The property screens for a security manager definition can be used for adding, editing and deleting user, group and resource definitions held in the associated external security manager (ESM), and for specifying resource permissions. This functionality is dependent on the ESM module, with which you connect to the ESM, providing support, and on the ESM honouring the requests submitted through these screens. Where such support is not available, users, groups and resources must be managed through the tools provided with your external security manager. Please check the documentation provided with your ESM module for details.
In addition to the conditions listed above, the security manager definition must be included in the security manager list that is used by MF Directory Server. See To add a security manager to the Directory server's security manager list or, if MF Directory Server is using the Default ES Security configuration, To add a Security Manager to the Default ES Security Manager List.
In order to use these property screens, your user account must have User Administration permissions. See Resource Classes for MF Directory Server for details.
注意: Please note that the display and setting of permissions for MFDS Internal Security differs from that for other Security Managers, and is covered separately by To assign resource permissions when using MFDS Internal Security.
The screen displays a tree structure. Expanding the top level node displays the various resource classes. Expanding a class displays the resource entities that it contains and the permissions that the group has for those entities. Please note, the permissions displayed are for those Access Control List entries that apply to the group, either by fully specifying the group ID or by a wildcard match.
Related topics: