![Netscape NETSCAPE DIRECTORY SERVER 6.02 Скачать руководство пользователя страница 124](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673124.webp)
Creating and Maintaining Database Links
124
Netscape Directory Server Administrator’s Guide • May 2002
Setting this attribute to on in the
cn=default instance config,cn=chaining
database,cn=plugins,cn=config
entry means that all new database link
instances will have the
nsCheckLocalACI
attribute set to on in their
cn=
database_link_name
,cn=chaining database,cn=plugins,cn=config
entry.
Creating Client ACIs
Because you have enabled local ACI evaluation, you need to create the appropriate
client application ACIs on all intermediate database links as well as the final
destination database.
To do this on the intermediate database links, you first need to create a database
that contains a suffix that represents a root suffix of the final destination suffix.
For example, if you are chaining a client request made to the
c=africa,ou=people,dc=example,dc=com
suffix on a remote server, all
intermediate database links need to contain a database associated with the
dc=example,dc=com
suffix.
You then need to add any client ACIs to this superior suffix entry. For example,
you might add the following
aci: (targetattr = "*")(version 3.0; acl "Client authentication for
database link users"; allow (all) userdn = "ldap:///uid=*
,cn=config";)
This ACI allows client applications that have a
uid
in the
cn=config
entry of
server one to perform any type of operation on the data below the
ou=people,dc=example,dc=com
suffix on server three.
Detecting Loops
An LDAP control included with Directory Server prevents loops. When first
attempting to chain, the server sets this control to be the maximum number of
hops, or chaining connections, allowed. Each subsequent server decrements the
count. If a server receives a count of 0 it determines that a loop has been detected
and notifies the client application.
The number of hops allowed is defined using the
nsHopLimit
attribute. If not
specified, the default value is 10.
To use the control, add the following OID to the
nsTransmittedControl
attribute
in the
cn=config,cn=chaining database,cn=plugins,cn=config
entry:
nsTransmittedControl: 1.3.6.1.4.1.1466.29539.12
If the control is not present in the configuration file of each database link, loop
detection will not be implemented.
Содержание NETSCAPE DIRECTORY SERVER 6.02
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Страница 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 40: ...Starting the Server in Referral Mode 40 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 258: ...Compatibility with Earlier Releases 258 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 274: ...Setting Resource Limits Based on the Bind DN 274 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 330: ...Solving Common Replication Conflicts 330 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 374: ...Attribute Name Quick Reference Table 374 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 390: ...Configuring LDAP Clients to Use SSL 390 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 412: ...Monitoring Database Link Activity 412 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 502: ...Storing Information in Multiple Languages 502 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 522: ...Searching an Internationalized Directory 522 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...