Setting up and managing NDS objects

Managing organizational role objects

An Organizational Role object allows you to assign rights to a particular position rather than to the person who occupies that position. The people who occupy that position may change frequently, but the responsibilities of that position do not.

The user assigned to an Organizational Role is called the occupant and is granted all rights that are granted to the Organizational Role object.

For example, you decide that you need a print manager for SALES. You create an Organizational Role object called PRINT MANAGER. You grant the PRINT MANAGER object all object rights to all the Printer, Print Queue, and Print Server objects in that part of the Directory tree.

You may also grant the PRINT MANAGER object the property rights to the Print Job Configuration property of users.

You can assign anyone to the PRINT MANAGER object without having to re-create all the trustee assignments.

When a user is added to the occupant list of an Organizational Role object, the Organizational Role is listed in that user's ``Security Equal To'' property. The user is granted all rights that any object (User, Group, Printer, and so on) in that list is granted, both to objects and to files and directories.

You can use NetWare Administrator or NETADMIN to create an Organizational Role object. Both procedures are described in this topic.

Creating organizational role objects using NetWare Administrator

The following list describes the prerequisites:

Carry out the following procedure:

  1. From the Windows Program Manager or the OS/2 desktop, click on the ``NetWare Administrator'' icon.

  2. Select the object that will contain the new Organizational Role object.

    For information on moving around in the browser and selecting objects, press <F1>.

    Only Organization and Organizational Unit objects can contain Organizational Role objects.

  3. From the Object menu, choose Create.

  4. From the ``New Object'' dialog box, choose ``Organizational Role''.

    If ``Organizational Role" does not appear under ``New Object'', you cannot create Organizational Role objects in this container. Select or create another object to contain the Organizational Role object.

  5. Choose OK.

    The ``Create Organizational Role'' dialog box appears.

  6. Type the Organizational Role object name in the box provided.

  7. (Optional) ``Select Define Additional Properties''.

  8. Select the Create button at the bottom of the window.

    The ``Identification'' page of the ``Object'' dialog box appears.

  9. Enter information in the fields provided in the ``Identification'' dialog box.

  10. Choose the button to the right of ``Occupant''.

  11. Choose Add.

    The ``Select Object'' window appears.

  12. Select User objects from the ``Directory Context'' window until the objects you want are shown in the ``Object'' window.

  13. Select the User object in the left window to occupy the Organizational Role; then choose OK.

    The object you selected appears in the ``Occupant'' window.

  14. Choose OK in the ``Occupant'' window.

  15. When you are finished adding User objects as Occupants, choose OK in the ``Organizational Role'' window.

  16. (Optional) Select the See Also button at the right side of the object dialog box.

    The ``See Also'' page allows you to add information about the Organizational Role object you are creating. For example, you might list the User objects that you have assigned as occupants.

  17. To save the new Organizational Role object and return to the browser, choose OK.

Creating Organizational Role objects using NETADMIN

The following list describes the prerequisites:

Carry out the following procedure:

  1. At the DOS prompt, type
    NETADMIN
    
    For information on moving around in NETADMIN and selecting objects, press <F1> after starting the utility.

  2. From the NetAdmin Options menu, choose Manage Objects.

  3. Select the object that will contain the new Organizational Role object.

    The objects in the selected container are listed.

    To see if you are in the right context, look at the title bar on the screen. Press <F1> for help.

  4. Press <Ins>.

  5. Select ``Organizational Role''.

    If the Organizational Role object class does not appear, you cannot create that object in the selected container. Press <Esc> to return to the browser, and then select a different container type.

  6. Type the new Organizational Role object name.

  7. Type the Mailbox Location and press <Enter>.

  8. If you want to create another Organizational Role object, choose ``Yes''. If you do not, choose ``No.''

    If you choose ``Yes'', you are prompted to type the new Organizational Role object name. Repeat Step 6 and then continue with Step 9.

    If you choose ``No,'' then the Organizational Role object is displayed in the Directory tree. Continue with Step 9.

  9. To edit this object, press <F10>.

    A menu appears from which you can choose to view or edit information about this object.

  10. Choose View or Edit Properties of This Object.

  11. From the View or Edit Organizational Role menu, choose Identification.

  12. Specify a User object for the Organizational Role.

  13. Select additional User objects as needed.

  14. To save the list of occupants, press <F10>.

  15. Enter information in other fields as needed.

  16. To save changes, press <F10>.

  17. To exit, press <Esc> until you return to the NetAdmin Options menu.

© 1999 The Santa Cruz Operation, Inc. All rights reserved.
UnixWare 7 Release 7.1.1 - 5 November 1999