25.06.2013 Views

Lotus Domino Administrator 7 Help - Lotus documentation

Lotus Domino Administrator 7 Help - Lotus documentation

Lotus Domino Administrator 7 Help - Lotus documentation

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Server names<br />

You can add server names to an ACL to control the changes a database receives from a database replica.<br />

To ensure tighter security, use the full hierarchical name of the server -- for example, Server1/Sales/Acme<br />

-- regardless of whether the name of the server being added is in a different hierarchical organization<br />

than that of the server that stores the database.<br />

Group names<br />

You add a group name -- for example, Training -- to the ACL to represent multiple users or servers that<br />

require the same access. Users must be listed in groups with a primary hierarchical name or an alternate<br />

name. Groups can also have wildcard entries as members. Before you can use a group name in an ACL,<br />

you must create the group in the <strong>Domino</strong> Directory or in either a secondary <strong>Domino</strong> Directory or an<br />

external LDAP Directory that has been configured for group authorization in the Directory Assistance<br />

database.<br />

Note: Be sure that any group names you use in an ACL comply with the specified guidelines for creating<br />

them. The use of erroneous names may cause access problems.<br />

Tip: Use individual names rather than group names for the managers of a database. Then when users<br />

choose Create - Other - Memo to Database Manager, they’ll know whom they are addressing.<br />

Groups provide a convenient way to administer a database ACL. Using a group in the ACL offers the<br />

following advantages:<br />

v Instead of adding a long list of individual names to an ACL, you can add one group name. If a group<br />

is listed in more than one ACL, modify the group document in the <strong>Domino</strong> Directory or the LDAP<br />

Directory, rather than add and delete individual names in multiple databases.<br />

v If you need to change the access level for several users or servers, you can do so once for the entire<br />

group.<br />

v Use group names to reflect the responsibilities of group members or the organization of a department<br />

or company.<br />

Tip: You can also use groups to let certain users control access to the database without giving them<br />

Manager or Designer access. For example, you can create groups in the <strong>Domino</strong> Directory for each level<br />

of database access needed, add the groups to the ACL, and allow specific users to own the groups. These<br />

users can then modify the groups, but they can’t modify the database design.<br />

Terminations group<br />

When employees leave your organization, you should remove their names from all groups in the <strong>Domino</strong><br />

Directory and add them to a Deny List Only group used to deny access to servers. The Deny Access list<br />

in the Server document contains the names of Notes users and groups who no longer have access to<br />

<strong>Domino</strong> servers. You should also make sure that the names of terminated employees are removed from<br />

the ACLs of all databases in your organization. When you delete a person from the <strong>Domino</strong> Directory,<br />

you have the option to ″Add deleted user to deny access group,″ if such a group has been created. (If no<br />

such group exists, the dialog box displays ″No Deny Access group selected or available.″)<br />

For more information on Deny List Only groups, see the chapter ″Setting Up and Managing Groups.″<br />

For more information on the Deny Access list, see the chapter ″Controlling Access to <strong>Domino</strong> Servers.″For<br />

more information on the Deny Access list, see the chapter ″Controlling Access to <strong>Domino</strong> Servers.″<br />

Alternate names<br />

An alternate name is an optional alias name that an administrator assigns to a registered Notes user. You<br />

can add alternate names to an ACL. An alternate name provides the same level of security as the user’s<br />

primary hierarchical name. For a user whose primary name is Sandra Brown/West/Sales/Acme, an<br />

example of an alternate name format would be Sandy Smith/ANWest/ANSales/ANAcme, where AN is<br />

an alternate name.<br />

1028 <strong>Lotus</strong> <strong>Domino</strong> <strong>Administrator</strong> 7 <strong>Help</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!