Chapter 3. Configuring Directory Databases
66
The database link on Server A binds to Server B using a special user as defined
in the
nsMultiplexorBindDN
attribute and a user password as defined in the
nsMultiplexorCredentials
attribute. In this example, Server A uses the following bind
credentials:
nsMultiplexorBindDN: cn=proxy admin,cn=config
nsMultiplexorCredentials: secret
Server B must contain a user entry corresponding to the
nsMultiplexorBindDN
, and set the proxy
authentication rights for this user. To set the proxy authorization correctly, set the proxy ACI as any
other ACI.
WARNING
Carefully examine access controls when enabling chaining to avoid giving access to
restricted areas of the directory. For example, if a default proxy ACI is created on a
branch, the users that connect via the database link will be able to see all entries below
the branch. There may be cases when not all of the subtrees should be viewed by a user.
To avoid a security hole, create an additional ACI to restrict access to the subtree.
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...