OSF DCE Administration Guide--Core Components

Accessing Registry Objects
_______________________________________________________________________________
Permission Meaning
_________________________________________________________________
_________________________________________________________________
Execute commands that act on replicas (sec_admin).A
_________________________________________________________________
a Modifies authentication information.
_________________________________________________________________
Modifies ACLs on objects. All registry ACLs must have one
entry that specifies c (control) permission.
c
_________________________________________________________________
d Deletes from an object’s contents.
_________________________________________________________________
D Deletes an object from the registry.
_________________________________________________________________
Modifies a principal’s, group’s, or organization’s full name.f
_________________________________________________________________
g Adds a principal to a group.
_________________________________________________________________
i Adds to a object’s contents.
_________________________________________________________________
m Modifies management information.
_________________________________________________________________
Adds and deletes members from this group or organization. To
add a member to a group, you must also have g permission for
the principal to be added.
M
_________________________________________________________________
Modifies the name of a directory, a principal, a group, or an
organization.
n
_________________________________________________________________
u Modifies user information.
_________________________________________________________________
Views management, authentication, and user information.r
_________________________________________________________________
Tests the group or organization membership of a named
principal.
t
_________________________________________________________________
41.2.1 Management, Authentication, and User Information
The registry contains three different kinds of information about the objects in it:
management information, authentication information, and user information. The specific
items of information that are kept for each object type are summarized in the following
subsections.
41.2.1.1 Management Information
Management information includes the following categories:
For registry policies and properties
— The account lifespan
— The password minimum length
— The password lifespan
— Whether or not passwords can contain spaces
124243 Tandem Computers Incorporated 413