Previous Contents Index DocHome Next |
iPlanet Directory Server Access Management Edition Administration Guide |
Chapter 4 User Management
This chapter describes the user management features of iPlanet Directory Server Access Management Edition (DSAME). The User Management interface provides a way to view, manage and configure all DSAME objects and identities. This chapter contains the following sections:
The User Management Interface
The User Management Interface
There are two types of user management views. Depending on the roles of the user logging in, they might gain access to the User Management View or the User Profile View.
User Management View
When a user with an administrative role authenticates to the DSAME, their default view is the User Management View. In this view the administrator can perform all user-based administrative tasks. This can include, but is not limited to, creating objects and identities, configuring services and assigning policies.
Figure 4-1    User Management View with Organization Properties Displayed
User Profile View
When a user without an administrative role authenticates to the DSAME, the default view is their own User Profile. In this view the user can modify the values of the attributes particular to their personal profile. This can include, but is not limited to, name, home address and password. The attributes displayed in the User Profile View can be extended. For more information on adding customized attributes for objects and identities, see the iPlanet Directory Server Access Management Edition Programmer's Guide.
Figure 4-2    User Profile View
Managing DSAME Objects
The User Management interface contains all the components needed to view and manage the DSAME objects (organization, configured enterprise organizations and their corresponding groups, roles, users, policies and containers). This section explains the object types and details on how to configure them.
Organizations
This object represents the top level of a hierarchical structure used by an enterprise to manage its departments and resources. Upon installation, DSAME dynamically creates a top-level organization (default o=isp) to manage the DSAME enterprise configurations. Additional organizations can be created after installation to manage separate enterprises. All created organizations fall beneath the top-level organization.
Choose Organizations from the Show menu in User Management.
Delete an OrganizationClick Create in the navigation pane.
Enter a value for the name of the Organization in the Create Organization template.
Choose a status of active or inactive.
Click Submit.
- The default is active. This can be changed at any time during the life of the organization by selecting the Properties icon. Choosing inactive disables log in to the organization.
Choose Organizations from the Show menu in User Management.
Select the checkbox next to the name of the Organization to be deleted.
Note There is no warning message when performing a delete. All entries within the organization will be deleted.
Containers
The container entry is used when, due to object class and attribute differences, it is not possible to use an organization entry. It is important to remember that the DSAME container entry and the DSAME organization entry are not necessarily equivalent to the LDAP object classes organizationalUnit and organization. They are abstract DSAME entries. Ideally, the organization entry will be used instead of the container entry.
Navigate to the navigation pane of the Organization or Container where the new Container will be created.
Click Create.
Enter the name of the Container to be created.
Navigate to the navigation pane of the Organization or Container which contains the Container to be deleted.
Choose Containers from the Show menu.
Select the checkbox next to the name of the Container to be deleted.
Note Deleting a container will delete all objects that exist in that Container. This includes all objects and sub Containers.
People Containers
A People Container is the default LDAP organizational unit to which all users are assigned when they are created within an organization. People Containers can be found at the organization level and at the People Container level as a sub People Container. They can only contain other People Containers and users. Additional People Containers can be added into the organization, if desired.
Note The display of People Containers is optional. To view People Containers you must select Show People Containers in the DSAME Administration service. For more information, see "Show People Containers".
Navigate to the navigation pane of the Organization or People Container where the new People Container will be created.
Click Create.
Enter the name of the People Container to be created.
Navigate to the navigation pane of the organization or People Container which contains the People Container to be deleted.
Choose People Containers from the Show menu.
Select the checkbox next to the name of the People Container to be deleted.
Note Deleting a People Container will delete all objects that exist in that People Container. This includes all users and sub People Containers.
Group Containers
A Group Container is used to manage groups. It can only contain groups and other group containers. The group container Groups is dynamically assigned as the parent entry for all managed groups. Additional group containers can be added, if desired.
Navigate to the navigation pane of the Organization or the Group Container which contains the Group Container to be created.
Choose Group Containers from the Show menu.
Click Create.
Type a value in the Name field and press Submit.
Navigate to the navigation pane of the Organization which contains the Group Container to be deleted.
Choose Group Containers from the Show menu.
Select the checkbox next to the Group Container to be deleted.
Roles
This grouping represents a selection of privileged operations. By applying the role to a user or a service, the principal can perform the operations. For example, by confining certain privileges to an Employee role or a Manager role and applying the role to a user, the user's accessibility is confined to the privileges granted it by the role.
Navigate to the navigation pane of the Organization where the role will be created.
Choose Roles from the Show menu.
- Choose Organizations from the Show menu in User Management and select the organization from the navigation pane. The Location path displays the default top-level organization and chosen organization.
Click Create in the navigation pane.
- The three default roles created when an organization is configured display in the navigation pane: iPlanetAMOrgAdminRole, iPlanetAMOrgHelpDeskAdminRole and People Admin. For descriptions of these roles, see "Dynamic Admin Roles ACIs" of the Attribute Reference Guide.
Enter a name for the role.
Enter a description of the role.
Choose the type of role from the Type menu.
Choose a default set of ACIs to apply to the role from the Access Permission menu.
Click Submit.
- The default ACIs are permissions to access entries within the organization. They are discussed in the section "Default Role Permissions (ACIs)". No permissions can also be chosen. (The default ACIs shown are in no particular order.)
Navigate to the organization that contains the role for deletion.
Choose Roles from the Show menu.
- Choose Organizations from the Show menu in User Management and select the organization from the navigation pane. The Location path displays the default top-level organization and chosen organization.
Navigate to the Organization that contains the role to modify.
Choose Roles from the Show menu.
- Choose Organizations from the Show menu in User Management and select the organization from the navigation pane. The Location path displays the default top-level organization and chosen organization.
Choose Users from the Show menu.
Enter a user id.
Choose the users from the names returned by selecting the checkbox next to the user name.
- Search criteria can also be entered (including first name, last name or active/inactive) if specific user id information is not available.
Navigate to the Organization that contains the role to modify.
Choose Roles from the Show menu.
- Choose Organizations from the Show menu in User Management and select the organization from the navigation pane. The Location path displays the default top-level organization and chosen organization.
Choose Users from the Show menu.
Services
Activating a service for an organization is a two step process. In the first step you need to register the service with the organization. After a service is registered, a template configured specifically for that organization must be created. For additional information, see Chapter 2 "Service Management."
Navigate to the Organization where you will add services.
Choose Services from the Show menu.
- Choose Organizations from the Show menu in User Management and select the organization from the navigation pane. The Location path displays the default top-level organization and chosen organization.
Select the checkbox next to the services to be added.
Create a Template for a Service
Navigate to the organization or role where the registered service exists.
Choose Services from the Show menu
- Choose Organizations from the Show menu in User Management and select the organization from the navigation pane. The Location path displays the default top-level organization and chosen organization.
Click the properties icon next to the name of the service to be activated.
Click Create.
Accept or modify the default values and click Submit.
Navigate to the organization where you will remove services.
Choose Services from the Show menu.
- Choose Organizations from the Show menu in User Management and select the organization from the navigation pane. The Location path displays the default top-level organization and chosen organization.
Policies
Policies define rules to help protect an organization's web resources. They can be assigned to organizations and roles only. Policies cannot be created, deleted or viewed in User Management; they can only be assigned. See Chapter 3 "Policy Management for information on how to configure policies.
Navigate to the Organization or Role where the policy will be added.
Choose Policies in the Show menu.
Select the checkbox for the policy to assign.
Navigate to the organization or role where the policy exists.
Choose Policies in the Show menu.
Select the checkbox next to the policy to be deleted.
Users
Users represent the identity of a person. They are created within an organization's default People Container. If Show People Containers in the Administration service of the organization is disabled, users are visible at the organization level. If Show People Containers is enabled, users are visible within the organization's default People Container. (People Containers are discussed on page 45.)
Navigate to the Organization or People Container where the user should be created.
Choose Users from the Show menu.
Enter values for the required attributes and any optional fields.
Click Submit.
- Information on the user profile attributes can be found in "User Profile Attributes".
Navigate to the Organization or People Container where the user exists.
Choose Users from the Show menu.
Select the checkbox next to the name of the user to be deleted.
Managed Groups
This grouping represents a collection of users with a common function, feature or interest. Typically, this grouping has no privileges associated with it. They can exist at two levels, within an organization and within other managed groups as a sub group. Users can be added to Managed Groups either statically or dynamically (filtered).
Membership By Subscription. A group created by subscription creates a group based on the option chosen in Managed Group Type. If the Managed Group Type value is static, group members are added to a group entry using the groupOfNames or groupOfUniqueNames object class. If the Managed Group Type value is dynamic, a LDAP filter is used to search and return only user entries that contain the memberof attribute.
Membership By Filter. A filtered group is one that is created through the use of a LDAP filter. All entries are funneled through the filter and dynamically assigned to the group. The filter would look for any attribute in an entry and return those that contain the attribute.
Navigate to the Organization or Managed Group where the group will be created.
Choose Managed Groups from the Show menu.
- Use the Show menu in the navigation pane and the Location path in the location pane. Managed groups are listed underneath Group Containers.
Select the group type from within the data pane.
If a static subscription group is to be created, select Membership By Subscription and click Submit.
Enter a name for the group in the Name field.
If a dynamic (LDAP filtered) group is to be created, select Membership By Filter and click Submit.Add users to the group by selecting Add...
Enter a user id to search for a user entry or configure a LDAP filter.
Choose the users from the names returned by selecting the checkbox next to the user name and pressing Submit.
Select Users Can Subscribe to this Group to allow users to subscribe to the group themselves.
Enter a name for the group in the Name field.
Construct the LDAP search filter.
Click Submit.
- The fields used to construct the filter use either an OR or AND operator. All the fields listed in the UI are used. If a field is left blank it will match all possible entries for that particular attribute.
Navigate to the Organization or Managed Group where the group exists.
Choose Managed Groups from the Show menu.
- Use the Show menu in the navigation pane and the Location path in the location pane. Managed groups are listed underneath Group Containers.
Select the checkbox next to the name of the group to be deleted.
Properties Function
To view or modify an entry's properties, click the arrow next to the object's name. It's attributes and corresponding values are displayed in the data pane. Different objects display different properties.
Organizations properties allow status modification between active and inactive.
See the iPlanet Directory Server Access Management Edition Programmer's Guide for information on how to extend an entry's properties.Role properties include role and permission descriptions and the services registered to the role. ACI details can be viewed by selecting Show Access Permissions.
User properties include, but are not limited to, basic user information such as first name, last name, home address, telephone number and password.
The Groups configurable attribute, aside from the naming attribute, is allowing or disallowing the user to self-subscribe themselves to the group.
Containers do not have any configurable attributes excepting the naming attribute.
Policy properties are a listing of the URLs being affected by the policy.
Service properties include any of the attribute listed in Part 2, "Attribute Reference Guide" depending on the service.
Previous Contents Index DocHome Next
Copyright © 2001 Sun Microsystems, Inc. Some preexisting portions Copyright © 2001 Netscape Communications Corp. All rights reserved.
Last Updated December 12, 2001