ACI and Directory Views

We're working with ds 5.1 and set up an ACI:
(targetattr = "*")
(target = "ldap:///ou=HongKong,ou=vpnaccess,dc=test,dc=com")
(version 3.0;
acl "HKAdminACI";
allow (all)
(groupdn = "ldap:///cn=HKAdminG, ou=administrators, ou=vpnaccess,dc=test,dc=com")
This allows access to only one ou in our tree. When the user in this group logs into the console they can search for other objects and view only a limited amount of attibutes through Users and Groups. We want this group to view the dn of every object so they know where they reside in our Directory Tree. Does anyone know how we can do this?
We tried to add this group to "Set Access Permissions" on the directory itself under Server Group and this gave the group full rights to the whole tree.

Hi,
We're working with ds 5.1 and set up an ACI:
(targetattr = "*")
(target =
"ldap:///ou=HongKong,ou=vpnaccess,dc=test,dc=com")
(version 3.0;
acl "HKAdminACI";
allow (all)
(groupdn = "ldap:///cn=HKAdminG, ou=administrators,
ou=vpnaccess,dc=test,dc=com")
This allows access to only one ou in our tree. When
the user in this group logs into the console they can
search for other objects and view only a limited
amount of attibutes through Users and Groups. We
want this group to view the dn of every object so
they know where they reside in our Directory Tree.
Does anyone know how we can do this?I am not sure I understand what you are trying to accomplish here.
Just two comments:
- the placement of the ACI is important (i.e. the entry holding this ACI). If you place the above ACI into ou=HongKong,ou=vpnaccess,dc=test,dc=com, then you don't even need to use the target keyword
- you probably don't need "all" rights to allow users to search that tree
We tried to add this group to "Set Access
Permissions" on the directory itself under Server
Group and this gave the group full rights to the
whole tree.It's not a surprise, since "all" allows this. For more information about ACIs, refer to the Managing Access Control chapter of the Administrator's Guide (http://docs.sun.com/source/816-5606-10/acl.htm#997355)
Bertold

Similar Messages

  • Zip and directory or package

    How on earth do I zip a package like an Omnigraffle file? I have a nice folder-action script that zips a file into an archive when it is dropped into the folder, but when I dropped an omnigraffle file into the folder it broke it into all the files that the original omnigraffle file consisted of, in other words it treats the file like a directory and breaks it open. I guess omnigraffle files are packages. If I use ditto it complains and tells me that the file is a directory. I cannot find any zip parameter that allows me to compress an omnigraffle file and keep it is a single compressed file. If I right-click and select compress on a file OS X has no problem and I get a single compressed file with the name and a .zip appended, but if I execute the zip application in terminal, or from my script, I get all the tiffs and jpegs and bits and bobs that the omnigraffle file is built with and the file it a goner.
    Most frustrating.
    Thanks for any help.
    Lawrence

    Well - that's done, works fine. The issue I was having was that I wanted files to be zipped into an archive without any path, so I would include the -j parameter. The -j parameter however would not only NOT store the path of the file, but it would also NOT store directory names.
    Okay - I thought. There is the -r parameter, this tells zip to travel the directory structure recursively thus picking up sub-directory content. However the -j conflicts with this and what I found was that zip would take the contents of any sub-directory and stick it at the same level as anything outside the folder.
    At first I thought this would be okay as I wanted this script to be used for ONLY files. However when I added an Omnigraffle file I was stuck as these are packages, and zip views them as directories. So any omnigraffle file would essentially be burst into its component parts, all rendered as files, at the root level of the archive folder. A total no-no.
    If I removed the -j, so that directories would be read and compressed, as well as the omnigraffle files, everything worked fine. Only now each file had a great long file path rooted at /System/user/me..... If I decompressed the zip archive I got a folder named "System" inside which was a folder named "user" and inside that was "me" and on and on until I finally got a folder with my unzipped files in it.
    Horrible.
    I realized that the key word in "man zip" was that the file path zip uses is relative to where the zip is running, and I was running it as a folder action which defaulted to the root, hence the vast great file path. So all I needed to do was to modify the script so that the zip command references just the file names without path, and then do a cd to the archive directory immediately prior to the zip command itself. Thus I implemented a "do shell script" which had two commands on the same line, separated by a semi-colon, the first command being the cd with the full path to the archive folder and the second being the zip without any paths at all and using just the -r parameter.
    Bingo.
    Thanks for everyone's help.
    Lawrence

  • Nautilus directory view settings

    Nautilus forget directory view settings. I set up settings from the menu. Sometimes it change the directory view, sometimes it does not show hidden (what it should do). It occurs for different directories.

    If you hold down the Command key (the one with the cloverleaf looking thingy) and click on an item a new window will open with whatever settings the item had last time it was used. If you hold down the Option key and click on an item, its window opens, with whatever settings it had, and the original Finder window closes. Otherwise just clicking an item in the Sidebar opens the item in whatever format the current window has.
    Francine
    Francine
    Schwieder

  • No XMP ID written when ingesting through file directory view.

    I found that media ingested using file directory view do not get XMP ID written to them at any point of my workflow even if the "Write XMP ID to Files on Import" is checked on Prelude, Media Encoder and Premiere Pro. Those are mostly files from GoPro, Canon DSLR and Sound Devices PIX recorders.
    Media ingested through specific view mode like AVCHD and XDCAM EX do get a proper XMP ID when ingested. I'm transcoding on ingest so it is not a write permission issue.
    I'm using Adobe CS6 (up to date) on OSX 10.8.3
    Does anyone else have the same issue ?

    Hi jenny.
    Ok my post wasn't maybe that clear, I was talking about the unique identifier that is supposedly written in the Basic > Identifier metadata field when you import files in Prelude, Media Encoder or Premiere Pro with this option enabled :
    For clips imported through specific view mode, it works just fine and they get a long random string of characters generated and written on the Identifier field. For files imported through the basic file directory view, it does not seems to work and the Basic > Identifier field ends up empty. Amongst other things, having this XMP ID avoid cache file conflict for files that do have the same file name. And as we work on multiple project at the same time on a networked storage, we do end up sometimes with different files having the same name used concurrently. No problem when they have the XMP ID, but when they do not cache related stuff tends to be acting weird (like rebuilding and piling up new .pek peak files over and over every time the project is opened, we can end up with thousands of them).
    The fast and easy way to avoid this is renaming everything we're going to import through file directory view but I'd prefer being able to benefit from the automated XMP ID generation.
    Everything else metada related works about fine for me.

  • Audit Policy and Event Viewer

    Hi everyone,
    I'm a junior IT auditor seeking for answers about audit policy and event viewer.
    First of all I would like to know what are the difference of log that we obtain from audit policy and event viewer?
    I would like to know that can event viewer show these logs:
    Audit account logon events
    Audit account management
    Audit directory service access
    Audit logon events
    Audit object access
    Audit policy change
    Audit privilege user
    Audit process tracking
    Audit system events
    Thanks in advanced :)

    Hi sally_scrubb,
    As you said, if you configure audit policy, it can provide broad security audit capabilities for client computers and servers. And if you configure this policy, you will find the related events in the Event Viewer.
    For your information, please refer to the following article:
    Audit Policy Settings Under Local Policies\Audit Policy
    In this article, you can find the several links which deliver more detailed information about the items which were listed in your post. From the links, you can learn how to configure the item, what you can get from the item, and the related events about
    the item.
    Hope that helps!
    Regards,
    Lany Zhang

  • ACI and embedded groups

    I'm wondering how the "embedded group" feature works from an ACI point of view.
    I've defined an ACI bades on groupdn = "ldap:///cn=group_A,ou=groups,dc....
    If group_A is a static group containing group_B, it works fine if group_B it a static group that uses objectclass=groupofuniquenames and RDN = cn (I mean using uniquemember attribute is not enough).
    If group_A is a static group containing group_B and group_B is dynamic - filter = (&(objeclass=person)(uid=testuser)) - it works fine too.
    But - maybe I mis use the feature - : if group_A is a dynamic group containg - through filter = (&(objectclass=groupofuniquename)(cn=group_B)) - and group_B is either dynamic or static, it doesn't work.
    Does it mean that dynamic groups used within ACI can only contain users and not groups or that the "embedded group" feature doesn't work with dynamic group concept unless the dynamic group is the last one of the chain and therefore contains users ?
    I'm sure I don't understand something but I can't figure what.
    Regards,
    Christian

    ismemberof only works for static groups.
    My main objective so to use dynamic groups to setup some ACI.
    eg: allow user w/ attribute gidNumber=400 full read/write.Have you considered using filtered roles ?

  • PORTAL SERVER 6.0 and Directory Server 5.1 existing

    I have one istance on sunone directory server 5.1 . I want install secure portal server 6.0 and i want use this directory server? . In the installation manual there are't this procedure.
    When I install the portal I select the installation with existing ldap and the portal server is installed . When I started the portal server this don't work.
    Thank's

    Go to Identity Server v5.1 documentation. It's well documented there. In two words, after you installed it this way, you have to apply 'existing.ldif' file to create ACIs and roles, then to create all services.
    Please check existing.ldif before you will apply it. Depending on your DIT, it may be quite broken. Don't forget to change ums.xml to match your schema.

  • Remote Control and Remote View Problem

    Hi,
    I work at a High School running Netware 6.0 SP5 and Zen works 4.01 ir7.
    Remote Control and Remote View works great but I noticed one problem.
    We have a logo of the school that is forced down on to the desktop when a
    user logs in through group policies. This logo works perfect for the
    desktop wall paper and loads every time a user logs in.
    When I Remote Control or Remote View a computer the users desktop wall
    paper turns from the logo being forced down through group policies to the
    desktop to a blue desktop wall paper.
    I would prefer the desktop wall paper staying the schools logo when I
    Remote Control or Remote View because if the desktop wall paper changes to
    the blue color I mentioned above when I Remote Control or Remote View the
    users computer, they will know that someone is taking over their computer
    which sometimes we dont want them knowing.
    We have Windows 98SE computer running Novell Client 3.4 and we have some
    computers running Windows XP Professional SP1 and Windows XP Professional
    SP2 both running Novell Client 4.91 SP2.
    The Remote Control and Remote View problem of the desktop wall paper
    changing on the users computer occurs on all operating systems mentioned
    above.
    Is there a solution to my above problem? When Remote Controlling and
    Remote Viewing someone's computer I don't want the desktop wall paper to
    change.
    Thanks!

    Bpilon,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
    - Check all of the other support tools and options available at
    http://support.novell.com.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://support.novell.com/forums)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://support.novell.com/forums/faq_general.html
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • What is the diffrence between SAP View and CAD View ?

    What is the diffrence between SAP View and CAD View ?
    What is the main purpose of SAP View
    and
    What is the main purpose of CAD View
    On SAP help i found
    SAP View is used for :The SAP view displays the SAP structure (document-based structure) for the active CAD object, or another document info record (header document), with a single-level or multilevel document structure in a tree structure. You can variably configure the fields using the layout editor.
    CAD View is used for :The CAD view displays the document-based structure of the currently active CAD object, such as the structure of an assembly. The CAD system determines the complete (multilevel) structure and copies it either completely or in stages to the SAP system, in accordance with the default explosion level.
    BUT I did not understand it well
    Can someone explain this with an example
    THanks
    Raj

    Hello Raj,
    SAP View  can be further described as the view that is based on what is existing already in the SAP system. This view is generally used by SAP purchasing, MM people etc
    CAD view is nothing but the replication of the model tree view in the SAP system. This is used by the design engineer and this view replicates only the parts that are actively displayed on the CAD tool window.
    hope this helps. Let me know if you have further questions else please close the message.
    regards
    N K

  • Starting single sign-on and directory service

    i am trying to install oracle 9i infrastructure on my clean win2000 box with 2.4 GHz proc and 1GB RAM.
    i am getting falilure messages for the following:
    infrastructure instance configuration assistant: failed
    oracle 9i application server randomize password: failed
    single sign on configuration assistant: failed
    infrastructure mod-osso configuration assistant: failed
    OPMN configuration assistant: failed
    log file says:
    Configuration failed for IAS
    IAS Instance creation failed
    Configuration failed for JAZN
    JAZN configuration failed: unable to establish a directory context.
    Configuration succeeded for IASProperty
    Configuration failed for IAS
    Configuration failed for JAZN
    after which single sign-on and directory service dont start. which means no connectivity :(
    can somebody please guide me about how to avoid this failure in installation or how to manually start these after installation.
    it would be a great help
    ashish

    Hi,
    we're having exactly the same problem.
    Could you tell me what the problem is with the network ?
    You say configure it properly but what do you mean ?
    It's installed on a Windows 2000 Server machine, it's own DNS.
    Thanks,
    Yuri Arts

  • When frequently switching between mobile and desktop view

    When I frequently switching between mobile and desktop view I have to open the layers every time since they get closed/collapsed. Adobe may need to fix it for the next version.

    You can use CTRL+# to switch between Code and Design View.
    By the way, this is the Dreamweaver Application Development forum which deals with questions about using server-side scripting languages like PHP or ColdFusion. General Dreamweaver questions should be posted in the regular Dreamweaver General Discussions forum.
    And while I´m at it: please use descriptive headlines such as "how to switch between Code and Design View" for your posts -- mentioning your screen name "Goula129" is not helpful to other users.

  • Design view and browser view in DW are different than when I view from local folder

    I'm brand new to Dreamweaver CS5.5 and here is my problem:
    I've made an html page in dreamweaver with a banner, with an additional graphic and some text on top of the banner.  It displays just fine in every browser when I view from the local folder, but when I open DW and view, it displays incorrectly in all three design, live and browser views within DW.  If I make changes to the css file until it views correctly in design view, it no longer displays correctly from the local folder and it still doesn't view correctly in live or browser view within DW.  If what I'm doing isnt going to display accurately in any of the views provided by Dreamweaver as compared to the live server, whats the point in having this software?  I could just keep building webpages in notepad and uploading with CoreFTP.
    Any suggestions?  Is it some setting that I dont know about that I need to change within DW?   Please help.

    align="center" is deprecated (obsolete) code in XHTML & HTML5 doc types.  Instead of styling markup with HTML, you should be using CSS. 
    CSS
    .center {text-align:center}
    HTML
    <p class="center">some centered text here</p>
    With respect to break tags, in XHTML doc types the correct syntax is <br /> not <br>.  However your usage of line breaks is inconsistent with good symantic markup.  Use headings <h1> <h2> <h3> <h4> for important keywords.  Use <p> for descriptive paragraphs.  Use <ul> <li> or <ol> <li> for lists.  Line breaks should be used minimally if ever.
    XHTML doc types require all tags to be lowercase.  Uppercase tags will throw errors.
    Your design is too rigid.  When text size is increased in browsers, your content is unreadable.  See screenshot.
    SOLUTIONS:
    1) DO NOT USE POSITION ABSOLUTE.  You don't need it.  Absolute positioning removes content from the normal document flow resulting in a jumbled mess.  Use default CSS positioning (none) with margins, padding & floats to align elements.
    2) Remove HEIGHT values from all CSS containers.  Height limits a container's capacity to hold more content when needed.  Container height should always be determined by the amount of content it holds; not explicit values.  If required to reveal a background image, for example, use CSS min-height instead of height.
    CSS Box Model
    http://www.w3schools.com/css/css_boxmodel.asp
    CSS Floats
    http://www.w3schools.com/cssref/pr_class_float.asp
    CSS min-height
    http://www.w3schools.com/cssref/pr_dim_min-height.asp
    Nancy O.
    Alt-Web Design & Publishing
    Web | Graphics | Print | Media  Specialists 
    http://alt-web.com/
    http://twitter.com/altweb
    http://alt-web.blogspot.com/

  • Creating and Binding View Objects dynamically : Oracle Jdeveloper 11g

    Hello,
    We are trying to create and bind view objects dynamically to adf data visualization components.
    The view object is a result of multiple tables.
    We are using Oracle JDeveloper 11g Technical Preview. ( can't upgrade to TP2 or TP3 now).
    We have found this : http://radio.weblogs.com/0118231/stories/2003/07/15/creatingUpdateableMultientityViewObjectDefinitionsDynamically.html on our search for the same.
    The sample application however, is in 10g , hence required migration.
    Also, it was a standalone application with the TestClient.java having a main() method.
    Our requirement is for Web Application; we use Adf+jsf .
    Guidance of any sort is very much appreciated.
    Thanks in advance.
    -Anil Golla

    Hi,
    there also exist a forum for JDeveloper 11: JDeveloper and OC4J 11g Technology Preview
    What you are trying todo is not trivial because you need to not only dynamically create the VO, you would also dynamically need to create the binding meta data for it (assuming you use ADF). Not sure if the API to modify the binding is public, so posting it on the JDeveloper 11 forum bears a glimpse of hope for an answer
    In JDeveloper 10.1.3 you can't do this
    Frank

  • Excel 2007 and Smart View 9.3.1.4.041

    Dear Experts,
    We are now working with Excel 2007 and Smart View 9.3.1.4.041, and encounter the problem that ervery time open the protected excel file there would be the warning message "Drawing Objectes in one or more sheet(s) in the workbook are protected. Please unprotect them and try to save again."
    Can any one suggest with;
    1. How to set the Excel security settings for Excel 2007 to work for smart view?
    2. How to avoid the message mentioned above while working with Excel 2007?
    3. How to create a protected Excel file to work with Smart View 9.3.1.4.041 both in Excel 2003 and Excel 2007?
    Tks
    Edited by: Moonlight on May 19, 2010 10:00 AM

    I've experiencied similiar problems, though other users may have found a better solution, I've unlocked the spreadsheat, refreshed, and then relocked via a VBA macro. A button object at the top of the spreadsheet was added to make it easier for the users use as well. If there is a better solution I am very interested in this as well.
    JTF

  • How can I quickly view pdf files like I can do with Windows Picture and Fax viewer for jpg files?

    How can I quickly view pdf files like I can do with Windows Picture and Fax viewer for jpg files? I need to look at several thousand PDF files. It takes too long to open each one individually. The only thing I could think of is combining them into large groups and then using the Navigation index. But I like the way windows Picture and Fax Viewer does it because you can keep the files separate. Combining PDFs causes loss of individual file names. That would be a problem since I do need to have the individual file names.

    Windows Picture and Fax Viewer is a DLL and is started via a rundll32.exe call and can't be set as an application to handle images in Firefox 3 and later versions.
    Try to set Windows Picture and Fax Viewer as the default viewer in Windows, then it should be listed automatically in the Mozilla Firefox Browse dialog.
    *http://www.winhelponline.com/articles/115/1/Windows-Picture-and-Fax-Viewer-as-the-default-viewer-in-Mozilla-Firefox.html
    '''If this reply solves your problem, please click "Solved It" next to this reply when <u>signed-in</u> to the forum.'''

Maybe you are looking for

  • IMovie app keeps trying to update on my first gen iPad. Apple ID is the same on multiple devices. What's the fix?

    If iMovie is incompatible with the iPad first gen, why does it keep asking me to update, then fail? It forces me to update all ther apps individually instead of allowing update all.

  • Two questions: Scanner and exception handlers

    Extreme Newbie Alert: I took a single college semester involving Java, almost five years ago, and haven't really touched it since until recently when I decided to try to get back into it. I am now working on building a program while reading the Java

  • IPod "mine" cannot be synced. An unknown error occurred (-50).

    Every time I try to sync my iPod vid classic 30gb I get this error. Furthermore, it will not let me eject the iPod because it says files are in use. Occasionally, it tells me that it cannot find the drive. Yes, I have done all the "r"s. I've tried fu

  • Batch Determination Error in SD

    Hi All, I am getting an error while activating the Batch Management Box under Sales:general/Plant while creating MM01.The error is Batch Management requirement cannot be changed;Choose "Display errors".Can Anybody help me out on this Best Wishes Sree

  • Changing vendor number in BE PO

    Hi all, As you know, if you need to change the material code when the PO is being transfered to the R/3 BE system, you can use  the B31I_MATERIAL_READ driver to adjust/change the material code number. Now, we need to change also the vendor number whe