
Maintaining Novell eDirectory
551
n
ov
do
cx (e
n)
11
Ju
ly 20
08
When an object is created in eDirectory, default ACLs might be added on the object. This depends
on ACL templates in the schema definition for the objectClass to which this object belongs. For
example, in the default configuration for inetOrgPerson, there can be up to six ACLs added on the
user object. When an LDAP search request is made to return this user object with all attributes, it
takes slightly longer to return this object to the client than returning this user object without ACL
attributes.
Though default ACLs can be turned off, administrators may not want to turn them off because they
are required for better access control. However, you can improve the search performance by not
requesting them or by marking them as read filtered attributes. These changes do not break any
applications because most applications use effective privileges and do not rely on specific ACLs.
Not requesting ACLs:
An ACL attribute is not needed by several applications, so the applications
can be modified to request specific attributes in which the application is interested. This results in
better performance of the LDAP search.
Marking an ACL as read filtered:
If an application cannot be modified, the
arf_acl.ldif
can be
used by an administrator to mark the ACL attribute as a read filtered attribute. When the ACL is
marked as a read filtered attribute, the server does not return the attribute on the entry if all attributes
are requested. However, the if the LDAP search is done to return operational attributes or if the
request specifically asks for ACL attributes, the marked attribute is returned.
rrf_acl.ldif
can be used
to turn off the read filtered flag on an ACL attribute. These LDIFs affect the ACL attribute on the
schema, so only a user with Supervisor rights on tree root can extend them.
By default, an ACL is not marked as read filtered, so the performance benefit for requests to return
all attributes is not seen.
The following table depicts the location of
arf_acl.ldif
and
rrf_acl.ldif
files in different platforms.
18.4 Advanced Referral Costing
Server applications often communicate with other servers via a built-in client (Dclient), because a
single server doesn't contain all the necessary eDirectory data for an application to operate. An
example is NLDAP, when it is configured to chain requests.
When a server application requests data that the local server does not hold, the server locates another
server that contains the requested data, and subsequently retrieves the data for the client. This
process is called “tree walking”. It naturally takes longer for a server to fulfill a request through tree
walking. Although best practice guidelines for eDirectory tree design minimize the need for tree
walking, it is still sometimes necessary.
Platform
Location
UNIX
/opt/novell/eDirectory/lib/nds-schema/
NetWare
<unzipped_location>\nw\sys\system\schema
Windows
<unzipped_location>\nt\I386\NDSonNT\ndsnt\nds
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...