Accessing and Modifying Server Configuration32 Red Hat Directory Server Configuration, Command, and File Reference • May 2005Accessing and Modifying Server ConfigurationThis section discusses access control for configuration entries and describes thevarious ways in which the server configuration can be viewed and modified. Italso covers restrictions to the kinds of modification that can be made anddiscusses attributes that require the server to be restarted for changes to takeeffect.• Access Control for Configuration Entries• Changing Configuration AttributesAccess Control for Configuration EntriesWhen the Directory Server is installed, a default set of access control instructions(ACIs) is implemented for all entries under cn=config. Code Example 2-3 showsan example of these default ACIs.Code Example 2-3 Default ACIs in dse.ldifThese default ACIs allow all LDAP operations to be carried out on allconfiguration attributes by the following users:• Members of the Configuration Administrators Group.aci: (targetattr = "*")(version 3.0; acl "ConfigurationAdminstrators Group"; allow (all)groupdn = "ldap:///cn=Configuration Administrators,ou=Groups,ou=TopologyManagement, o=NetscapeRoot";)aci: (targetattr = "*")(version 3.0; acl "ConfigurationAdminstrator"; allow (all)userdn = "ldap:///uid=admin,ou=Administrators,ou=TopologyManagement, o=NetscapeRoot";)aci: (targetattr = "*")(version 3.0; acl "Local DirectoryAdminstrators Group"; allow (all)groupdn = "ldap:///ou=Directory Administrators,dc=example,dc=com";)aci: (targetattr = "*")(version 3.0; acl "SIE Group"; allow(all)groupdn = "ldap:///cn=slapd-phonebook, cn=Red Hat DirectoryServer, cn=Server Group, cn=phonebook.example.com,dc=example,dc=com, o=NetscapeRoot";)