30
OES 2 SP1: Novell iFolder 3.7 Administration Guide
no
vd
ocx
(e
n)
13
Ma
y 20
09
If the user is moved to a different container that is not specified as a Search DN before the user
is moved, the user is removed from the iFolder user list. The user’s iFolders are orphaned and
the user is removed as a member of iFolders owned by others. If the new container is later
added as a Search DN, the user is treated as a new user, with no association with previous
iFolders and memberships.
If the user appears in multiple defined Search DNs, and if one or more DNs are removed from
the LDAP settings, the user remains in the iFolder user list if at least one DN containing the
user remains.
If the user is deleted from LDAP or moved from all defined Search DNs, the user is removed as
an iFolder user. The user’s iFolders are orphaned and the user is removed as a member of
iFolders owned by others.
The iFolder Admin user and iFolder Proxy user are tracked by their GUIDs, whether their user
objects are in a context in the Search DN or not.
2.5.3 Synchronizing LDAPGroup Accounts with LDAP
You can specify any existing containers and groups in the Search DNs field of the iFolder LDAP
settings. Based on the Search DNs, LDAPGroups are automatically provisioned with accounts for
iFolder services.
The list of LDAPGroup is updated periodically when the LDAP synchronization occurs. New
LDAPGroups are added to the list of iFolder users. Deleted LDAPGroups are removed from the list
of iFolder users. (This might create orphaned iFolders if the deleted LDAPGroup owned any
iFolders). If by mistake LDAPGroup is deleted from the LDAP, you can create that LDAPGroup
again with the same FDN within the
Delete member grace interval
so that you can recover the user’s
iFolders. For more information on this, see
Step 7 on page 133
in the
“Accessing and Viewing the
Server Details Page” on page 132
.
IMPORTANT:
Whenever you move a LDAPGroup between contexts and you want to provide
continuous service for the LDAPGroup, make sure to add the target context to the list of LDAP
Search DNs before you move the LDAPGroup object in eDirectory.
The LDAP synchronization tracks a LDAPGroup object’s eDirectory
TM
GUID to identify the
LDAPGroup in multiple contexts. It tracks as you add, move, or relocate LDAPGroup objects, or as
you add and remove contexts as Search DNs.
The following guidelines apply:
If the LDAPGroup is added to an LDAP container, group, or LDAPGroup that is in the Search
DN, the LDAPGroup is added automatically to the iFolder LDAPGroup list.
Any changes to the LDAPGroup member list are automatically synchronized during next
synchronization cycle.
If a LDAPGroup is moved to a different container, and the new container is also in the Search
DN, the LDAPGroup remains in the iFolder LDAPGroup list.
If you intend to keep the LDAPGroup as an iFolder LDAPGroup without interruption of
service and loss of memberships and data, the new container must be added as a Search DN
before the LDAPGroup is moved.
Summary of Contents for IFOLDER 3.7 - SECURITY ADMINISTRATION
Page 12: ...12 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 24: ...24 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 38: ...38 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 98: ...98 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 100: ...100 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 102: ...102 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 162: ...162 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 168: ...168 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 172: ...172 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 182: ...182 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 184: ...184 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 196: ...196 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 202: ...202 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 216: ...216 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...