In a small business where one DBA fills many roles, these parameters might be set to the same group name.
Similarly, you can group users based on roles defined in the deployment descriptor, and create corresponding entries in the LDAP server.
The assumption is that you'll begin to REVOKE privileges previously granted to individual user IDs (and/or to RACF—or equivalent—group IDs) as you phase in the use of roles and trusted contexts.
假设您将开始 REVOKE 以前在逐步使用角色和可信上下文期间授给个人用户 ID(和/或 RACF(或等效的)组 ID)特权。