role (nrcmd)						role (nrcmd)


NAME
    role - Configures a role

SYNOPSIS
    role <name> create <base-role> [<attribute>=<value>] 
    role <name> delete
    role list  
    role listnames
    role <name> show
    role <name> set =<value> [<attribute>=<value> ...]
    role <name> get <attribute>

    role <name> enable <attribute>
    role <name> disable <attribute>

DESCRIPTION
    The role command configures the specified role. A role describes
    the operations that an administrator can perform and any data
    constraints that should be applied. A role must be assigned to
    an administrator group to be associated with an administrator.

    The constaint property should be manipulated using the web UI.

EXAMPLES

STATUS

SEE ALSO
    group, admin
    
PROPERTIES
  Attributes:

    all-sub-roles[8] (AT_BOOL, Optional, default: true)
        Controls whether to ignore the sub-role attribute for this attribute.
        If this attribute is unset, or if it is set to true, then the server
        ignores the value of the sub-roles attribute and this subrole is
        authorized for all sub-roles.  If this attribute is false, then the
        sub-roles attribute provides the list of subroles for which this
        role instance is authorized.  If the unconstrained attribute
        is set to true, then the values of this attribute and the
        of the sub-roles attribute are ignored, and the sub-role
        authorization for the role is for all sub-roles.

    constraints[42] (AT_NLIST(AT_OBJ), Optional, default: <none>)
        The list of constraints for the role.

    groups[3] (AT_NLIST(AT_STRING), Optional, default: <none>)
        Lists the groups with which this role is associated.  Any member of
        a listed group can perform the operations that the role allows.

    name[1] (AT_STRING, Required, default: <none>)
        Identifies the name of this role.

    read-only[6] (AT_BOOL, Optional, default: false)
        Indicates that all constraints associated with this role are
        limited to read-only access.

    role[2] (AT_STRING, Optional, default: <none>)
        Specifies the base role for this object.  The base role defines
        operations, such as modifying a zone, that are allowed and
        the further constraints on these operations. For example,
        a constrained role could limit the list of zones to a specific
        list of Owners.

    sub-roles[7] (AT_NLIST(AT_STRING), Optional, default: <none>)
        Lists subroles associated with this role instance. If the
        all-sub-roles attribute is unset, or if it is set to true,
        then this attribute is ignored.  If the all-sub-roles
        attribute is set to false, then this attribute specifies
        the list of subroles for this role instance, and an administrator
        associated with this role has authorization limited to the
         specified subroles.  If the admininistrator has multiple roles
        in which the role attribute is the same, then subrole authorization
        for that role should be taken to be the union of all the sets of
        subroles from the individual role instances; and, if any of these
        role instances has the all-sub-roles attribute set to true,
        then subrole authorization for that role is for all sub-roles.
        Also, if any role instance for a matching role has the unconstrained
        attribute set to true, then subrole authorization for that role is
        for all subroles.

    unconstrained[5] (AT_BOOL, Optional, default: false)
        Indicates that this role has no other constraints beyond
        the list of operations it can perform.

