5.6 Rights

Rights refers to eDirectory trustee rights and trustees. When you create a tree, the default rights assignments give your network generalized access and security. iManager lets you perform the following rights-related tasks:

For more information about eDirectory rights, see the Novell eDirectory 8.8 SP7 Administration Guide.

5.6.1 Modifying the Inherited Rights Filter

Both eDirectory and the NetWare file system provide an Inherited Rights Filter (IRF) mechanism to block rights inheritance on individual subordinate items. One exception is that the Supervisor right can’t be blocked in the NetWare file system.

For more information about Inherited Rights Filters, see the Novell eDirectory 8.8 SP7 Administration Guide.

  1. In Roles and Tasks, select Rights > Modify Inherited Rights Filter.

  2. Specify the full name of the object whose inherited rights filter you want to modify, or use the Object Selector to find it, then click OK.

    This displays a list of the inherited rights filters that have already been set on the object.

  3. On the property page, edit the list of inherited rights filters as needed, then click OK.

    To edit the list of filters, you must have the Supervisor or Access Control right to the ACL property of the object. You can set filters that block inherited rights to the object as a whole, to all the properties of the object, and to individual properties.

5.6.2 Modifying Trustee Rights

A trustee is one object that has been granted explicit rights to another object in your directory tree. To modify the trustee list for a given object:

  1. In Roles and Tasks, select Rights > Modify Trustees.

  2. Specify, or use the Object Selector to find, the name of the object whose trustee list you want to view, then click OK.

    This opens a list of the object’s currently assigned trustees.

  3. Modify the trustee list as needed, then click OK.

    • Add a trustee by clicking Add Trustee.

    • Remove a trustee by selecting its check box and clicking Remove Selected.

    • Modify a trustee’s rights assignment by selecting the Assigned Rights link for that trustee.

5.6.3 Rights to Other Objects

This task allows you to view and modify the list of objects to which an object is a trustee.

  1. In Roles and Tasks, select Rights > Rights To Other Objects.

  2. In the Rights To Other Objects page, provide the required information, then click OK.

    • Specify the name of the object in Trustee name.

    • Specify the context in which you want to search for objects that have this trustee in Context to search from.

      Select Search entire subtree to search all containers under the specified context.

  3. Modify the object list as needed, then click OK.

    • Add explicit rights to another object by clicking Add Object.

    • Remove explicit rights to an object by selecting its check box and clicking Remove Selected.

    • Modify the explicit rights granted to an object by selecting the Assigned Rights link for that object.

5.6.4 Viewing Effective Rights

Effective rights is the combination of explicit and inherited rights that an object has at any point in the directory tree. To view an object’s effective rights to another object:

  1. In Roles and Tasks, select Rights > View Effective Rights.

  2. Specify, or use the Object Selector to find, the name of the trustee whose rights you want to view, then click OK.

  3. In the Object name field, specify the name of the object for which you want to calculate the trustee’s effective rights.

    eDirectory calculates the effective rights and displays them in the Effective Rights field.

  4. Click Done when finished.