03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

1. To add new user names or groups to the ACL, use the LDAP format for the<br />

name, but use forward slashes (/) as delimiters rather than commas (,). For<br />

example, if the name of a user in the LDAP directory is:<br />

cn=clerk01,o=ITSO<br />

then you should enter in the database ACL:<br />

cn=clerk01/o=ITSO<br />

2. To add the name of a non-hierarchical LDAP directory group into an ACL, do<br />

not include the name of an attribute as part of the entry, but only the value for<br />

the attribute. For example, if the name of the LDAP group is cn=managergrp,<br />

in the ACL enter only managergrp. However, if the name of the group is<br />

hierarchical, like cn=managergrp,o=ITSO, then you should enter<br />

cn=managergrp/o=ITSO.<br />

Note: When the LDAP attributes correspond to the attributes used in Notes<br />

(for example: cn,ou,o,c), the ACL will not display the attributes. For<br />

example, cn=manager01/o=ITSO appears in the ACL as manager/ITSO<br />

3. To add users and groups to the ACL database, make sure that you have<br />

manager access to the database and perform the following tasks:<br />

a. From the Notes Client, right-click the database icon on the workspace and<br />

select Database -> Access Control.<br />

This will open an access control dialog box.<br />

b. Set the following ACL for the ITSOBankComments Application database.<br />

The table shows only entries related to the application; here we do not<br />

specify all the entries as presented in Figure C-9. Similarly, we did not<br />

change default authorizations to test the scenario. That is why the<br />

Authorization column is left blank.<br />

Table C-1 Access control list specified for ITSOBankComments application<br />

People, servers,<br />

groups<br />

User type Access level Authorization<br />

Default Unspecified NoAccess None<br />

clerk01/ITSO Person Author<br />

accountant01/ITSO Person Author<br />

manager01/ITSO Person Author<br />

504 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!