314
Novell eDirectory 8.8 Administration Guide
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
The key concepts of proxy user anonymous binds are as follows:
• All LDAP client access through anonymous binds is assigned through the Proxy User object.
• Because LDAP clients do not supply passwords during anonymous binds, the Proxy User must
have a null password and must not have any password restrictions (such as password change
intervals). Do not force the password to expire or allow the Proxy User to change passwords.
• You can limit the locations that the user can log in from by setting address restrictions for the
Proxy User object.
• The Proxy User object must be created in eDirectory and assigned rights to the eDirectory
objects you want to publish. The default user rights provide Read access to a limited set of
objects and attributes. Assign the Proxy User Read and Search rights to all objects and
attributes in each subtree where access is needed.
• The Proxy User object must be enabled on the General page of the LDAP Group object that
configures LDAP Services for eDirectory. Because of this, there is only one Proxy User object
for all servers in an LDAP group. For more information, see
Section 13.4, “Configuring LDAP
Objects,” on page 340
.
• You can grant a Proxy User object rights to All Properties (default) or Selected Properties.
To give the Proxy User rights to only selected properties:
1
In Novell iManager, click the
Roles and Tasks
button
.
2
Click
Rights
>
Modify Trustees
.
3
Specify the name and context of the top container the Proxy User has rights over, or click
to browse to the container in question, then click
OK
.
4
On the Modify Trustees screen, click
Add Trustee
.
5
Browse to and click the Proxy User's object, then click OK.
6
Click
Assigned Rights
to the left of the Proxy User you just added.
7
Check the
All Attributes Rights
and
Entry Rights
check boxes, then click
Delete Property
.
8
Click
Add Property
, then check the
Show All Properties in Schema
check box.
9
Select an inheritable right for the Proxy User, such as mailstop (in the lowercase section of the
list) or Title, then click
OK
.
To add additional inheritable rights, repeat Steps 9 and 10.
10
Click
Done
, then click
OK
.
To implement proxy user anonymous binds, you must create the Proxy User object in eDirectory and
assign the appropriate rights to that user. Assign the Proxy User Read and Search rights to all objects
and attributes in each subtree where access is needed. You also need to enable the Proxy User in
LDAP Services for eDirectory by specifying the same proxy username.
1
In Novell iManager, click the
Roles and Tasks
button
.
2
Click
LDAP
>
LDAP Overview
.
3
Click the name of an LDAP Group object to configure.
4
Specify the name and context of an eDirectory User object in the
Proxy User
field.
5
Click
Apply
, then click
OK
.
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...