The database link on server A binds to server B using a special user as defined in
the
nsMultiplexorBindDN
nsMultiplexorCredentials
following bind credentials:
nsMultiplexorBindDN: cn=proxy admin,cn=config
nsMultiplexorCredentials: secret
Server B must contain a user entry corresponding to the
and you must set the proxy authentication rights for this user. To set the proxy
authorization right, you need to set the "proxy" ACI as you would any other ACI.
CAUTION
Carefully examine access controls when enabling chaining to avoid
giving access to restricted areas of your directory. For example, if
you create a default proxy ACI on a branch, the users that connect
via the database link will be able to see all entries below the branch.
There may be cases when you do not want all of the subtrees to be
viewed by a user. To avoid a security hole, you may need to create
an additional ACI to restrict access to the subtree.
attribute and a user password as defined in the
attribute. In this example, server A uses the
Chapter 3
Creating and Maintaining Database Links
nsMultiplexorBindDN
Configuring Directory Databases
,
103
Need help?
Do you have a question about the NETSCAPE DIRECTORY SERVER 6.02 - ADMINISTRATOR and is the answer not in the manual?
Questions and answers