The following entry in the kadm5.acl file gives any principal in the ACME.COM realm with the admin instance all the privileges on the database.
*/admin@ACME.COM * |
The following entry in the kadm5.acl file gives the jdb@ACME.COM principal the priviledge to add, list, and inquire about any principal that has the root instance.
jdb@ACME.COM ali */root@ACME.COM |