
Understanding LDAP Services for Novell eDirectory
325
n
ov
do
cx (e
n)
11
Ju
ly 20
08
“Enabling Nonstandard Schema Output” on page 330
“Syntax Differences” on page 331
“Supported Novell LDAP Controls and Extensions” on page 332
13.2.1 Connecting to eDirectory from LDAP
All LDAP clients bind (connect) to Novell eDirectory as one of the following types of users:
[Public] User (Anonymous Bind)
Proxy User (Proxy User Anonymous Bind)
NDS or eDirectory User (NDS User Bind)
The type of bind the user authenticates with determines the content that the LDAP client can access.
LDAP clients access a directory by building a request and sending it to the directory. When an
LDAP client sends a request through LDAP Services for eDirectory, eDirectory completes the
request for only those attributes that the LDAP client has the appropriate access rights to.
For example, if the LDAP client requests an attribute value (which requires the Read right) and the
user is granted only the Compare right to that attribute, the request is rejected.
Standard login restrictions and password restrictions still apply. However, any restrictions are
relative to where LDAP is running. Time and address restrictions are honored, but address
restrictions are relative to where the eDirectory login occurred—in this case, the LDAP server.
Connecting As a [Public] User
An anonymous bind is a connection that does not contain a username or password. If an LDAP
client without a name and password binds to LDAP Services for eDirectory and the service is not
configured to use a Proxy User, the user is authenticated to eDirectory as user [Public].
User [Public] is a non-authenticated eDirectory user. By default, user [Public] is assigned the
Browse right to the objects in the eDirectory tree. The default Browse right for user [Public] allows
users to browse eDirectory objects but blocks user access to the majority of object attributes.
The default [Public] rights are typically too limited for most LDAP clients. Although you can
change the [Public] rights, changing them will give these rights to all users. Because of this, we
recommend that you use the Proxy User Anonymous Bind. For more information, see
“Connecting
As a Proxy User” on page 325
.
To give user [Public] access to object attributes, you must make user [Public] a trustee of the
appropriate container or containers and assign the appropriate object and attribute rights.
Connecting As a Proxy User
A proxy user anonymous bind is an anonymous connection linked to an eDirectory username. If an
LDAP client binds to LDAP for eDirectory anonymously, and the protocol is configured to use a
Proxy User, the user is authenticated to eDirectory as the Proxy User. The name is then configured in
both LDAP Services for eDirectory and in eDirectory.
The anonymous bind traditionally occurs over port 389 in LDAP. However, during the installation
you can manually configure different ports.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...