NetWare 4.1/9000 Concepts
1-186
NetWare Glossary
S
You can assign and change passwords, or assign initial passwords and allow
users to change them. To increase login security, consider requiring these
password options:
• Minimum password length. Prevents the use of passwords that might be easily
guessed. Default: 5 characters.
• Periodic change in the password. Prevents keeping a password indefinitely.
Default: every 90 days.
• Unique password. Prevents alternating between a few favorite passwords. The
server remembers and rejects the use of the eight passwords most recently used
for one day or longer.
Trustee security
A trustee is a User or Group object that has been granted access to a
directory, file, or object.
Access is granted through a trustee assignment. A trustee assignment says,
in effect, “This user can access this directory, file, or object in these ways.”
Any object with sufficient rights can make trustee assignments with the
“RIGHTS”, “NETADMIN”, or “NetWare Administrator” utilities.
• Trustee List. Each directory, file, and object has a list of trustee assignments,
called a trustee list, that specifies who can access that directory, file, or object. An
object’s trustee list is stored in the object’s ACL property. A directory or files
trustee list is stored in the trustee data base of each NetWare volume.
• Trustees of groups. For several users to access a directory, file, or object, a trustee
assignment is required for each user. Rather than make trustee assignments for
each user, create a Group object, include the users in the group, and then grant
access for the group with one trustee assignment.
• [Public] trustee. [Public] is a special trustee that can be added to an object,
directory or file. The rights assigned to [Public] are effective for anyone who has
no rights to the file, directory, or object.
Rights security
Rights assigned to a NetWare Directory Services (NDS) object control the
access the NDS object has to directories, files, or other NDS objects.
Creating, reading, and other operations can be done only if an object has
rights to perform them.