![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 115](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675115.webp)
Creating and Maintaining Database Links
Chapter
3
Configuring Directory Databases
115
3.
From the Object menu, select Delete.
You can also right-click the database link and select Delete from the pop-up
menu.
The Deleting Database Link confirmation dialog box is displayed.
4.
Click Yes to confirm that you want to delete the database link.
A progress dialog box appears telling you the steps the Directory Server
completes during the deletion.
Once deleted, the database link no longer appears in the right pane.
Database Links and Access Control Evaluation
When a user binds to a server containing a database link, the database link sends
the user’s identity to the remote server. Access controls are always evaluated on
the remote server. Every LDAP operation evaluated on the remote server uses the
original identity of the client application passed via the proxied authorization
control. Operations succeed on the remote server only if the user has the correct
access controls on the subtree contained on the remote server. This means that you
need to add the usual access controls to the remote server with a few restrictions:
•
You cannot use all types of access control.
For example, role based or filter based ACIs need access to the user entry.
Because you are accessing the data via database links, only the data in the
proxy control can be verified. Consider designing your directory in a way that
ensures the user entry is located in the same database as the user’s data.
•
All access controls based on the IP address or DNS domain of the client may
not work, as the original domain of the client is lost during chaining.
The remote server views the client application as being at the same IP address
and in the same DNS domain as the database link.
The following restrictions apply to the ACIs you create to use with database links:
•
ACIs must be located with any groups they use. If the groups are dynamic, all
users in the group must be located with the ACI and the group. If the group is
static, it may refer to remote users.
•
ACIs must be located with any role definitions they use and with any users
intended to have those roles.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...