![Netscape NETSCAPE DIRECTORY SERVER 6.02 Скачать руководство пользователя страница 130](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673130.webp)
Creating and Maintaining Database Links
130
Netscape Directory Server Administrator’s Guide • May 2002
Add the local proxy authorization ACI to the
c=africa,ou=people,dc=example,dc=coml
entry:
aci:(targetattr="*")(target="l=Zanzibar,c=africa,ou=people,
dc=example,dc=com")(version 3.0; acl "Proxied authorization for
database links"; allow (proxy) userdn = "ldap:///cn=server1 proxy
admin,cn=config";)
Then add the local client ACI that will allow the client operation to succeed on
server two given that ACI checking is turned on. This ACI is the same as the ACI
you will create on the destination server to provide access to the
l=Zanzibar,c=africa,ou=people,dc=example,dc=com
branch. You may decide
that you want all users within
c=us,ou=people,dc=example,dc=com
to have
update access to the entries in
l=Zanzibar,c=africa,ou=people,dc=example,dc=com
on server three. The
following ACI is the ACI you would need to create on the
c=africa,ou=people,dc=example,dc=com
suffix on server two to allow this:
aci:(targetattr="*")(target="l=Zanzibar,c=africa,ou=people,
dc=example,dc=com")(version 3.0; acl "Client authorization for
database links"; allow (all) userdn =
"ldap:///uid=*,c=us,ou=people,dc=example,dc=com";)
This ACI allows clients that have a uid in
c=us,ou=people,dc=example,dc=com
on server one to perform any type of operation on the
l=Zanzibar,c=africa,ou=people,dc=example,dc=com
suffix tree on server
three. Should you have users on server two under a different suffix that will
require additional rights on server three, you may need to add additional client
ACIs on server two.
Configuring Server Three
The final configuration step in our cascading chaining example is to configure
server three. First, you create an administrative user on server three for server two
to use for proxy authorization:
NOTE
To create these ACIs it is assumed that the database corresponding
to the
c=africa,ou=people,dc=example,dc=com
suffix already
exists to hold the entry. This database needs to be associated with a
suffix above the suffix specified in the
nsslapd-suffix
attribute of
each database link. That is, the suffix on the final destination server
should be a sub suffix of the suffix specified on the intermediate
server.
Содержание NETSCAPE DIRECTORY SERVER 6.02
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Страница 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 40: ...Starting the Server in Referral Mode 40 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 258: ...Compatibility with Earlier Releases 258 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 274: ...Setting Resource Limits Based on the Bind DN 274 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 330: ...Solving Common Replication Conflicts 330 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 374: ...Attribute Name Quick Reference Table 374 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 390: ...Configuring LDAP Clients to Use SSL 390 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 412: ...Monitoring Database Link Activity 412 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 502: ...Storing Information in Multiple Languages 502 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 522: ...Searching an Internationalized Directory 522 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...