Ricoh InfoPrint Pro C900AFP InfoPrint Manager - Page 144

Security groups, Reorder Job, admin, Security-ACL, Operations, Delete, acl_admin, administrator, Notes

Page 144 highlights

For operations, there is only one level of permission: read. If a user has read permission, they can do that action; if he does not, he cannot do the action. For example, userB is a printer operator and must be able to move jobs to different positions in the print queue because some jobs need to be printed before others. You can give userB read permission for the operation Reorder Job to allow him to do his job. On the other hand, userC submits print jobs from his office workstation and does not like to wait for the jobs ahead of his in the queue to print. If you want to prevent him from moving jobs, do not put him on the ACL for the Reorder Job operation. When he tries to move his job to the top of the queue, the action will be denied. When you install InfoPrint Manager, many operations are already protected so that only members of the admin and oper groups can do them. You can see the ACLs for operations in the Management Console by selecting the Security-ACLOperations item in the left pane. If you want users to be able to do those operations, you must either add those users to the individual ACLs or to a group that has permission (either the existing admin and oper groups or a new group that you create). Note: If an object is protected, a user can only do an operation on that object if he has both read permission for the operation and the appropriate level of permission for the object. If the object is not protected, only users in the default admin or oper groups are able to do the action. If a user is added to a non-standard group, they are not able to do the action unless they are the owner of the job in question. If the object has an ACL the permission needed depends on the operation. For example, List requires read, Set requires write, and Delete requires delete. Security groups No matter what size organization you work in, manually adding every user to every ACL can be a time-consuming process. To reduce some of the work, you can create security groups, groups of users who need to have the same levels of permission for the same objects. You use the name of the security group like a user ID; instead of adding each user ID to an ACL, you add the group name. For example, if you want all ten of your print operators to be able to perform the same operations, create a group and name it operators. Then, add operators to the appropriate ACLs. When you install InfoPrint Manager, three security groups are created by default: v acl_admin Users who have authority to manage security by changing access control lists and groups. The default members are administrator and the user who was logged on when InfoPrint Manager was installed. v admin Users who have administrator authority. The default members are administrator and the user who was logged on when InfoPrint Manager was installed. v oper Users who have operator authority. The default member is administrator. Notes: 1. There is another security group called JobTicketer that is created if you have installed InfoPrint Job Ticketer as part of the Print-on-Demand feature. Unlike 130 InfoPrint Manager for AIX: Procedures

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418

For operations, there is only one level of permission:
read
. If a user has
read
permission, they can do that action; if he does not, he cannot do the action. For
example, userB is a printer operator and must be able to move jobs to different
positions in the print queue because some jobs need to be printed before others.
You can give userB
read
permission for the operation
Reorder Job
to allow him to
do his job. On the other hand, userC submits print jobs from his office workstation
and does not like to wait for the jobs ahead of his in the queue to print. If you
want to prevent him from moving jobs, do not put him on the ACL for the
Reorder Job
operation. When he tries to move his job to the top of the queue, the
action will be denied.
When you install InfoPrint Manager, many operations are already protected so that
only members of the
admin
and
oper
groups can do them. You can see the ACLs
for operations in the Management Console by selecting the
Security-ACL-
Operations
item in the left pane. If you want users to be able to do those
operations, you must either add those users to the individual ACLs or to a group
that has permission (either the existing admin and oper groups or a new group
that you create).
Note:
If an object is protected, a user can only do an operation on that object if he
has both
read
permission for the operation and the appropriate level of permission
for the object. If the object is not protected, only users in the default admin or oper
groups are able to do the action. If a user is added to a non-standard group, they
are not able to do the action unless they are the owner of the job in question.
If the object has an ACL the permission needed depends on the operation. For
example,
List
requires read,
Set
requires write, and
Delete
requires delete.
Security groups
No matter what size organization you work in, manually adding every user to
every ACL can be a time-consuming process. To reduce some of the work, you can
create
security groups
, groups of users who need to have the same levels of
permission for the same objects. You use the name of the security group like a user
ID; instead of adding each user ID to an ACL, you add the group name. For
example, if you want all ten of your print operators to be able to perform the same
operations, create a group and name it
operators
. Then, add
operators
to the
appropriate ACLs.
When you install InfoPrint Manager, three security groups are created by default:
v
acl_admin
Users who have authority to manage security by changing access control lists
and groups. The default members are
administrator
and the user who was
logged on when InfoPrint Manager was installed.
v
admin
Users who have administrator authority. The default members are
administrator
and the user who was logged on when InfoPrint Manager was installed.
v
oper
Users who have operator authority. The default member is
administrator
.
Notes:
1.
There is another security group called
JobTicketer
that is created if you have
installed InfoPrint Job Ticketer as part of the Print-on-Demand feature. Unlike
130
InfoPrint Manager for AIX: Procedures