
326
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
The key concepts of proxy user anonymous binds are as follows:
All LDAP client access through anonymous binds is assigned through the Proxy User object.
Because LDAP clients do not supply passwords during anonymous binds, the Proxy User must
have a null password and must not have any password restrictions (such as password change
intervals). Do not force the password to expire or allow the Proxy User to change passwords.
You can limit the locations that the user can log in from by setting address restrictions for the
Proxy User object.
The Proxy User object must be created in eDirectory and assigned rights to the eDirectory
objects you want to publish. The default user rights provide Read access to a limited set of
objects and attributes. Assign the Proxy User Read and Search rights to all objects and
attributes in each subtree where access is needed.
The Proxy User object must be enabled on the General page of the LDAP Group object that
configures LDAP Services for eDirectory. Because of this, there is only one Proxy User object
for all servers in an LDAP group. For more information, see
Section 14.4, “Configuring LDAP
Objects,” on page 354
.
You can grant a Proxy User object rights to All Properties (default) or Selected Properties.
To give the Proxy User rights to only selected properties:
1
In Novell iManager, click the
Roles and Tasks
button
Description: Roles and Tasks button
.
2
Click
Rights
>
Modify Trustees
.
3
Specify the name and context of the top container the Proxy User has rights over, or click
Description: Search button
to browse to the container in question, then click
OK
.
4
On the Modify Trustees screen, click
Add Trustee
.
5
Browse to and click the Proxy User's object, then click OK.
6
Click
Assigned Rights
to the left of the Proxy User you just added.
7
Check the
All Attributes Rights
and
Entry Rights
check boxes, then click
Delete Property
.
8
Click
Add Property
, then check the
Show All Properties in Schema
check box.
9
Select an inheritable right for the Proxy User, such as mailstop (in the lowercase section of the
list) or Title, then click
OK
.
To add additional inheritable rights, repeat Steps 9 and 10.
10
Click
Done
, then click
OK
.
To implement proxy user anonymous binds, you must create the Proxy User object in eDirectory and
assign the appropriate rights to that user. Assign the Proxy User Read and Search rights to all objects
and attributes in each subtree where access is needed. You also need to enable the Proxy User in
LDAP Services for eDirectory by specifying the same proxy username.
1
In Novell iManager, click the
Roles and Tasks
button
Description: Roles and Tasks button
.
2
Click
LDAP
>
LDAP Overview
.
3
Click the name of an LDAP Group object to configure.
4
Specify the name and context of an eDirectory User object in the
Proxy User
field.
5
Click
Apply
, then click
OK
.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...