home *** CD-ROM | disk | FTP | other *** search
-
-
-
- AAAACCCCLLLL____DDDDBBBB((((5555)))) KKKK----TTTTaaaallllkkkk bbbbyyyy XXXXiiiinnnneeeetttt ((((11110000////11114444////99999999 11110000....1111)))) AAAACCCCLLLL____DDDDBBBB((((5555))))
-
-
-
- NNNNAAAAMMMMEEEE
- acl_db - database of Access Control Lists
-
- DDDDEEEESSSSCCCCRRRRIIIIPPPPTTTTIIIIOOOONNNN
- The _a_c_l__d_b file is used by various Xinet programs to grant
- (or deny) access to various subsystems. It consists of a
- series of named ``Access Control Lists'' that specify
- AppleTalk and/or IP addresses and User Accounts that are
- allowed to use a service. As of this writing, ACLs are used
- to control access to AppleShare Volumes and the
- configuration GUI.
-
- The file consists of a sequence of text lines, one list per
- line, where each line looks like:
- ACL_name:flags:list_item_1[,_l_i_s_t__i_t_e_m__N]
- where _A_C_L__n_a_m_e is the reference name, _f_l_a_g_s is used by the
- GUI to control which ACLs are effective for a service, and
- the comma-separated _l_i_s_t__i_t_e_m_s make up the access list.
- Spaces are allowed, but are significant (i.e. always part
- of any name). The list item sequence can consist of:
-
- A_s_t_a_r_t:_e_n_d
- If access is via AppleTalk, allow any host in the
- network range _s_t_a_r_t to _e_n_d.
-
- H_i_p_a_d_d_r
- Allow a host with IP address _i_p_a_d_d_r, which can be a
- name or in standard Internet dot notation.
-
- N_i_p_a_d_d_r:_m_a_s_k
- Allow hosts on IP Network _i_p_a_d_d_r (which must be in dot
- notation), with _m_a_s_k number of upper bits denoting the
- network portion of the address.
-
- U_n_a_m_e
- Allow login account _n_a_m_e access. If an ACL contains _n_o
- account items, all users from access-granted host
- addresses are allowed access.
-
- L_a_c_l Search ACL list _a_c_l along with this access list. If
- one ACL has users listed, they do NOT combine with or
- affect other referenced ACLs. Once access is granted,
- sub-ACLs are ignored.
-
- There are two pre-defined ACLs that are always available
- whether or not any ACLs are provided in the database (and if
- they ARE included in the database, they will be ignored).
- They are: <<<<LLLLooooccccaaaallll NNNNeeeettttwwwwoooorrrrkkkkssss>>>> and <<<<NNNNoooo AAAAcccccccceeeessssssss>>>> (where the
- brackets are part of the name). Services protected by the
- <<<<LLLLooooccccaaaallll NNNNeeeettttwwwwoooorrrrkkkkssss>>>> ACL will be useable by any AppleTalk or IP
- networks directly-connected to the server. If the <<<<NNNNoooo
-
-
-
- Page 1 (printed 5/15/100)
-
-
-
-
-
-
- AAAACCCCLLLL____DDDDBBBB((((5555)))) KKKK----TTTTaaaallllkkkk bbbbyyyy XXXXiiiinnnneeeetttt ((((11110000////11114444////99999999 11110000....1111)))) AAAACCCCLLLL____DDDDBBBB((((5555))))
-
-
-
- AAAAcccccccceeeessssssss>>>> ACL is used, the service is effectively disabled.
-
- If a service is protected by an ACL, and that ACL name does
- not match an entry in this database, that access control
- defaults to the <<<<LLLLooooccccaaaallll NNNNeeeettttwwwwoooorrrrkkkkssss>>>> ACL.
-
- FFFFIIIILLLLEEEESSSS
- /var/adm/appletalk/acl_db
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Page 2 (printed 5/15/100)
-
-
-
-