|
This section describes the general behavior of the access control system, regardless of whether access control is enabled, or not.
- For external users, enabling of "access control" is optional
- The access control system can be enabled or disabled at any time, including:
- Initial application installation
- Later application use
- Access control applies to all users
- If enabled, all users will be limited by their group assignments
- If disabled, all users have free access to system resources
- Initial user accounts
- ACME will ship with two initial user accounts:
- Administrator
- Unknown User
- These two initial user accounts cannot be deleted
- Administrator account
- The Administrator user is in a group also named Administrator
- Regardless of whether security is enabled, there will always be an administrative user
- The administrator of external security will have the username "Administrator"
-
The password for this account is initially "admin"
-
A password for this account is mandatory
- The password for this account can be changed only by the Administrator
- The Administrator user account cannot be deleted or edited
- The Administrator group cannot be deleted or edited
- Unknown User account
- The Unknown User user is in a group named Unknown User
- The Unknown User user cannot be deleted or edited
- The Unknown Group group cannot be deleted or edited
- The Unknown Group group has full access to all functional areas other than User and Group management
- Users cannot log in as the user Unknown User when security is enabled
- CRUDing User Accounts
- The Administrator is the only user that can add, delete, and edit user account information
- All users can view usernames, group names, group members, and group rights without restriction.
- The Administrator can log in and use ACME, and has no security restrictions whatsoever.
Next: Access Control Requirements, Security
Up: External User Login and
Previous: External User Login and
  Contents
  Index
|
|