366
Novell eDirectory 8.8 Administration Guide
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
Adding an Immediate Superior Reference
You can add an auxiliary object class called immeditateSuperiorReference to an entry in the
nonauthoritative area. This auxiliary class adds a ref attribute, which is populated with one or more
LDAP URLs. Each URL points to a DSA’s host name and (optionally) port.
Adding a Superior Reference
Historically, the LDAP Group object has had an ldapReferral attribute. This attribute held a default
reference that was used for various failover situations when returning referrals to other eDirectory
servers in an eDirectory tree. In LDAP Services for eDirectory 8.8, this attribute is used to hold a
single default referral to a superior DSA in a federated tree.
Additionally, the ldapReferral attribute has been added to the LDAP Server object. If the
ldapReferral attribute contains a value on the LDAP Server object, that setting overrides the value
held in the same attribute on the LDAP Group object. This behavior allows you to configure all
LDAP servers participating in a group to have a particular default referral, while one or two servers
override that value with a different default referral.
The value on the ldapReferral attribute is an LDAP URL. The URL holds the host and optional port
of the DSA being referred to.
13.9.4 Updating Reference Information through LDAP
If you followed the steps above, in order, and used LDAP to perform the tasks, you were likely
unable to add an immediate superior reference. This is because the root partition had already been
marked nonauthoritative, so LDAP sends referrals for any operation acting on data within that
partition.
To update or interrogate information in a nonauthoritative area, the ManageDsaIT control must
accompany the LDAP request. For information on this control, see
RFC 3296 (http://www.ietf.org/
rfc/rfc3296.txt)
. This control effectively causes the LDAP server to treat the entire nonauthoritative
area as though it is authoritative.
NOTE:
The superior reference feature is only available through LDAP. Other protocols (for
example, NDAP) are not affected by the presence of the authoritative attribute. Therefore, the use of
ConsoleOne or Novell iManager to interrogate and update data in the nonauthoritative area is
unhindered.
13.9.5 Affected Operations
Nonauthoritative areas and superior referrals affect the following LDAP operations:
• Search and Compare
• Modify and Add
DN-syntax attribute values are not checked. Therefore, a group member attribute can contain
DNs that point to entries in a nonauthoritative area.
• Delete
• Rename (moddn)
• Move (moddn)
Summary of Contents for EDIRECTORY 8.8 - GUIDE
Page 4: ...novdocx ENU 01 February 2006...
Page 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...