22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

privilege select one of these access levels when they are using Domino<br />

Designer 6 to build an agent:<br />

► Restricted mode<br />

► Unrestricted mode<br />

► Unrestricted mode with full administration rights<br />

Only users who have this access can choose an option other than “Do not allow<br />

restricted operations.” This access is enabled by default for the current server<br />

and Lotus Notes template developers.<br />

If users in this list are also listed as a database administrators in the Server<br />

document, they are allowed to perform database operations without having to be<br />

listed explicitly in the database ACL (for example, they can delete databases<br />

without being listed in the ACL of those databases).<br />

Note: To have the ability to run agents in unrestricted mode with full administration<br />

rights, the agent signer should be listed in this field, or in the Full Access Administrator<br />

field, as well as have this mode selected in the Agent Builder. Being listed in the Full<br />

Access Administrator list alone is not sufficient to run agents in this mode.<br />

Sign agents to run on behalf of someone else<br />

Enter the names of users and groups who are allowed to sign agents that will be<br />

executed on anyone else's behalf. The default is blank, which means that no one<br />

can sign agents in this manner.<br />

Note: This privilege should be used with caution, as the name the agent is signed on<br />

behalf of is used to check ACL access.<br />

Sign agents to run on behalf of the invoker of the agent<br />

Enter the names of users and groups who are allowed to sign agents that will be<br />

executed on behalf of the invoker, when the invoker is different from the agent<br />

signer. This setting is ignored if the agent signer and the invoker are the same.<br />

This is used currently only for Web agents. The default is blank, which means<br />

that everyone can sign agents invoked in this manner (this is for backwards<br />

compatibility).<br />

Run restricted LotusScript/Java agents<br />

Enter the names of users and groups allowed to run agents created with<br />

LotusScript and Java features, but excluding privileged methods and operations,<br />

such as reading and writing to the file system. Leave the field blank to deny<br />

access to all users and groups.<br />

Chapter 11. Domino/Notes 6 security features 437

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!