« Zurück zu LDAP

LDAP with OpenDS

Asset-Tag: ldap opends opendj

You can see the configurations in following pictures. 

 

0 Anhänge
33679 Angesehen
Durchschnitt (0 Stimmen)
Die durchschnittliche Bewertung ist 0.0 von max. 5 Sternen.
Kommentare
Antworten im Thread Autor Datum
whole the appreciation goes to Tom Yeo. Chris Shayan 11. Dezember 2009 02:34
Hi Chris, Can you add some more details about... Jorge Ferrer 11. Dezember 2009 09:53
Hey about mentionidng the name you're right,... Chris Shayan 12. Dezember 2009 10:31
Also, since I spent some time to find out:... Bruno Vernay 22. Oktober 2010 05:09

whole the appreciation goes to Tom Yeo.
Gepostet am 11.12.09 02:34.
Hi Chris,

Can you add some more details about the configuration?

Also, please avoid mentioning names in the wiki article text, since that discourages further collaboration by other community members.
Gepostet am 11.12.09 09:53.
Hey
about mentionidng the name you're right, but in the comments i should mention the Tom Yeo's name just to take care about his credit as well. Thx for notice.

What kind of detail configuration you want to know?
Gepostet am 12.12.09 10:31 als Antwort auf Jorge Ferrer.
Also, since I spent some time to find out: "isMemberOf" is an "Operational" attribute.

It means that it is calculated from the Group's "member" (or "uniqueMember") attribute, which by opposition is a "User defined" attribute.

Why it is important ? Because "Operational" attribute does not behave like "User defined" attribute. For example, if you define an ACL to authorize read access to all attribute, you may write:
aciemoticontarget = "ldap:///ou=people,dc=ZZtop,dc=com")
(targetattr="*")
(version 3.0; acl "Read all user defined attributes";
allow (read) userdn="ldap:///uid=LifBind,ou=systemAccount,dc=ZZtop,dc=com";)

But if you want to be able to read the "operational" attribute "isMemberOf", you will have to be specific: (targetattr="*||isMemberOf")

Hope that it will avoid others to loose some hours.
By the way check out OpenDJ: http://forgerock.com/opendj.html
Gepostet am 22.10.10 05:09.