PreviousNext

Adding Members to the Namespace Authorization Group

To facilitate managing and troubleshooting your namespace, the cell configuration process creates a namespace authorization group under the fixed name subsys/dce/cds-admin. The configuration process then grants the group full access to the cell root directory. This access propagates to the entire namespace as it evolves.

Immediately after its creation, the authorization group contains only the name that the initial namespace administrator specified during the cell configuration process. You can use the dcecp program's group add command to add the principal names of other individuals in your organization who you want to administer and troubleshoot the namespace. Because this group possesses full access to the entire namespace, its members can intervene, whenever necessary, to solve problems for namespace users with fewer permissions. By removing a user's principal name from the group, the user described by that principal loses the access assigned to the group.

(See Part 6 of this guide for complete information on how to add and delete group members.)