![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 134](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675134.webp)
Creating and Maintaining Database Links
134
Netscape Directory Server Administrator’s Guide • August 2002
Add the local proxy authorization ACI to the
c=africa,ou=people,dc=example,dc=coml
entry:
aci:(targetattr="*")(target="l=Zanzibar,c=africa,ou=people,
dc=example,dc=com")(version 3.0; acl "Proxied authorization for
database links"; allow (proxy) userdn = "ldap:///cn=server1 proxy
admin,cn=config";)
Then add the local client ACI that will allow the client operation to succeed on
server two given that ACI checking is turned on. This ACI is the same as the ACI
you will create on the destination server to provide access to the
l=Zanzibar,c=africa,ou=people,dc=example,dc=com
branch. You may decide
that you want all users within
c=us,ou=people,dc=example,dc=com
to have
update access to the entries in
l=Zanzibar,c=africa,ou=people,dc=example,dc=com
on server three. The
following ACI is the ACI you would need to create on the
c=africa,ou=people,dc=example,dc=com
suffix on server two to allow this:
aci:(targetattr="*")(target="l=Zanzibar,c=africa,ou=people,
dc=example,dc=com")(version 3.0; acl "Client authorization for
database links"; allow (all) userdn =
"ldap:///uid=*,c=us,ou=people,dc=example,dc=com";)
This ACI allows clients that have a uid in
c=us,ou=people,dc=example,dc=com
on server one to perform any type of operation on the
l=Zanzibar,c=africa,ou=people,dc=example,dc=com
suffix tree on server
three. Should you have users on server two under a different suffix that will
require additional rights on server three, you may need to add additional client
ACIs on server two.
Configuring Server Three
The final configuration step in our cascading chaining example is to configure
server three. First, you create an administrative user on server three for server two
to use for proxy authorization:
NOTE
To create these ACIs it is assumed that the database corresponding
to the
c=africa,ou=people,dc=example,dc=com
suffix already
exists to hold the entry. This database needs to be associated with a
suffix above the suffix specified in the
nsslapd-suffix
attribute of
each database link. That is, the suffix on the final destination server
should be a sub suffix of the suffix specified on the intermediate
server.
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...