
l This form of the permit_objlist command allows the user to create objects of the specified type.
The command arguments for assigning permission to objects in an object list are as follows:
l type - One of the following object types: cert,cluster,crl,geocluster,geosite,port,server,
srvpool,subnet,user,vlan.
l default - Specifies that objects created by this user will only be visible to the user creating the object
and any user with the admin flag set.
l objlist_name - Specifies that the user can supply the given object list name as an argument when
creating objects of the specified type. An entry for the created object is placed in the object list. Objects
created in this manner will be visible to other users who have permission to use this object list.
For example, the following command executed in the global context allows user1 to create servers that other non-
admin users cannot access:
eqcli > user user1 permit_objlist create server default
The following command allows user1 to create servers and specify the objlist1 object list when creating a
server, thus adding the new server to objlist1:
eqcli > user user1 permit_objlist create server objlist1
User Permissions Assigned on Object Creation
When an object is created, the user creating the object is given read, write, and delete permissions for the
object.
Displaying User Information
In the user context, a show command displays the user settings for duration and flags, followed by the user
permission list.
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
185
Equalizer Administration Guide
Comentarios a estos manuales