Advanced Feature: Configuring Cascading Chaining
83
Attribute
Description
nsFarmServerURL
URL of the server containing the next database
link in the cascading chain.
nsTransmittedControls
Enter the following OIDs to the database links
involved in the cascading chain:
nsTransmittedControls:
2.16.840.1.113730.3.4.12
nsTransmittedControls:
1.3.6.1.4.1.1466.29539.12
The first OID corresponds to the Proxy
Authorization Control. The second OID
corresponds to the Loop Detection Control.
aci
This attribute must contain the following ACI:
aci: (targetattr = "*")(version 3.0; acl
"Proxied
authorization for database links";
allow (proxy) userdn = "ldap:///cn=proxy
admin,cn=config";)
nsCheckLocalACI
To enable evaluation of local ACIs on all
database links involved in chaining, turn local
ACI evaluation on, as follows:
nsCheckLocalACI: on
Table 3.7. Cascading Chaining Configuration Attributes
3.3.7.7. Cascading Chaining Configuration Example
To create a cascading chain involving three servers as in the diagram below, the chaining components
must be configured on all three servers.
Summary of Contents for DIRECTORY SERVER 8.0
Page 18: ...xviii ...
Page 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Page 30: ...12 ...
Page 112: ...94 ...
Page 128: ...110 ...
Page 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Page 224: ...206 ...
Page 324: ...306 ...
Page 334: ...316 ...
Page 358: ...340 ...
Page 410: ...392 ...
Page 420: ...402 ...
Page 444: ...426 ...
Page 454: ...436 ...
Page 464: ...446 ...
Page 484: ...466 ...
Page 512: ...494 ...
Page 522: ...504 ...