Setting Up a Workstation Policy Package

In order to have a Workstation Policy Package, you must first create the policy package. To create a Workstation Policy Package, do the following:

  1. Start ConsoleOne.

  2. Browse to the container where you want to have the policy package. Remember that you do not have to create the policy package in the container where you are doing the associations. You can associate the same policy package to many containers in your tree.

  3. Create the policy package by right-clicking and choosing New, Policy Package or by selecting the Policy Package icon on the toolbar.

  4. Select the Workstation Policy Package object in the wizard panel and press Next.

  5. Enter the desired name of the package in the Policy Package Name field and select the container where you want the package to be located. The container field is already filled in with the selected container so you should not have to browse to complete this field. If it is not filled in, press the browser button next to the field to find the container where you want the policy object stored. Press Next.

  6. Select the Define Additional Attributes field in order to go into the properties of your new object and activate some policies. Press Finish.

  7. Check and set any policies you desire for this Workstation Policy Package and press OK.

The following subsections describe each of the fields and property pages that are available in the Workstation Policy Package.

Policies Property Page

All of the policies are activated within the Policies property page. Initially the page is on the general policies. As other platforms are selected additional policies are displayed. You can select which platform to display by clicking the small triangle to the right of the word Policies in the tab. This activates a drop-down menu that enables you to select which platform-specific page you want to display.

The following sections discuss briefly each of the policy pages; subsequent sections cover the specifics of each policy.

General Policies

When you first go into the properties of the Workstation Policy Package, you are presented with the Policy Property page. The policy page first displays the general category. All policies activated in the general category are active for all workstation platforms supported by ZENworks for Desktops 4 and associated to the workstation.

Figure 9.1 shows a snapshot of the initial property page of the Workstation Policy Package.

Figure 9.1. Workstation Policy Package policies general property page.

graphics/09fig01.jpg

As you can see in Figure 9.1, four policies are available to all of the platforms supported by ZENworks for Desktops 4. They include the Novell iPrint Policy, the Remote Control Policy, the Workstation Imaging Policy, and the ZENworks for Desktops Agent Policy. These, as well as all of the other policies, are discussed later in this chapter.

In order to activate a policy, you simply need to select it. You can then go into the details of the policy and set additional configuration parameters on that specific policy.

Windows NT Policies

Within the policies tab you can select the Windows NT policy page. This page displays the policies that are available for Windows NT workstations, including the Computer Extensible Policies, the Novell iPrint Policy, the Remote Control Policy, the Workstation Imaging Policy, the Workstation Inventory, and the ZENworks for Desktops Agent Policy. See Figure 9.2 for a sample of the Windows NT policies page.

Figure 9.2. Workstation Policy Package, Windows NT policies property page.

graphics/09fig02.jpg

As you can see, the same policies appear on the General and on the Windows NT policies page. When you select a policy in the Windows NT page, it overrides any selections made on the General tab for that platform. The policies are not merged, and only the platform-specific policy is used. For example, if the Workstation Import policy is selected in the General tab and in the Windows NT tab, agents on a Windows 2000 system use the Windows NT Workstation Import policy rather than the policy in the General tab.

Windows 2000 Policies

Within the policies tab you can select the Windows NT policy page. This page displays the policies that are available for Windows 2000 workstations, including the Computer Extensible Policies, the Novell iPrint Policy, the Remote Control Policy, the Windows Group Policy, the Workstation Imaging Policy, the Workstation Inventory, and the ZENworks for Desktops Agent Policy. See Figure 9.3 for a sample of the Windows 2000 policies page.

Figure 9.3. Workstation Policy Package, Windows 2000 policies property page.

graphics/09fig03.jpg

As you can see, the same policies are on the General and the Windows 2000 policies page. When you select a policy in the Windows 2000 page, it supercedes any selections made on the General tab. The policies are not merged, and only the platform-specific policy is used. For example, if the Workstation Import policy is selected in the General tab and in the Windows 2000 tab, agents on a Windows 2000 system use the Windows 2000 Workstation Import policy rather than the policy in the General tab.

Windows XP Policies

Within the policies tab, you can select the Windows XP policy page. This page displays the policies that are available for Windows XP workstations. These policies include the Computer Extensible Policies, the Novell iPrint Policy, the Remote Control Policy, the Windows Group Policy, the Workstation Imaging Policy, the Workstation Inventory, and the ZENworks for Desktops Agent Policy. See Figure 9.4 for a sample of the Windows XP policies page.

Figure 9.4. Workstation Policy Package, Windows XP policies property page.

graphics/09fig04.jpg

As you can see, the same policies are on the General and the Windows XP policies page. When you select a policy in the Windows XP page, it supercedes any selections made on the General tab. The policies are not merged, and only the platform-specific policy is used. For example, if the Workstation Import policy is selected in the general tab and in the Windows XP tab, agents on a Windows 2000 system use the Windows XP Workstation Import policy rather than the policy in the General tab.

WindowsNT-2000-XP Policies

The WindowsNT-2000-XP tab provides backward-compatibility for workstations using previous versions of ZENworks. If you need to set policies for workstations that are using versions of ZENworks previous to ZENworks for Desktop 4, you need to set these policies using the WindowsNT-2000-XP tab.

Associations Property Page

The Associations page of the Workstation Policy Package displays all of the locations in the tree (containers) where the policy package has been associated. These associations do not necessarily reflect where the policy package is located in the directory. The agents that are associated with users or workstations that are in or below those containers have this policy package enforced. Choosing the Add or Remove buttons enables you to add or remove containers in the list that are associated with this policy.

NDS Rights Property Pages

The NDS Rights Property page is made up of three sections. You can get to each of the pages by clicking on the small triangle to the right of the page name, and then selecting the desired page to be displayed.

These pages enable you to specify the rights that users have to this object in the directory. The following subsections discuss briefly each of these pages. These NDS Rights pages are displayed for every object in the tree.

Trustees of This Object Page

On this page, you can assign objects rights as trustees of the Workstation Policy Package. These trustees have rights to this object or to attributes within this object.

If user admin.novell has been added to the trustee list, this user has some rights to this object. To get into the details of any trustee assignment (in order to modify the assignment), you need to choose the Assigned Rights button.

When you press the Assign Rights button, you are presented with a dialog box that enables you to select [All Attribute Rights] (meaning all of the attributes of the object) or [Entry Rights] (meaning the object, not implying rights to the attributes).

From within the Assigned Rights dialog box, you can set the rights the object can have on this package. You can set those rights on the object as well as any individual property in the object. The rights that are possible are the following:

  • Browse Although not in the list, this right shows up from time to time (especially in the effective rights screens). This right represents the capability to view this information through public browse capabilities.

  • Supervisor This right identifies that the trustee has all rights, including delete, for this object or attribute.

  • Compare This right provides the trustee with the capability to compare values of attributes.

  • Read This right enables the trustee to read the values of the attribute or attributes in the object.

  • Write This right provides the trustee with the capability to modify the contents of an attribute.

  • Add Self This right enables the trustee to add him or herself as a member to the list of objects of the attribute. For example, if this right were given on an attribute that contains a list of linked objects, the trustee could add him or herself (a reference to their object) to the list.

If you want to add the object as a trustee to an attribute, you need to press the Add Property button to access a list of properties or attributes that are available for this object.

From this list, you can select a single attribute. This attribute is then displayed in the Assigned Rights dialog box. From there, you can select the attribute and then set the rights you want the trustee to have for that property. A user does not require object rights in order to have rights on a single attribute in the object.

Remember that rights flow down in the tree, and if you give a user or an object rights at a container level, those rights continue down into that container and any sub-containers until that branch is exhausted, or until another explicit assignment is given for that user in a sub-container or on an object. An explicit assignment changes the rights for the user at that point in the tree. You can also use inherited rights filters to restrict this flow of rights down into the tree.

Inherited Rights Filters Page

This page enables you to set the IRF (Inheritance Rights Filter) for this object. This filter restricts the rights of any user who accesses this object, unless that user has an explicit trustee assignment to this object.

You can think of the IRF as a filter that lets only items checked pass through unaltered. Rights that bump up against an IRF filter are blocked and discarded if the item is not checked. For example, consider a user who has write privileges inherited at some point above the current container (they were explicitly granted that right at some container at or above the one they're in). This user runs into an IRF for an object or attribute that has the write privilege revoked (that is, unchecked). When the user gets to that object, his write privilege is gone for that object. If the object is a container, the user loses write privileges for all objects in that container or sub-container.

You can effectively remove supervisor privileges from a portion of the tree by setting an IRF with the supervisor privilege turned off. You must be careful to not do this without someone being assigned as the supervisor of that branch of the tree. Otherwise, you won't be able to delete any objects in that branch of the tree. ConsoleOne helps prevent you from performing this action by giving you an error dialog box. You cannot put an IRF on the [Entry Rights] of the object without having first given an explicit supervisor assignment on the same container.

Effective Rights Page

The Effective Rights property page enables you to query the system to discover the rights that selected objects have on the object you are administering.

Within this page you are presented with the Distinguished Name (DN) of the object whose rights you want to observe. Initially, this is your currently logged-in user running ConsoleOne. You can use the browse button to the right of the trustee field to browse throughout the tree and select any object.

When the trustee object is selected, you can then move to the properties table on the lower half of the screen. As you select the property, the rights box changes to reflect the rights that the trustee has on that property. These rights may be via an explicit assignment or through inheritance.

Other Property Page

This page might not be displayed for you, depending on your rights to the plug-in that now comes with ConsoleOne. This page is particularly powerful. People who do not have an intimate knowledge of the schema of the object in question and its relationships with other objects in the directory should avoid using this page. The intention of this property page is to give you generic access to properties that you cannot modify or view via the other plugged-in pages. The attributes and their values are displayed in a tree structure, enabling those attributes that have multiple types (are compound types that consist of, say, an integer and a distinguished name or postal code that has three separate address fields).

Every attribute in eDirectory is defined by one of a specified set of syntaxes. These syntaxes identify how the data is stored in eDirectory. For this page, ConsoleOne has developed an editor for each of the syntaxes that are currently available in eDirectory. When an attribute is displayed on this page, the editor displays the data and then modifies it should the user click the specific attribute.

For example, if the syntax for an attribute were a string or an integer, an in-line editor is launched, enabling the administrator to modify the string or the integer value on the screen. More abstract syntaxes, such as octet-string, require that an octet editor be launched, thus giving the administrator access to each of the bytes in the string, without interpretation of the data.

The danger with this screen is that some applications require that there be a coordination of attribute values between two attributes within the same object or across multiple objects. Additionally, many applications assume that the data in the attribute is valid, because the normal user interface checks for invalid entries and does not allow them to be stored in the attribute. If you should change a data value in the other page, no knowledge of related attributes, objects, or valid data values are checked, because the generic editors know nothing about the intention of the field. Should you change a value without making all the other appropriate changes, some programs and the system could be affected.

Rights are still in effect in the Other property page and you are not enabled to change any attribute values that are read-only or that you do not have rights to modify.

Rights to Files and Folders Property Page

This page in the property book is present in all objects in the directory. This property page enables you to view and set rights for this object on the volumes and specific files and folders on that volume.

You must first select the volume that contains the files and folders in which you are interested. You can do this by pressing the Show button on the right and then browsing the directory to the volume object. Selecting the volume object places it in the volumes view. When that volume is selected you can use the Add button to add a file or folder of interest. This brings up a dialog box enabling you to browse to the volume object; then clicking on the volume object moves you into the file system. You can continue browsing that volume until you select the file or directory to which you are interested in granting rights.

Selecting the file or folder in the lower pane displays the rights that the object has been granted on that file or folder. To modify the rights, simply select the rights that you want to have explicitly granted for the object.

You can also view the effective rights that the object has on the files by pressing the Effective Rights button. This displays a dialog box, enabling you to browse to any file in the volume. The object's effective rights are displayed (in bold). These effective rights include any explicit and inherited rights from folders higher in the file system tree. Remember that anyone who has supervisor rights to the server or volume objects automatically gets supervisor rights in the file system.



Novell's ZENworks for Desktops 4. Administrator's Handbook
Novell ZENworks for Desktops 4 Administrators Handbook
ISBN: 0789729857
EAN: 2147483647
Year: 2003
Pages: 198
Authors: Brad Dayley

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net