<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.open-xchange.com/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bob.meecham</id>
	<title>Open-Xchange - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.open-xchange.com/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bob.meecham"/>
	<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Special:Contributions/Bob.meecham"/>
	<updated>2026-10-03T04:03:53Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.7</generator>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Reseller_Bundle&amp;diff=25130</id>
		<title>Reseller Bundle</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Reseller_Bundle&amp;diff=25130"/>
		<updated>2019-12-03T16:52:22Z</updated>

		<summary type="html">&lt;p&gt;Bob.meecham: /* Initializing the restrictions */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Open-Xchange Reseller package =&lt;br /&gt;
&lt;br /&gt;
The reseller package introduces an additional layer of permissions, so called subadmins.&lt;br /&gt;
&lt;br /&gt;
* subadmins can be managed by the oxadminmaster account&lt;br /&gt;
* subadmins are oxadminmaster accounts with restricted rights:&lt;br /&gt;
** they can only manage contexts (no database, filestore, etc)&lt;br /&gt;
** they can only manage their own contexts (list/change/delete) &lt;br /&gt;
** they might be able to create further subadmins (see below)&lt;br /&gt;
&lt;br /&gt;
The corresponding documentation of restrictions available and what they do can&lt;br /&gt;
be found in the javadoc api documentation found in&lt;br /&gt;
/usr/share/doc/open-xchange-admin-reseller/javadoc/doc on Debian.&lt;br /&gt;
&lt;br /&gt;
== Restrictions ==&lt;br /&gt;
&lt;br /&gt;
These are basically the restrictions available:&lt;br /&gt;
&lt;br /&gt;
 Subadmin.MaxOverallUser&lt;br /&gt;
   - the maximum number of users a subadmin can create distributed over all it&#039;s&lt;br /&gt;
     contexts&lt;br /&gt;
&lt;br /&gt;
 Subadmin.MaxContext&lt;br /&gt;
   - the maximum number of contexts a subadmin can create&lt;br /&gt;
&lt;br /&gt;
 Context.MaxUser&lt;br /&gt;
   - the maximum number of users in a single context a contextadmin can create&lt;br /&gt;
     Note: this is a restriction, a subadmin can apply to each context&lt;br /&gt;
&lt;br /&gt;
 Subadmin.MaxOverallContextQuota&lt;br /&gt;
   - the maximum number of quota distributed over all contexts a subadmin&lt;br /&gt;
     can use&lt;br /&gt;
&lt;br /&gt;
 Subadmin.CanCreateSubadmin&lt;br /&gt;
   - Should this subadmin be able to create subsubadmins? This is NOT allowed by default.&lt;br /&gt;
     There&#039;s also only one additional level. &#039;&#039;&#039;Note:&#039;&#039;&#039; A subsubadmin cannot create any further&lt;br /&gt;
     subadmins.&lt;br /&gt;
&lt;br /&gt;
 Subadmin.MaxSubadmin&lt;br /&gt;
   - If a subadmin is allowed to create subsubadmins, should there be a maximum?&lt;br /&gt;
 &lt;br /&gt;
plus all the restrictions based on module access combinations as found in &lt;br /&gt;
/opt/open-xchange/etc/ModuleAccessDefinitions.properties&lt;br /&gt;
&lt;br /&gt;
{{InstallPlugin|version=6.22 or later|pluginname=open-xchange-admin-reseller|toplevel=products|sopath=appsuite/stable/backend}}&lt;br /&gt;
&lt;br /&gt;
== Setup and Configuration ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The reseller package requires additional tables in the configdb database&lt;br /&gt;
as well as the package open-xchange-admin-autocontextid to be installed.&lt;br /&gt;
&lt;br /&gt;
open-xchange-admin-autocontextid introduces the feature, that context ids&lt;br /&gt;
can no longer be specified and maintained by the system administrator, but are&lt;br /&gt;
now generated by open-xchange itself. This is a requirement since reseller&lt;br /&gt;
admins do not know, which context ids are already used.&lt;br /&gt;
&lt;br /&gt;
In OX App Suite version 7.10.1 and before you need to add those tables manually. In newer versions the tables are added automatically.&lt;br /&gt;
To add the new tables to the configdb, either run&lt;br /&gt;
&lt;br /&gt;
 $ mysql -u openexchange -p&amp;lt;YOURPW&amp;gt; configdb \&lt;br /&gt;
    &amp;lt; /opt/open-xchange/etc/mysql/reseller.sql&lt;br /&gt;
 $ mysql -u openexchange -p&amp;lt;YOURPW&amp;gt; configdb \&lt;br /&gt;
    &amp;lt; /opt/open-xchange/etc/mysql/autocid.sql&lt;br /&gt;
&lt;br /&gt;
or on a fresh setup, when running initconfigdb, add the following arguments:&lt;br /&gt;
&lt;br /&gt;
 $ /opt/open-xchange/sbin/initconfigdb --configdb-pass secret -a \&lt;br /&gt;
    --addon-sql &amp;quot;reseller.sql autocid.sql&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important: It is required to NOT set MASTER_AUTHENTICATION_DISABLED=true or CONTEXT_AUTHENTICATION_DISABLED=true in &amp;lt;tt&amp;gt;/opt/open-xchange/etc/AdminDaemon.properties&amp;lt;/tt&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Initializing the restrictions ==&lt;br /&gt;
&lt;br /&gt;
After the additional tables in the configdb have been created (may require restart), the restrictions&lt;br /&gt;
must be initialized. This can be done via RMI, SOAP or on commandline using&lt;br /&gt;
&lt;br /&gt;
 $ initrestrictions -A oxadminmaster -P secret&lt;br /&gt;
&lt;br /&gt;
== Manage subadmins ==&lt;br /&gt;
&lt;br /&gt;
Subadmin accounts can be managed via the create/change/deleteadmin commands&lt;br /&gt;
installed to /opt/open-xchange/sbin&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ /opt/open-xchange/sbin/createadmin -A oxadminmaster -P secret -u testadmin \&lt;br /&gt;
    -d &amp;quot;Test Subadmin&amp;quot; -p secret -a Subadmin.MaxContext=2000 \&lt;br /&gt;
    -a Subadmin.MaxOverallUser=2100 \&lt;br /&gt;
    -a Subadmin.MaxOverallUserByModuleaccess_webmail_plus=2010&lt;br /&gt;
&lt;br /&gt;
Would create a subadmin which is able to create max. 2000 contexts containing&lt;br /&gt;
max. 2100 users and of these users, max. 2010 can have the module access&lt;br /&gt;
combination webmail_plus.&lt;br /&gt;
&lt;br /&gt;
list it with&lt;br /&gt;
&lt;br /&gt;
 $ /opt/open-xchange/sbin/listadmin -A oxadminmaster -P secret&lt;br /&gt;
 Id Name      Displayname   Restrictions&lt;br /&gt;
 36 testadmin Test Subadmin Subadmin.MaxOverallUser=2100,Subadmin.MaxOverallUserByModuleaccess_webmail_plus=2010,Subadmin.MaxContext=2000&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Manage contexts ==&lt;br /&gt;
&lt;br /&gt;
When the reseller package has been installed, context listings contain&lt;br /&gt;
additional information such as the owner of the single contexts.&lt;br /&gt;
&lt;br /&gt;
 $ /opt/open-xchange/sbin/listcontext -A oxadminmaster -P secret&lt;br /&gt;
 cid fid fname       enabled qmax qused name        lmappings   CustomID         Owner&lt;br /&gt;
   1   3 1_ctx_store true     500     0 1                                        oxadminmaster&lt;br /&gt;
   2   3 2_ctx_store true     500     0 example.com example.com                  oxadminmaster&lt;br /&gt;
   3   3 3_ctx_store true     500     0 3                                        oxadminmaster&lt;br /&gt;
   4   3 4_ctx_store true     500     0 4                       a custom id 1234 testadmin    &lt;br /&gt;
&lt;br /&gt;
The subadmin called testadmin can only list it&#039;s own context(s):&lt;br /&gt;
&lt;br /&gt;
 $ /opt/open-xchange/sbin/listcontext -A testadmin -P secret&lt;br /&gt;
 cid fid fname       enabled qmax qused name lmappings CustomID         Owner    &lt;br /&gt;
   4   3 4_ctx_store true     500     0 4              a custom id 1234 testadmin&lt;br /&gt;
&lt;br /&gt;
== Using the SOAP Interface ==&lt;br /&gt;
&lt;br /&gt;
To use the soap interface, you need to install &amp;lt;tt&amp;gt;open-xchange-admin-soap-reseller&amp;lt;/tt&amp;gt; in addition.&lt;br /&gt;
&lt;br /&gt;
Due to the fact, that we cannot use the plugin mechanism we&#039;re using in Java to&lt;br /&gt;
extend the existing objects, the APIs and objects&lt;br /&gt;
&lt;br /&gt;
* OXContext&lt;br /&gt;
* OXGroup&lt;br /&gt;
* OXResource&lt;br /&gt;
* OXUser&lt;br /&gt;
* Context&lt;br /&gt;
&lt;br /&gt;
had to be wrapped into new APIs&lt;br /&gt;
&lt;br /&gt;
* OXResellerContext&lt;br /&gt;
* OXResellerGroup&lt;br /&gt;
* OXResellerResource&lt;br /&gt;
* OXResellerUser&lt;br /&gt;
* ResellerContext&lt;br /&gt;
&lt;br /&gt;
and the corresponding SOAP URLs&lt;br /&gt;
&lt;br /&gt;
* http://localhost/webservices/OXResellerContextService?wsdl&lt;br /&gt;
* http://localhost/webservices/OXResellerUserService?wsdl&lt;br /&gt;
* http://localhost/webservices/OXResellerGroupService?wsdl&lt;br /&gt;
* http://localhost/webservices/OXResellerResourceService?wsdl&lt;br /&gt;
&lt;br /&gt;
and of course the additional API to manage the subadmin accounts: &lt;br /&gt;
&lt;br /&gt;
* http://localhost/webservices/OXResellerService?wsdl&lt;br /&gt;
&lt;br /&gt;
That also means that the existing SOAP interfaces for the mentioned classes&lt;br /&gt;
above cannot be used anymore when installing the reseller package.&lt;br /&gt;
&lt;br /&gt;
ResellerContext just adds some additional members to the existing Context&lt;br /&gt;
object and the corresponding APIs just oberate on and return this wrapped&lt;br /&gt;
class.&lt;/div&gt;</summary>
		<author><name>Bob.meecham</name></author>
	</entry>
</feed>