
632
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
E.3.4 Editing Foreign Principals
You can add Kerberos principal names to the eDirectory users using iManager.
1
In iManager, click
Kerberos Management
>
Edit Foreign Principals
to open the Edit Foreign
Principals page.
2
Specify the FDN of a valid User object or use the
Object Selector
icon to select the User object
reference.
3
Click
OK
.
4
Specify the foreign principal names, then click
Add
Description: add
.
The principal name must be in the format principalname@
REALMNAME
.
To delete the foreign principal name, select the name and then click Delete
Description:
remove
.
5
Click
OK
.
E.4 Creating a Login Sequence
For information on creating a login sequence, refer to the Managing Login Sequences section in the
NMAS 3.0 Administration Guide
(http://www.novell.com/documentation/beta/nmas30/
index.html?page=/documentation/beta/nmas30/admin/data/a49tuwk.html#a4)
.
E.5 How Does LDAP Use SASL-GSSAPI?
Once you have configured SASL-GSSAPI, it is added along with the other SASL methods to the
supportedSASLMechanisms attribute in rootDSE.
The LDAP server queries SASL for the installed mechanisms when it gets its configuration, and
automatically supports whatever is installed. The LDAP server also reports the current supported
SASL mechanisms in its rootDSE by using the supportedSASLMechanisms attribute.
Therefore, once you configure GSSAPI, it becomes the default mechanism.
However, to specifically do an LDAP operation over the SASL GSSAPI mechanism, you can
mention GSSAPI at the commandline.
For example, in OpenLDAP to do a search using the GSSAPI mechanism, enter the following:
ldapsearch -Y GSSAPI -h 164.99.146.48 -b "" -s base
E.6 Error Messages
The SASL-GSSAPI error messages are logged into the following locations:
Linux and UNIX:
ndsd.log
For more information, refer to “
Error Messages
” in the
eDirectory 8.8 Troubleshooting Guide
(http:/
/www.novell.com/documentation/edir88/index.html)
.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...