Directory manager authorizations are usually the most complicated authorizations to give. Often you want to give different kinds of authorization to different directory managers.
We recommend that authorizations for directory managers enable them to use all selections from the Manager Selection Menu on only the user IDs they manage. This authorization is given by adding the following record to the AUTHORIZ CONFIG file:
GRANT MANAGE OVER *DIRUSRS OF *SELF TO *DIRMGRS
Because selection 3 on the Manager Selection Menu accesses the User Selection Menu, you also need to add the following GRANT record to allow directory managers to use it:
GRANT USER OVER *DIRUSRS OF *SELF TO *DIRMGRS
CA VM:Director provides authorizations for the Manager Selection Menu and for each of its selections separately. All Manager Selection Menu selections are authorized with the MANAGE authorization. Authorizations to individual selections are listed in the table, Authorization to Use CA VM:Director Commands and Utilities, in this chapter.
The following extended examples will help you create the authorizations you want.
Example:1
Authorizing your directory managers for Sales and for Shipping to use different commands on the user IDs they manage:
LIST *SALEMGR SILAS DAN GLORIA ALICIA LIST *SHIPMGR SCOTT LONNIE WENDY GARY
LIST *SALECMD CHANGE MANAGE USER ULIST LIST *SHIPCMD CHGMDISK MANAGE USER CLASS EXPIRE
GRANT *SALECMD OVER *DIRUSRS OF *SELF TO *SALEMGR GRANT *SHIPCMD OVER *DIRUSRS OF *SELF TO *SHIPMGR
Alternatively, give the directory managers authorization to use the commands for all users:
GRANT *SALECMD TO *SALEMGR GRANT *SHIPCMD TO *SHIPMGR
GRANT *NEWUSRS TO *SALEMGR GRANT *NEWUSRS TO *SHIPMGR
WITHHOLD MANSEL06 FROM DAN
GRANT PASSWORD OVER *DIRUSRS OF *SHIPMGR TO SILAS
GRANT MANAGE OVER LONNIE’S *MANAGEE TO SILAS
or
GRANT MANAGE OVER *DIRUSRS OF LONNIE TO SILAS
GRANT MANAGE OVER *NEWUSRS TO *DIRMGRS
GRANT MANAGE OVER *DIRUSRS OF *SELF TO *DIRMGRS
Example:2
Giving full authorization to a menu and then withholding individual selections.
You want to authorize each directory manager to perform all management tasks except defining or reactivating a user ID (selection 1; MANSEL01) for any user ID. You want to give MANSEL01 authorization only to MARY:
LIST *DMAN JOHN MARK JANET MIKE PETE ALICE AMY
GRANT MANAGE TO *DMAN MARY
GRANT MANAGE *NEWUSRS TO MARY
WITHHOLD MANSEL01 FROM *DMAN
Example:3
Authorizing each program manager to move minidisks for any user IDs on the system:
LIST *PRGMRS MAC DAVE JIM
GRANT MANSEL06 OVER *ALL TO *PRGMRS
Example:4
Authorizing your program managers to use the User Selection Menu and to edit directory comments and review directory entries for any user IDs on the system:
LIST *PRGCMD MANSEL03 MANSEL07 MANSEL08 USER
GRANT *PRGCMD OVER *ANY TO *PRGMRS
or
GRANT *PRGCMD TO *PRGMRS
|
Copyright © 2014 CA.
All rights reserved.
|
|