
Configuring LDAP Services for Novell eDirectory
371
n
ov
do
cx (e
n)
11
Ju
ly 20
08
Historically, the eDirectory LDAP server sent the default referral in a number of failover situations.
Many users find these behaviors strange and sometimes unpredictable. LDAP Services for
eDirectory 8.8 let you control when the default referral is sent for any kind of subordinate referral.
The new option is a value (setting) held on the ldapDefaultReferralBehavior attribute on the LDAP
server and LDAP Group objects. The value is an integer which is a bitmask of the following bits.
If the LDAP server is configured to Always Refer for the operation, and if any of the conditions
listed are met and the corresponding value is set, the default referral is returned.
Setting Referrals for Search Operations
Functionality interacted to LDAP for eDirectory 8.7 causes referrals to behave slightly differently
than with earlier versions of eDirectory and NDS. The differences influence the way you configure
LDAP Services.
You can configure the eDirectory LDAP server to return referrals to other eDirectory servers within
the eDirectory tree. By default, the LDAP server chains all operations to other eDirectory servers on
behalf of the user, and referrals are never returned.
Prior to eDirectory 8.7, the referral options only existed as settings on the LDAP Group object. With
eDirectory 8.8 you can set these options on the LDAP server object also. Any setting on the LDAP
server object overrides that setting on the LDAP Group object.
You set the Referral Option by manipulating the ldapSearchReferralOption attribute. Previous to
LDAP Services for eDirectory 8.7, you could set this attribute to the following options:
“Prefer Chaining” on page 373
(the default option)
“Prefer Referrals” on page 373
“Always Refer” on page 374
These referral options apply only to referring and chaining to other eDirectory servers within the
eDirectory tree. These configuration settings don’t control referrals that come from a
nonauthoritative partition. Therefore, even though you select an option (for example, Always Chain)
from the Referral Options drop-down list, referrals will still come from nonauthoritative partitions to
other servers.
To support superior referrals to non-eDirectory DSAs, LDAP Services for eDirectory 8.7.a has an
Always Chain option. See
“Always Chain” on page 372
.
The following figure illustrates the LDAP referral drop-down lists for searches and other operations.
Bits
Value
0x00000001
The base DN is not found
0x00000002
The base DN is on an unavailable eDirectory server
0x00000004
An entry in the search scope is on an unavailable eDirectory
server
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...