22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

436 Lotus Security Handbook<br />

Table 11-2 Default ACL for the Web Administrator database<br />

Authenticating administrators<br />

You can use either an Internet password or an SSL client certificate to access<br />

the Web Administrator. The Web Administrator uses either name-and-password<br />

or SSL authentication to verify your identity. The method the Web Administrator<br />

uses depends on whether you set up the server or the Domino Web<br />

Administrator database (WEBADMIN.NSF), or both, to require<br />

name-and-password or SSL authentication.<br />

To access the Web Administrator database, you must have name-and-password<br />

authentication or SSL client authentication set up on the server.<br />

Name-and-password authentication is enabled for the HTTP protocol by default.<br />

11.1.4 Programmability restrictions<br />

New for<br />

Domino 6<br />

Default name Access<br />

User and group names listed in either of these<br />

fields on the Server document:<br />

Full Access Administrators<br />

Administrators<br />

Name of server Manager<br />

- Default - No access<br />

Anonymous No access<br />

OtherDomainServers No access<br />

Manager with all roles<br />

To control the types of agents users can run on a server, you can set up<br />

restrictions for server agents in the Server document. As with administrator<br />

access, the list of server agents in the Server document is organized<br />

hierarchically with regard to privileges. “Run unrestricted methods and<br />

operations” has the highest level of privilege and “Run Simple and Formula<br />

agents” has the lowest. A user or group name in one list will automatically<br />

receive the rights of the lists beneath. Therefore a name has to be entered in<br />

only one list, which then gives that user the highest rights.<br />

Tip: Create a group for each class of users to be used in every category.<br />

Run unrestricted methods and operations<br />

Users and groups in this category are allowed to select, on a per agent basis,<br />

one of three levels of access for agents signed with their ID. Users with this

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!