
be separated by commas. If spaces are included, the entire list of permissions must be enclosed in
quotes.
l type - One of the following object types:
cert,cluster,crl,geocluster,geosite,port,server,srvpool,subnet,user,vlan.
l object_name - The name of an existing object of the
type
given on the command line.
For example, the following command executed in the global context assigns read and write permission to the
server sv00 for the existing login user1:
eqcli > user user1 permit_object read,write server sv00
Using permit_objlist to Assign User Permissions on a Group of Objects
The user context permit_objlist command has the following syntax for assigning read, write, and
delete permissions:
permit_objlist perm type objlist_name
This form of the permit_objlist command assigns the given permission (perm) on all objects of the specified
type that appear in the object list specified by objlist_name. The command arguments for assigning
permission to objects in an object list are as follows:
l perm - One or more of the following permissions: read, write, delete. Multiple permissions must be
separated by commas. If spaces are included, the entire list of permissions must be enclosed in quotes.
l type - One of the following object types: cert,cluster,
crl,geocluster,geosite,port,server,srvpool,subnet,user,vlan.
l objlist_name - The name of an existing object list.
For example, the following command executed in the global context assigns read and write permission to all of
the servers listed in the object list objlist1 for the login user1:
eqcli > user user1 permit_objlist read,write server objlist1
For more information on object lists, please see "Object List Commands" on page 163.
Using permit_objlist to Allow a User to Create Objects
The user context permit_objlist command has the following syntax for assigning the create permission to
a user:
permit_objlist create type {default | objlist_name}
184
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
Comentarios a estos manuales