Select Schema from the task selection bar. The Attribute Types and Object Classes Click the Create Like button at the top of the tree. The base object class’s

16 Configuring Oracle Virtual Directory Access Control 16-1 16 Configuring Oracle Virtual Directory Access Control This chapter explains how to configure access control for Oracle Virtual Directory and includes the following topics: ■ Creating Access Control Lists Using Oracle Directory Services Manager ■ Managing Access Control Lists Using Oracle Directory Services Manager

16.1 Creating Access Control Lists Using Oracle Directory Services Manager

Perform the following steps to create an ACL using Oracle Directory Services Manager: 1. Log in to Oracle Directory Services Manager.

2. Select Security from the task selection bar. The Access Control Point navigation

tree appears listing the existing Access Control Points.

3. Click the Create button. The new ACL dialog box appears.

4. Identify the Access Control Point for the new ACL by entering the DN where you want to apply the new ACL in the DN field.

5. Configure the scope of the new ACL by selecting either entry or subtree from the

Scope list. Selecting entry applies the new ACL only at the Access Control Point DN entry in the virtual tree. Selecting subtree applies the new ACL at the Access Control Point DN entry and all the entries in the subtree below it.

6. Click the Create button in the Structural Access Items Entry Level Operations

area to create access policy for the entries in the virtual directory tree. The Structural Access configuration dialog box appears.

7. Click the Permissions tab and perform the following to set the entry permissions

for the access policy: Note: If two ACLs differ only by their grantdeny property, the resulting permission will be a deny regardless of the order in which the ACLs are added. For example, the following two ACLs will result in a deny for Searchs and Readr of all attributes for public: deny:s,r[all]public: grant:s,r[all]public: 16-2 Oracle Fusion Middleware Administrators Guide for Oracle Virtual Directory ■ To explicitly grant access for an entry permission, select Grant from the Access Type list and select the permissions you want to grant access to. ■ To explicitly deny access for an entry permission, select Deny from the Access Type list and select the permissions you want to deny access to.

8. Click the By Whom tab and perform the following to set to whom the entry access

policy applies: ■ Select the subject of the ACL from the By Whom list. ■ Enter the DN or IP address of the in the DN or IP Address field if you chose Specific DN or IP Address from the By Whom list. Click the OK button to save the Structural Access Items Entry Level Operations settings. The new entry access policy appears in the Structural Access Items Entry Level Operations table.

9. Click the Create button in the Content Access Items Attribute Level Operations

area to create access policy for the attributes of the entry. The Content Access configuration dialog box appears.

10. Click the Target tab and select the attributes from the Attribute list that the access

policy applies to. Selecting applies the access policy to all attributes.

11. Click the Permissions tab and perform the following to set the attribute

permissions for the access policy: ■ To explicitly grant access for an attribute permission, select Grant from the Access Type list and select the permissions you want to grant access to. ■ To explicitly deny access for an attribute permission, select Deny from the Access Type list and select the permissions you want to deny access to.

12. Click the By Whom tab and perform the following to set to whom the attribute

access policy applies: ■ Select the subject of the ACL from the By Whom list. ■ Enter the DN or IP address of the in the DN or IP Address field if you chose Specific DN or IP Address from the By Whom list. 13. Click the OK button to save the Content Access Items Attribute Level Operations settings. The new attribute access policy appears in the Content Access Items Attribute Level Operations table.

16.2 Managing Access Control Lists Using Oracle Directory Services Manager

This topic explains how to manage ACLs using Oracle Directory Services Manager and contains the following sections: ■ Updating Access Control Lists ■ Deleting Access Control Lists Entries

16.2.1 Updating Access Control Lists

Perform the following steps to edit an existing ACL using Oracle Directory Services Manager: 1. Log in to Oracle Directory Services Manager.