
Creating and Maintaining Database Links
104
Red Hat Directory Server Administrator’s Guide • May 2005
Some components send internal LDAP requests to the server, expecting to access
local data only. For such components, you need to control the chaining policy so
that the components can complete their operations successfully. One example is
the certificate verification function. If you chain the LDAP request made by the
function to check certificates, it implies that you trust the remote server. If the
remote server is not trusted, then you have a security problem.
By default, all internal operations are not chained. However, you can override this
default by specifying components that you want to chain using the Console or the
command-line. By default, no components are allowed to chain.
You must also create an ACI on the remote server to allow the plug-in you specify
to perform its operations on the remote server. You create the ACI in the suffix
assigned to the database link.
The following table lists component names, the potential side-effects of allowing
them to chain internal operations, and the permissions they need in the ACI you
create on the remote server:
Table 3-2
Components Allowed to Chain
Component Name
Description
Permissions
ACI Plug-in
This plug-in implements the access control feature.
Operations used to retrieve and update ACI attributes are
not chained because it is not safe to mix local and remote
ACI attributes. However, requests used to retrieve user
entries may be chained. Specify the following value in
nsActiveChainingComponents
attribute:
nsActiveChainingComponents: cn=ACI
Plugin,cn=plugins,cn=config
Read, search, and
compare
4.0 plug-ins
This component name represents all Directory Server 4.0
plug-ins. The 4.0 plug-ins share the same chaining policy.
Specify the following in the
nsActiveChainingComponents
attribute:
nsActiveChainingComponents: cn=old
plugin,cn=plugins,cn=config
Depends upon the 4.0
plug-in you are
allowing to chain
Resource limit
component
This component sets server limits depending on the user
bind DN. You can apply resource limits on remote users if
the resource limitation component is allowed to chain. To
chain this component’s operations, specify the following:
nsActiveChainingComponents: cn=resource
limits,cn=components,cn=config
Read, search, and
compare
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...