the entry
ou=Widget Division,ou=austin,o=sample, Ricardo Garcia cannot delete the entry or any of its child entries. If the administrator also clicked Grant all for the security class permissions, Ricardo Garcia is able to change the ACL. Ricardo Garcia can give himself permission to delete the child entries ofou=Widget Division,ou=austin,o=sampleand the parent entry itself. If you do select Grant all when you create ACLs, you might want to explicitly deny write permission to the restricted class for security purposes. - Additionally, you can specify permissions that are based
on the attribute instead of the security class to which the attribute
belongs.
- Select an attribute from the Define an attribute drop-down list.
- Click Define. The attribute is displayed with a permissions table.
- Specify whether to grant or deny each of the four security class permissions that are associated with the attribute or click Grant all or Deny all to grant or deny permissions globally.
- You can repeat this procedure for multiple attributes.
- To remove an attribute, select the attribute and click Delete.
- Click OK to return to the Edit ACL panel.
- Click OK to save your changes and exit.
- Specify Subject DN. Type the
DN of the entity that request access to run operations on the selected
entry.