Netscape DIRECTORY SERVER 6.01 - ADMINISTRATOR Administrator's Manual page 127

Table of Contents

Advertisement

Since database link DBLink2 is the intermediate database link in your cascading
chaining configuration, you need to set the
server to check whether or not it should allow the client and proxy administrative
user access to the database link.
The database link on server two must be configured to transmit the proxy
authorization control and the loop detection control. To implement the proxy
authorization control and the loop detection control you need to specify both
corresponding OIDs. Add the following information to the
cn=config,cn=chaining database, cn=plugins,cn=config
two:
dn: cn=config,cn=chaining database,cn=plugins,cn=config
changeType: modify
add: nsTransmittedControl
nsTransmittedControl: 2.16.840.1.113730.3.4.12
nsTransmittedControl: 1.3.6.1.4.1.1466.29539.12
where
nsTransmittedControl: 2.16.840.1.113730.3.4.12
Proxy Authorization control and
1.3.6.1.4.1.1466.29539.12
Again, remember to check beforehand whether or not the loop detection control is
already configured, and adapt the above command accordingly.
The next step is to configure your ACIs. On server two you need to ensure that a
suffix exists above the there is an existing suffix above the
l=Zanzibar,c=africa,ou=people,dc=example,dc=com
add the database link suffix
add a local proxy authorization ACI that will be used to allow server one to
connect using the proxy authorization administrative user that will be created
on server two, and
add a local client ACI that allows the client operation to succeed on server two,
so that it can be forwarded to server three. This local ACI is needed because
you have turned local ACI checking on for the DBLink2 database link.
Both ACIs will be placed on the database that contains the
c=africa,ou=people,dc=example,dc=com
nsCheckLocalACI
nsTransmittedControl:
is the OID for the loop detection control
suffix.
Chapter 3
Creating and Maintaining Database Links
to on, to allow the
entry on server
is the OID for
.
suffix to allow you to:
Configuring Directory Databases
127

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.01

Table of Contents