OSF DCE Administration Guide--Core Components
Accessing Registry Objects
xattrschema object
m permission
To modify ERA types, you must have m permission on the xattrschema object.
41.2.19 Permission Required to Change ACLs on Registry Objects
Figure 41-22 shows the permissions that are required to change ACLs on registry
objects.
Figure 41-22. Permission Required to Change ACLs on Registry Objects
object whose ACL
is being changed
c permission
To modify ACLs on registry objects, you must have the c permission on the object whose
ACL you are changing. The registry object can be the policy object or a principal, group,
or organization.
41.2.20 Permissions Required by Slave Replicas
In order to initialize and function properly, slave replicas must have the i, m, and I
permissions for the replist object (/.:/sec/replist). A slave server runs under the indentity
of the machine on which it runs. A machine name is the local host principal name in the
following form:
host/hostname/self
The required ACL entry is added when the dce_config tool initially configures the DCE
cell’s security server and when you use the tool to create new slave replicas. The entry
has the following form:
user:host/hostname/self:imI
124243 Tandem Computers Incorporated 41− 17