Understanding LDAP Services for Novell eDirectory
315
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
Using the ldapconfig Utility on Linux and UNIX
For example, LDAP Search Referral Usage specifies how the LDAP server processes LDAP
referrals.
1
At a system prompt, enter the following command:
ldapconfig -s “LDAP:otherReferralUsage=1”
2
Enter the User FDN (Fully Distinguished eDirectory Username) and password.
Connecting As an NDS or eDirectory User
An eDirectory user bind is a connection that an LDAP client makes using a complete eDirectory
username and password. The eDirectory user bind is authenticated in eDirectory, and the LDAP
client is allowed access to any information the eDirectory user is allowed to access.
The key concepts of eDirectory user binds are as follows:
• eDirectory user binds are authenticated to eDirectory using the username and password entered
at the LDAP client.
• The eDirectory username and password used for LDAP client access can also be used for
NetWare client access to eDirectory.
• With non-TLS connections, the eDirectory password is transmitted in clear text on the path
between the LDAP client and LDAP Services for eDirectory.
• If clear text passwords are not enabled, all eDirectory bind requests that include a username or
password on non-TLS connections are rejected.
• If an eDirectory user password has expired, eDirectory bind requests for that user are rejected.
Assigning eDirectory Rights for LDAP Clients
1
Determine the type of username the LDAP clients will use to access eDirectory:
• [Public] User (Anonymous Bind)
• Proxy User (Proxy User Anonymous Bind)
• NDS User (NDS User Bind)
See
“Connecting to eDirectory from LDAP” on page 313
for more information.
2
If users will use one proxy user or multiple eDirectory usernames to access LDAP, use
iManager to create these usernames in eDirectory or through LDAP.
3
Assign the appropriate eDirectory rights to the usernames that LDAP clients will use.
The default rights that most users receive provide limited rights to the user’s own object. To provide
access to other objects and their attributes, you must change the rights assigned in eDirectory.
When an LDAP client requests access to an eDirectory object and attribute, eDirectory accepts or
rejects the request based on the LDAP client’s eDirectory identity. The identity is set at bind time.
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...