Chapter 5. Managing Entries with Roles, Class of Service, and Views

The Directory Server Console automatically shows the nsRoleDN attribute.

1.2.3. Creating a Nested Role

Nested roles are roles that contain other roles. Before it is possible to create a nested role, another role must exist. When a nested role is created, the Console displays a list of the roles available for nesting. The roles nested within the nested role are specified using the nsRoleDN attribute.

To create and add members to a nested role, do the following:

1.Create a new role, as in Section 1.2.1, “Creating a Managed Role”.

2.Click Members in the left pane.

A search dialog box appears briefly.

3.In the right pane, select Nested Role.

4.Click Add to add roles to the list. The members of the nested role are members of other existing roles.

The Role Selector dialog box opens.

5.Select a role from the Available roles list, and click OK.

6.Click OK to save the new role.

The new role appears in the right pane.

NOTE

The nsRoleDN attribute is an operational attribute and must be explicitly requested in the search command in the list of search attributes. For example:

ldapsearch ... args ... “(uid=scarter)” \* nsRole nsRoleDN

The Console will automatically show the nsRoleDN attribute.

1.2.4. Viewing and Editing an Entry's Roles

136

Page 156
Image 156
HP UX Red Hat Direry Server Software manual Creating a Nested Role, Viewing and Editing an Entrys Roles, 136