
NMAS Considerations
A
601
n
ov
do
cx (e
n)
11
Ju
ly 20
08
A
NMAS Considerations
This appendix contains the following topics:
Section A.1, “Setting Up a Security Container As a Separate Partition,” on page 601
Section A.2, “Merging Trees with Multiple Security Containers,” on page 601
A.1 Setting Up a Security Container As a
Separate Partition
Novell
®
Modular Authentication Services (NMAS
TM
) relies on the storage of policies that are global
to the Novell eDirectory
TM
tree. The eDirectory tree is effectively the security domain. The security
policies must be available to all servers in the tree.
NMAS places the authentication policies and login method configuration data in the Security
container that is created off of the [Root] in NetWare
®
5.1 or later eDirectory trees. This information
must be readily accessible to all servers that are enabled for NMAS. The purpose of the Security
container is to hold global policies that relate to security properties such as login, authentication, and
key management.
With NMAS, we recommend that you create the Security container as a separate partition, and that
the container be widely replicated. This partition should be replicated as a Read/Write partition only
on those servers in your tree that are highly trusted.
NOTE:
Because the Security container contains global policies, be careful where writable replicas
are placed, because these servers can modify the overall security policies specified in the eDirectory
tree. In order for users to log in with NMAS, replicas of the User objects must be on the NMAS
server.
A.2 Merging Trees with Multiple Security
Containers
Special considerations need to be made when merging eDirectory trees where a Security container
has been installed in one or both of the trees. Make sure that this is something you really want to do
because this procedure has the potential to be a very time-consuming and laborious task.
IMPORTANT:
These instructions are complete for trees with Novell Certificate Server
TM
2.21 and
earlier, Novell Single Sign-on 2.
x
, and NMAS 2.
x
.
To merge trees with multiple Security containers:
1
In iManager, identify the trees that will be merged.
2
Identify which tree will be the source tree and which tree will be the target tree.
Keep in mind these security considerations for the source and target trees:
Any certificates signed by the source tree's Organizational CA must be deleted.
The source tree's Organizational CA must be deleted.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...