Configuring LDAP Services for Novell eDirectory
365
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
Create a partition boundary at the top of the authoritative area. An eDirectory server considers
itself authoritative for all data that it holds unless otherwise specified.
2
Mark the root partition as nonauthoritative.
2a
Add the authoritative attribute to the rootmost entry in the partition.
2b
Populate the authoritative attribute with a value of zero.
3
Draw a boundary at the bottom of the nonauthoritative area.
Create partition roots at the areas of the subtree that this server is to be authoritative for. For
example, in the figure above, a partition root exists at the OU=Sales entry. The new partitions
won't have the authoritative attribute set to zero. Therefore, the server will be authoritative for
the partitions.
4
Refresh the LDAP server.
The LDAP server caches the authoritative and nonauthoritative area boundaries whenever its
configuration is refreshed. If you don't manually refresh the server configuration, the server
will automatically refresh itself on a 30-minute background task.
Multiple partitions can be stacked in a chain of nonauthoritative areas. However, LDAP
Services for eDirectory 8.8 requires that all nonauthoritative partitions must be contiguous and
held in local replicas.
13.9.3 Specifying Reference Data
When the LDAP server finds that an operation is taking place in a nonauthoritative area, it looks for
information it can use to return a referral to the client. This referral information might be at one of
the following:
• Located on any or all of the entries in the nonauthoritative area
• Specified as a default referral on the LDAP Server or LDAP Group object that holds the
configuration data for the server
Referral information held on entries in the nonauthoritative area is an Immediate Superior
Reference. Such referral information consists of a multi-valued ref attribute. (For a description of
this attribute, see
RFC 3296 (http://www.ietf.org/rfc/rfc3296.txt)
. Referral information held in the
Default Referral configuration setting is a Superior Reference and is single-valued. (See immSupr
and supr DSE types in X.501.)
Reference data is held in the form of an LDAP URL, but only specifies the host and (optionally) the
port of the DSA being referred to. The following example illustrates this reference data:
ldap://ldap.digital_airlines.com:389
The LDAP server looks at the base DN for the operation (or if not found, the matched DN). If the
base DN contains reference information, the LDAP server returns that information as a referral.
If no reference information is found, the LDAP server traverses the tree upwards, looking for
reference information. If no reference information is found after exhausting all entries, the LDAP
server returns the superior reference. (This reference is held in the default referral setting on the
LDAP Group or LDAP Server object.)
Summary of Contents for EDIRECTORY 8.8 - GUIDE
Page 4: ...novdocx ENU 01 February 2006...
Page 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...