Este conteúdo não está disponível no idioma selecionado.
Chapter 22. Managing self-service rules using the IdM Web UI
Manage self-service rules in Identity Management (IdM) using the Web UI to control which attributes users can edit on their own entries. Self-service rules reduce administrative overhead by allowing users to manage specific personal data independently.
22.1. Self-service access control in IdM Copiar o linkLink copiado para a área de transferência!
Self-service access control rules define which operations an Identity Management (IdM) entity can perform on its IdM Directory Server entry: for example, IdM users have the ability to update their own passwords.
This method of control allows an authenticated IdM entity to edit specific attributes within its LDAP entry, but does not allow add or delete operations on the entire entry.
Be careful when working with self-service access control rules: configuring access control rules improperly can inadvertently elevate an entity’s privileges.
22.2. Creating self-service rules using the IdM Web UI Copiar o linkLink copiado para a área de transferência!
Create self-service rules using the Identity Management (IdM) WebUI to allow users to manage their own account attributes. Self-service rules reduce administrative burden while allowing users to update specific information.
Prerequisites
- Administrator privileges for managing IdM or the User Administrator role.
- You are logged-in to the IdM Web UI. For details, see Accessing the IdM Web UI in a web browser.
Procedure
- Open the IPA Server>Role-Based Access Control menu and select Self Service Permissions.
- Click Add at the upper-right of the list of the self-service access rules.
- On the Add Self Service Permission window, enter the name of the new self-service rule in the Self-service name field. Spaces are allowed.
- Select the checkboxes next to the attributes you want users to be able to edit.
Optional: If an attribute you want to provide access to is not listed, you can add a listing for it:
- Click the Add button.
- On the Add Custom Attribute window, enter the attribute name in the Attribute text field.
- Click the OK button to add the attribute.
- Verify that the new attribute is selected.
Click the Add button at the bottom of the form to save the new self-service rule.
Alternatively, you can save and continue editing the self-service rule by clicking the Add and Edit button, or save and add further rules by clicking the Add and Add another button.
22.3. Editing self-service rules using the IdM Web UI Copiar o linkLink copiado para a área de transferência!
Modify self-service rules using the Identity Management (IdM) WebUI to adjust which attributes users can manage themselves.
Prerequisites
- Administrator privileges for managing IdM or the User Administrator role.
- You are logged-in to the IdM Web UI. For details, see Accessing the IdM Web UI in a web browser.
Procedure
- Open the IPA Server>Role-Based Access Control menu and select Self Service Permissions.
- Click on the name of the self-service rule you want to modify.
- The edit page only allows you to edit the list of attributes to you want to add or remove to the self-service rule. Select or deselect the appropriate checkboxes.
- Click the Save button to save your changes to the self-service rule.
22.4. Deleting self-service rules using the IdM Web UI Copiar o linkLink copiado para a área de transferência!
You can delete self-service rules using the Identity Management (IdM) WebUI to revoke user permissions for managing their own attributes. Removing unnecessary self-service rules helps maintain appropriate access control.
Prerequisites
- Administrator privileges for managing IdM or the User Administrator role.
- You are logged-in to the IdM Web UI. For details, see Accessing the IdM Web UI in a web browser.
Procedure
- Open the IPA Server>Role-Based Access Control menu and select Self Service Permissions.
- Select the checkbox next to the rule you want to delete, then click on the Delete button on the right of the list.
- A dialog opens, click on Delete to confirm.