Unsupported content This version of the documentation is no longer supported. However, the documentation is available for your convenience. You will not be able to leave comments.

How to set up a time-based ACL policy


The following example procedure illustrates the creation of an ACL policy (named acl-pol1) that normally has a limited set of permissions, based on role1 and authorization profile ap2. However, at certain scheduled times, the ACL policy has a more extensive set of permissions, based on role1 and authorization profile ap1.

Click the thumbnails to enlarge figures.

To set up a time-based ACL policy

  1. Create and save an authorization profile (named ap1 in this example) with a relatively extensive set of permissions that allows you to create and execute BLPackages.
    01.png02.png
  2. Create and save another authorization profile (named ap2) with a minimal set of permissions.
    03.png04.png
  3. Create and save a role (named role1) and assign both authorization profiles (ap1 and ap2) to it. Step through the wizard panes as in the following series of figures.
    05.png06.png07.png
    08.png09.png
  4. Create a user (named rbac-user1) and assign role1 to it.
    10.png11.png12.png
  5. Create an ACL policy (named acl-pol1). Associate it by default to role1 and ap2, and schedule a time window during which it will be associated with role1 and ap1.
    1. Define a name for the ACL policy (and optionally also a description).
      13.png
    2. Click + to add the role and the default authorizations from the ap2 authorization profile.
      14.png15.png
    3. Click Add under Time Window for scheduling additional time-based authorizations.
      16.png
    4. Set scheduling name, date and time as per your requirements.
      17.png
    5. Click the Permissions tab and then click + to select the app1 authorization profile for this scheduled time. Click OK after selecting the app1 authorization profile and then click OK again to save your settings on the Permissions tab.
      18.png19.png20.png
    6. Click Next and then Finish to complete the creation of the ACL policy.
      21.png22.png
  6. Apply permissions (ACL and ACL policy) on the relevant objects.
    23.png24.png25.png
    Repeat this process for all yours items (including, for example, depot groups, job groups, and servers).
  7. Log on as BLAdmin (or switch role to BLAdmins) and push Acl-Agents on the Target Machine.
    27.png28.png
    Repeat this process for all other relevant targets.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*