Sun Java System Directory Server Enterprise Edition 6.3 Deployment Planning Guide

Using Roles Securely

Not every role is suitable for use within a security context. When creating a role, consider how easily it can be assigned to and removed from an entry. Sometimes, users should be able to add themselves to or remove themselves from a role. However, in some security contexts such open roles are inappropriate. For more information, see Directory Server Roles in Sun Java System Directory Server Enterprise Edition 6.3 Reference.