22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

502 Lotus Security Handbook<br />

of whether the name of the server being added is in a different hierarchical<br />

organization than that of the server that stores the database.<br />

Group names<br />

You add a group name – for example, Training – to the ACL to represent multiple<br />

users or servers that require the same access. Users must be listed in groups<br />

with a primary hierarchical name or an alternate name. Groups can also have<br />

wildcard entries as members. Before you can use a group name in an ACL, you<br />

must create the group in the Domino Directory or in either a secondary Domino<br />

Directory or an external LDAP Directory that has been configured for group<br />

authorization in the Directory Assistance database.<br />

Groups provide a convenient way to administer a database ACL. Using a group<br />

in the ACL offers the following advantages:<br />

► Instead of adding a long list of individual names to an ACL, you can add one<br />

group name. If a group is listed in more than one ACL, modify the group<br />

document in the Domino Directory or the LDAP Directory, rather than add and<br />

delete individual names in multiple databases.<br />

► If you need to change the access level for several users or servers, you can<br />

do so once for the entire group.<br />

► Use group names to reflect the responsibilities of group members or the<br />

organization of a department or company.<br />

Tip: You can also use groups to let certain users control access to the<br />

database without giving them Manager or Designer access. For example, you<br />

can create groups in the Domino Directory for each level of database access<br />

needed, add the groups to the ACL, and allow specific users to own the<br />

groups. These users can then modify the groups, but they can't modify the<br />

database design.<br />

Terminations group<br />

When employees leave an organization, you should remove their names from all<br />

groups in the Domino Directory and add them to a Deny List Only group used to<br />

deny access to servers. The Deny Access list in the Server document contains<br />

the names of Notes users and groups who no longer have access to Domino<br />

servers. You should also make sure that the names of terminated employees are<br />

removed from the ACLs of all databases in your organization. When you delete a<br />

person from the Domino Directory, you have the option to “Add deleted user to<br />

deny access group,” if such a group has been created. (If no such group exists,<br />

the dialog box displays “No Deny Access group selected or available.”)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!