Ricoh InfoPrint Pro C900AFP InfoPrint Manager - Page 49

Security groups, helpdesk, Important, acl_admin, Administrator, myuserid, admin, Job Ticketer

Page 49 highlights

Security groups No matter what size organization you work in, manually adding every user to every ACL can be a time-consuming process. To reduce some of the work, you can create security groups, groups of users who need to have the same levels of permission for the same objects. You use the name of the security group like a user ID; instead of adding each user ID to an ACL, you add the group name. For example, if you want all of your help desk operators to be able to perform the same operations, create a group and name it helpdesk. Then, add helpdesk to the appropriate ACLs. Important: All fields, such as User IDs, group names, hostnames, and DNS suffixes, are case sensitive. When you install InfoPrint Manager, three security groups are created by default: v acl_admin- Users who have authority to manage security by changing access control lists and groups. The default members are Administrator@* and the user who was logged on when InfoPrint Manager was installed (for example, myuserid@*). v admin- Users who have administrator authority. The default members are Administrator@* and the user who was logged on when InfoPrint Manager was installed (for example, myuserid@*). v oper- Users who have operator authority. The default member is Administrator@*. Note: 1. If you have installed InfoPrint Job Ticketer as part of the Print-on-Demand feature, the Job Ticketer group is created. Unlike the other groups, there are no default users created during installation. See InfoPrint Job Ticketer: Administrator's Guide for more information. 2. You can modify these groups as needed. In the example above, you could have simply added the help desk operators to the default oper group and modified any permissions that weren't set to the level that you wanted them. 3. The default group members contain the wildcard character (*) for greater flexibility. See below for more information about wildcarding. If you do not want the Administrator user on other systems to be able to administer InfoPrint Manager, replace the * with the explicit address of the system that the InfoPrint Manager server is installed on, for example [email protected]. You can add users to multiple groups, but you cannot make one group a member of another group. For example, if you hire five new print operators, you might create a group for them called trainees, since you only want them to have limited permissions until they are finished with their training. When they finish their training, you cannot add trainees as a member of the operators group. You will have to add their user IDs to the operators group one at a time. In addition, you will have to either delete the trainees group or delete the members from it- otherwise those users will have conflicting levels of permission. When users are members of more than one group and each group has a different level of permission for a particular object, the most restrictive permission applies. In the example above, if you forgot to remove the new employees from the trainees group at the end of their training, they wouldn't be able to perform the tasks their job required- they would still be restricted. Chapter 7. Managing security 31

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426

Security groups
No matter what size organization you work in, manually adding every user to
every ACL can be a time-consuming process. To reduce some of the work, you can
create
security groups
, groups of users who need to have the same levels of
permission for the same objects. You use the name of the security group like a user
ID; instead of adding each user ID to an ACL, you add the group name. For
example, if you want all of your help desk operators to be able to perform the
same operations, create a group and name it
helpdesk
. Then, add
helpdesk
to the
appropriate ACLs.
Important:
All fields, such as User IDs, group names, hostnames, and DNS
suffixes, are case sensitive.
When you install InfoPrint Manager, three security groups are created by default:
v
acl_admin
- Users who have authority to manage security by changing access
control lists and groups. The default members are
Administrator
@* and the user
who was logged on when InfoPrint Manager was installed (for example,
myuserid@*
).
v
admin-
Users who have administrator authority. The default members are
Administrator
@* and the user who was logged on when InfoPrint Manager was
installed (for example,
myuserid@*
).
v
oper-
Users who have operator authority. The default member is
Administrator@*
.
Note:
1.
If you have installed InfoPrint Job Ticketer as part of the Print-on-Demand
feature, the
Job Ticketer
group is created. Unlike the other groups, there are
no default users created during installation. See
InfoPrint Job Ticketer:
Administrator's Guide
for more information.
2.
You can modify these groups as needed. In the example above, you could
have simply added the help desk operators to the default
oper
group and
modified any permissions that weren't set to the level that you wanted them.
3.
The default group members contain the wildcard character (*) for greater
flexibility. See below for more information about wildcarding. If you do not
want the Administrator user on other systems to be able to administer
InfoPrint Manager, replace the * with the explicit address of the system that
the InfoPrint Manager server is installed on, for example
.
You can add users to multiple groups, but you cannot make one group a member
of another group. For example, if you hire five new print operators, you might
create a group for them called
trainees
, since you only want them to have limited
permissions until they are finished with their training. When they finish their
training, you cannot add
trainees
as a member of the
operators
group. You will
have to add their user IDs to the operators group one at a time. In addition, you
will have to either delete the
trainees
group or delete the members from it—
otherwise those users will have conflicting levels of permission.
When users are members of more than one group and each group has a different
level of permission for a particular object, the most restrictive permission applies.
In the example above, if you forgot to remove the new employees from the
trainees
group at the end of their training, they wouldn't be able to perform the
tasks their job required- they would still be restricted.
Chapter 7. Managing security
31