Upgrade Guide › Migrating PMDs to an Advanced Policy Management Environment › How to Migrate to Advanced Policy Management › Class Dependency
Class Dependency
When you export the rules for specified classes from a PMDB, you can choose to also export the rules for dependent classes. If you specify that CA Access Control should export dependent classes, CA Access Control exports the following:
- If you export rules that modify resources in a particular class, and the class has a corresponding resource group, CA Access Control also exports the rules that modify resources in that resource group.
For example, if you specify to export FILE class rules, CA Access Control exports the rules that modify resources in the FILE and GFILE classes.
- If you export rules that modify resources in a particular resource group, CA Access Control also exports the rules that modify the member resource of the resource group.
For example, if you specify to export GFILE class rules, CA Access Control exports the rules that modify resources in the GFILE and FILE classes.
- If you export rules that modify resources in a particular class and that class has a PACL The PACL property of a resource is an access control list. Each entry in the list specifies an accessor, the type of access to the resource that the accessor is allowed, and the name of the program that the accessor needs to use when accessing the resource. The program name can include wildcard characters. See also ACL, CALACL, NACL., CA Access Control also exports the rules that modify resources in the PROGRAM class.
- If you export rules that modify resources in a particular class and that class has a CALACL The CALACL property of a resource is an access control list that defines the accessors that are granted authorization to a resource, together with the type of access granted (for example, write) according to the accessors' status in the Unicenter TNG calendar. See also ACL, NACL, PACL., CA Access Control also exports the rules that modify resources in the CALENDAR class.
- If you export rules that modify resources in a particular class, and one of the resources in that class is a member of a CONTAINER resource group, CA Access Control exports the rules that modify resources in the CONTAINER class and the rules that modify the resources that are members of each CONTAINER resource group.
For example, if you specify to export CONTAINER class rules, and the CONTAINER object holds FILE objects, CA Access Control exports the rules that modify resources in the CONTAINER and FILE classes.
|
Copyright © 2012 CA.
All rights reserved.
|
|