
Understanding LDAP Services for Novell eDirectory
327
n
ov
do
cx (e
n)
11
Ju
ly 20
08
Using the ldapconfig Utility on Linux and UNIX
For example, LDAP Search Referral Usage specifies how the LDAP server processes LDAP
referrals.
1
At a system prompt, enter the following command:
ldapconfig -s “LDAP:otherReferralUsage=1”
2
Enter the User FDN (Fully Distinguished eDirectory Username) and password.
Connecting As an NDS or eDirectory User
An eDirectory user bind is a connection that an LDAP client makes using a complete eDirectory
username and password. The eDirectory user bind is authenticated in eDirectory, and the LDAP
client is allowed access to any information the eDirectory user is allowed to access.
The key concepts of eDirectory user binds are as follows:
eDirectory user binds are authenticated to eDirectory using the username and password entered
at the LDAP client.
The eDirectory username and password used for LDAP client access can also be used for
NetWare client access to eDirectory.
With non-TLS connections, the eDirectory password is transmitted in clear text on the path
between the LDAP client and LDAP Services for eDirectory.
If clear text passwords are not enabled, all eDirectory bind requests that include a username or
password on non-TLS connections are rejected.
If an eDirectory user password has expired, eDirectory bind requests for that user are rejected.
Assigning eDirectory Rights for LDAP Clients
1
Determine the type of username the LDAP clients will use to access eDirectory:
[Public] User (Anonymous Bind)
Proxy User (Proxy User Anonymous Bind)
NDS User (NDS User Bind)
See
“Connecting to eDirectory from LDAP” on page 325
for more information.
2
If users will use one proxy user or multiple eDirectory usernames to access LDAP, use
iManager to create these usernames in eDirectory or through LDAP.
3
Assign the appropriate eDirectory rights to the usernames that LDAP clients will use.
The default rights that most users receive provide limited rights to the user’s own object. To provide
access to other objects and their attributes, you must change the rights assigned in eDirectory.
When an LDAP client requests access to an eDirectory object and attribute, eDirectory accepts or
rejects the request based on the LDAP client’s eDirectory identity. The identity is set at bind time.
13.2.2 Class and Attribute Mappings
A
class
is a type of object in a directory, such as a user, server, or group. An attribute is a directory
element that defines additional information about a specific object. For example, a User object
attribute might be a user’s last name or phone number.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...