4 4 3 Grolar:Using Access Control Lists: Difference between revisions

From SEPsesam
mNo edit summary
(Prepared for translation.)
Line 1: Line 1:
<div class="noprint">
<translate><div class="noprint"><languages /></translate>
__FORCETOC__
__FORCETOC__
{{Copyright SEP AG en}}
<translate>{{Copyright SEP AG en}}
{{Navigation_latest|release=4.4.3 ''Grolar''|link=[[Special:MyLanguage/SEP_sesam_Documentation#previous|documentation archive]]}}</div><br />
 
==Overview==
{{Navigation_latest|release=4.4.3 ''Grolar''|link=[[Special:MyLanguage/SEP_sesam_Documentation#previous|documentation archive]]}}</div></translate><br />
<div class="boilerplate metadata" id="Additional resources" style="background-color:#ecedf1; color:#8695a7; border: 1px ridge #cdd3db; margin: 0.5em; padding: 0.5em; float: right; width: 25%; "><center><b>Additional resources</b></center>
<translate>==Overview==</translate>
<div class="boilerplate metadata" id="Additional resources" style="background-color:#ecedf1; color:#8695a7; border: 1px ridge #cdd3db; margin: 0.5em; padding: 0.5em; float: right; width: 25%; "><center><b><translate>Additional resources</translate></b></center>


{|style="margin: auto; margin-bottom:1em; width:100%; border:0px solid grey;"
{|style="margin: auto; margin-bottom:1em; width:100%; border:0px solid grey;"
| rowspan="2" style="padding:0px 10px 0px;" | [[File:SEP Tip.png|45px|link=4_4_3_Grolar:About_Authentication_and_Authorization|About Authentication and Authorization]]
| rowspan="2" style="padding:0px 10px 0px;" | <translate>[[File:SEP Tip.png|45px|link=4_4_3_Grolar:About_Authentication_and_Authorization|About Authentication and Authorization]]</translate>
| style="padding:0px 40px 0px 10px; color: grey; font-size: 90%; text-align:left;" | See also: [[Special:MyLanguage/4_4_3_Grolar:About_Authentication_and_Authorization|About Authentication and Authorization]] – [[Special:MyLanguage/4_4_3_Grolar:Configuring_Database-Based_Authentication|Configuring Database-Based Authentication]] – [[Special:MyLanguage/Configuring_Location|Configuring Location]] – [[Special:MyLanguage/Configuring_Clients|Configuring Clients]] – [[Special:MyLanguage/4_4_3_Grolar:Administering_ACLs_from_the_Command_Line|Administering ACLs from the Command Line]]
| style="padding:0px 40px 0px 10px; color: grey; font-size: 90%; text-align:left;" | <translate>See also: [[Special:MyLanguage/4_4_3_Grolar:About_Authentication_and_Authorization|About Authentication and Authorization]] – [[Special:MyLanguage/4_4_3_Grolar:Configuring_Database-Based_Authentication|Configuring Database-Based Authentication]] – [[Special:MyLanguage/Configuring_Location|Configuring Location]] – [[Special:MyLanguage/Configuring_Clients|Configuring Clients]] – [[Special:MyLanguage/4_4_3_Grolar:Administering_ACLs_from_the_Command_Line|Administering ACLs from the Command Line]]</translate>
|}
|}


{|style="margin: auto; margin-bottom:1em; width:100%; border:0px solid grey;"
{|style="margin: auto; margin-bottom:1em; width:100%; border:0px solid grey;"
| rowspan="2" style="padding:0px 10px 0px;" |
| rowspan="2" style="padding:0px 10px 0px;" |
[[File:SEP Tip.png|45px|link=Special:MyLanguage/FAQ#permissions|FAQ]]
<translate>[[File:SEP Tip.png|45px|link=Special:MyLanguage/FAQ#permissions|FAQ]]</translate>
| style="padding:0px 40px 0px 10px; color: grey; font-size: 90%; text-align:left;" |
| style="padding:0px 40px 0px 10px; color: grey; font-size: 90%; text-align:left;" |
Check [[Special:MyLanguage/FAQ#permissions|FAQ]] to find the answers to most common questions.
<translate>Check [[Special:MyLanguage/FAQ#permissions|FAQ]] to find the answers to most common questions.</translate>
|}
|}


{|style="margin: auto; margin-bottom:1em; width:100%; border:0px solid grey;"
{|style="margin: auto; margin-bottom:1em; width:100%; border:0px solid grey;"
| rowspan="2" style="padding:0px 10px 0px;" | [[File:SEP Troubleshooting.png|45px|link=Special:MyLanguage/Troubleshooting_Guide|Troubleshooting Guide]]
| rowspan="2" style="padding:0px 10px 0px;" | <translate>[[File:SEP Troubleshooting.png|45px|link=Special:MyLanguage/Troubleshooting_Guide|Troubleshooting Guide]]</translate>
| style="padding:0px 40px 0px 10px; color: grey; font-size: 90%; text-align:left;" | Problems? Check the [[Special:MyLanguage/Troubleshooting_Guide| Troubleshooting Guide]].  
| style="padding:0px 40px 0px 10px; color: grey; font-size: 90%; text-align:left;" | <translate>Problems? Check the [[Special:MyLanguage/Troubleshooting_Guide| Troubleshooting Guide]].</translate>
|}</div>
|}</div>
An access control list (ACL) is a list of permissions attached to an object (e.g., client, location, backup, etc.). Use of ACL specifies the conditions for a particular user or group to do an operation on a specific object (e.g., client, location, backup, etc.). As of SEP sesam version [[Special:MyLanguage/SEP_sesam_Release_Versions|4.4.3 ''Grolar'']], you can configure ACLs for [[Special:MyLanguage/SEP_sesam_Glossary#location|locations]] and [[Special:MyLanguage/SEP_sesam_Glossary#SBC|clients]], if you have the ''admin'' rights.  
<translate>An access control list (ACL) is a list of permissions attached to an object (e.g., client, location, backup, etc.). Use of ACL specifies the conditions for a particular user or group to do an operation on a specific object (e.g., client, location, backup, etc.). As of SEP sesam version [[Special:MyLanguage/SEP_sesam_Release_Versions|4.4.3 ''Grolar'']], you can configure ACLs for [[Special:MyLanguage/SEP_sesam_Glossary#location|locations]] and [[Special:MyLanguage/SEP_sesam_Glossary#SBC|clients]], if you have the ''admin'' rights.  


Note that before you configure ACLs, you have to activate authentication, configure the users and specify their access rights. For details, see [[Special:MyLanguage/4_4_3_Grolar:Configuring_Database-Based_Authentication|Configuring Database-Based Authentication]].
Note that before you configure ACLs, you have to activate authentication, configure the users and specify their access rights. For details, see [[Special:MyLanguage/4_4_3_Grolar:Configuring_Database-Based_Authentication|Configuring Database-Based Authentication]].
Line 28: Line 29:
=={{anchor|configuration}}Configuring permissions (ACLs) for locations and clients==
=={{anchor|configuration}}Configuring permissions (ACLs) for locations and clients==


You can configure ACLs for a location (group of clients) or a specific client in the properties of the existing locations and clients. If you want to set up ACLs for a new location/client, you have to configure it first and then you can add the relevant permissions in their properties. For details on how to configure new locations and clients, see [[Special:MyLanguage/Configuring_Location|Configuring Location]] and [[Special:MyLanguage/Configuring_Clients|Configuring Clients]].
You can configure ACLs for a location (group of clients) or a specific client in the properties of the existing locations and clients. If you want to set up ACLs for a new location/client, you have to configure it first and then you can add the relevant permissions in their properties. For details on how to configure new locations and clients, see [[Special:MyLanguage/Configuring_Location|Configuring Location]] and [[Special:MyLanguage/Configuring_Clients|Configuring Clients]].</translate>


<ol><li>From '''Main selection''' -> '''Components''' -> '''Topology''', select the relevant location or a client (under the location) and double-click it (or click the '''Properties''' button). The ''Location/Client properties'' window appears.</li>  
<ol><li><translate>From '''Main selection''' -> '''Components''' -> '''Topology''', select the relevant location or a client (under the location) and double-click it (or click the '''Properties''' button). The ''Location/Client properties'' window appears.</translate></li>  
<li>Switch to the ''Permissions'' tab. Select the relevant user or group. You can also add a new user/group by clicking '''Add''' and selecting a relevant user/group from the drop-down list.<br />Click '''OK''' to add a new user/group.</li>
<li><translate>Switch to the ''Permissions'' tab. Select the relevant user or group. You can also add a new user/group by clicking '''Add''' and selecting a relevant user/group from the drop-down list.<br />Click '''OK''' to add a new user/group.</translate></li>
[[Image:Authentication_add_user.jpg|750px|link=]]
<translate>[[Image:Authentication_add_user.jpg|750px|link=]]</translate>
<br clear=all>
<br clear=all>
<li>Under ''Permissions'' panel, enable or disable access (to location/client) per user/group by clicking the '''Allow''' or '''Deny''' checkbox. </li>
<li><translate>Under ''Permissions'' panel, enable or disable access (to location/client) per user/group by clicking the '''Allow''' or '''Deny''' checkbox.</translate> </li>
{{note|
{{<translate>note</translate>|
*By default, members of the ''ADMIN'' and ''OPERATOR'' groups have full access to all locations and clients. The ''RESTORE'' group has restricted access to all locations and clients.  
*<translate>By default, members of the ''ADMIN'' and ''OPERATOR'' groups have full access to all locations and clients. The ''RESTORE'' group has restricted access to all locations and clients.</translate>
*ACLs can be set for the ''OPERATOR'' and ''RESTORE'' group. To ensure that your administrator(s) always have full access to all functionality, the following applies:
*<translate>ACLs can be set for the ''OPERATOR'' and ''RESTORE'' group. To ensure that your administrator(s) always have full access to all functionality, the following applies:</translate>
**If database-based authentication is enabled, you cannot set ACL for the user ''Administrator''  (the user ''Administrator'' has access to all features).  
**<translate>If database-based authentication is enabled, you cannot set ACL for the user ''Administrator''  (the user ''Administrator'' has access to all features).</translate>
**In case of policy-based authentication, ACLs cannot be set for members of the ''ADMIN'' group (the ''ADMIN'' group has access to all features).}}   
**<translate>In case of policy-based authentication, ACLs cannot be set for members of the ''ADMIN'' group (the ''ADMIN'' group has access to all features).</translate>}}   
<li>Click '''OK''' to set up ACLs for a location/client.</li>
<li><translate>Click '''OK''' to set up ACLs for a location/client.</translate></li>
[[Image:Authentication_permissions.jpg|link=]]
<translate>[[Image:Authentication_permissions.jpg|link=]]</translate>
<br clear=all>
<br clear=all>
</ol>
</ol>
When the administrator defines ACLs, the list of ACL entries is saved in the SEP sesam database and take effect immediately. This means that the new authorization settings (stored ACLs) are used for all further queries for the objects.  
<translate>When the administrator defines ACLs, the list of ACL entries is saved in the SEP sesam database and take effect immediately. This means that the new authorization settings (stored ACLs) are used for all further queries for the objects.
 
<div class="noprint">
<div class="noprint">
==See also==
==See also==
[[Special:MyLanguage/4_4_3_Grolar:About_Authentication_and_Authorization|About Authentication and Authorization]] – [[Special:MyLanguage/4_4_3_Grolar:Configuring_Database-Based_Authentication|Configuring Database-Based Authentication]] – [[Special:MyLanguage/Configuring_Location|Configuring Location]] – [[Special:MyLanguage/Configuring_Clients|Configuring Clients]] – [[Special:MyLanguage/4_4_3_Grolar:Administering_ACLs_from_the_Command_Line|Administering ACLs from the Command Line]]</div>
[[Special:MyLanguage/4_4_3_Grolar:About_Authentication_and_Authorization|About Authentication and Authorization]] – [[Special:MyLanguage/4_4_3_Grolar:Configuring_Database-Based_Authentication|Configuring Database-Based Authentication]] – [[Special:MyLanguage/Configuring_Location|Configuring Location]] – [[Special:MyLanguage/Configuring_Clients|Configuring Clients]] – [[Special:MyLanguage/4_4_3_Grolar:Administering_ACLs_from_the_Command_Line|Administering ACLs from the Command Line]]</div></translate>

Revision as of 12:24, 18 June 2018

Other languages:

Template:Copyright SEP AG en

Docs latest icon.png Welcome to the latest SEP sesam documentation version 4.4.3 Grolar. For previous documentation version(s), check documentation archive.


Overview

An access control list (ACL) is a list of permissions attached to an object (e.g., client, location, backup, etc.). Use of ACL specifies the conditions for a particular user or group to do an operation on a specific object (e.g., client, location, backup, etc.). As of SEP sesam version 4.4.3 Grolar, you can configure ACLs for locations and clients, if you have the admin rights.

Note that before you configure ACLs, you have to activate authentication, configure the users and specify their access rights. For details, see Configuring Database-Based Authentication.

Configuring permissions (ACLs) for locations and clients

You can configure ACLs for a location (group of clients) or a specific client in the properties of the existing locations and clients. If you want to set up ACLs for a new location/client, you have to configure it first and then you can add the relevant permissions in their properties. For details on how to configure new locations and clients, see Configuring Location and Configuring Clients.

  1. From Main selection -> Components -> Topology, select the relevant location or a client (under the location) and double-click it (or click the Properties button). The Location/Client properties window appears.
  2. Switch to the Permissions tab. Select the relevant user or group. You can also add a new user/group by clicking Add and selecting a relevant user/group from the drop-down list.
    Click OK to add a new user/group.
  3. Authentication add user.jpg
  4. Under Permissions panel, enable or disable access (to location/client) per user/group by clicking the Allow or Deny checkbox.
  5. Information sign.png Note
    • By default, members of the ADMIN and OPERATOR groups have full access to all locations and clients. The RESTORE group has restricted access to all locations and clients.
    • ACLs can be set for the OPERATOR and RESTORE group. To ensure that your administrator(s) always have full access to all functionality, the following applies:
      • If database-based authentication is enabled, you cannot set ACL for the user Administrator (the user Administrator has access to all features).
      • In case of policy-based authentication, ACLs cannot be set for members of the ADMIN group (the ADMIN group has access to all features).
  6. Click OK to set up ACLs for a location/client.
  7. Authentication permissions.jpg

When the administrator defines ACLs, the list of ACL entries is saved in the SEP sesam database and take effect immediately. This means that the new authorization settings (stored ACLs) are used for all further queries for the objects.