Netscape Directory Server Deployment Guide Index
Directory Deployment Guide
Index
A
access
anonymous 58, 71
determining general types
of 71
precedence rule 60
restricting by physical
location 72
access rules
overview 55
access-control
branching to support 87
planning 24
access-control information (ACI) 59
bind rules 64, 65, 66
filtered rules 63, 87
format 64-69
in the directory tree 87
permission 64
target 64, 65
usage advice 67
where to place 62, 125
access-control list (ACL) 59
defined 59
permissions 59
ACI, See access-control
information
ACL, See access-control list
adding object classes 47
strategies 48
allow permissions 61
usage advice 61
analyzing the site survey 34
anonymous access 71
for read 37
overview 58
API, server 141
applications 31
architecture 16
attribute 42
overview 44-46
required and allowed 44
values 45
attribute-data pair 29, 42
authentication 55, 57
certification-based 56
overview 55
root DN 59
with Directory Server NT 57
B
base distinguished name 20
bind DN 55
bind rules 64, 65, 66
binding to the directory 55
anonymously 58
certificate-based 56
branch point 76
DN attributes 82
searching 84
traditional 84
for access-control 87
for international trees 88
for replication and
referrals 86
network names 86
strategies 85
usage advice 82
C
c attribute 89
C SDK 140
cascading replication 97
certificate-based authenticate 56
changelog 102
circular groups 71
clients 15
API 138
bind algorithm 56
referrals and 121
SDK 140
cn attribute 42, 43, 89,
145
commonName attribute 42, 43, 89,
91
consumer server 94, 95
consumer servers 95
consumer-initiated replication 100
required directory entries
102
conventions, in this book 10
country attribute 62, 89
custom filters 137
strategies 138
custom LDAP clients 137
building 139
custom programs 137
client SDKs 140
clients, building 139
customizing the directory service 137
customizing the schema 40, 47-52
being consistent 50
FAQ 51
D
data access 37
data management
local management
example 131
planning 24
replication example 110
data mastering 34
for multiple applications
35
for replication 34, 107
data migration 138
data ownership 36
database 16
access rules 55
replacing 141
with ISPs 79
database plug-in 16, 141
default permissions 60
deny permissions 60
usage advice 61
when to use 61
deployment advice 25
Directory Access Protocol (DAP) 14
directory applications 31
browsers 31
email 31
directory data 27-40
access 37
characteristics 29
creating 147
entry size 106
examples of 30
mastering 34
for multiple
applications 35
for
replication 34
model 45
ownership 36
planning 28, 31
site survey 32-40
representation 42
what not to include 30
directory deployment team 33
directory design
activities 24
advice 23
examples
extranet
135
international
corporation 129-135
multiple suffix, local data
management 132
single suffix, global replication 129
single suffix, local data management 131
small
organization 124
state
government 127
directory entries
creating 147
directory information tree 17
directory of directories 133
directory schema 40
directory service 12-15
extending 137
global 14
LDAP 15
n+1 problem 13
Netscape solution 16
uses of 13
X.500 14, 127
directory suffix 76
country root point 78
planning 78
recommended 79, 144
directory tree 17, 75-91
branch point 76, 124, 127
DN attributes
82
searching 84
for
access-control 87
for
international trees 88
for replication
and referrals 86
network names
86
strategies 85
usage advice 82
consumer 95
design advice 145
overview 76
planning 25
populating 147
replicated 96
suffix 76, 124, 127
country root
point 78
planning 78
recommended 79,
144
supplier 95
distinguished name 18
name collision 90
avoiding 145
naming non-person entries
91
naming person entries 89
usage advice 145
DIT 17
DN, See distinguished name
DNS 13, 103
network sort 103
round robin 103
E
email applications 31
enterprise 12
examples
directory design 123-136
extranet
135
international
corporation 129-135
multiple suffix, local data
management 132
single suffix, global replication 129
single suffix, local data management 131
small
organization 124
state
government 127
replication
large sites 110
load balancing
server traffic 111
local data
management 110
messaging
traffic 113
small sites 109
extended operations 140, 141
extending the directory service 137
extending the schema 47
FAQ 51
extranet
example 135
replication 98
smart referrals 119
F
filtered access-control rules 63
fonts, in this book 10
G
global directory services 14
group attribute 62
groups
circular 71
examples 125
naming 91
nested 71
planning 25, 69
usage advice 71
H
highly available directory services
102
I
index 114
inetOrgPerson attribute 62
inheritance, in object classes 43
international enterprise
branching to support 88
interoperating with legacy directories
138
J
L
LDAP, See Lightweight
Directory Access Protocol
LDAP client API 138
LDAP Data Interchange Format (LDIF)
147
LDIF 147
legacy directory, interoperating with
138
Lightweight Directory Access Protocol
(LDAP) 15
client 15
API 138
authentication
55
anonymous 58
custom 137
custom,
building 139
custom operations 140
directory service
architecture 15
directory services 15
extended operations 140
referral handling 121
server 15
load balancing
the network 106
the server 105
local data management 131
M
mail attribute 90
mastering directory data 34
for multiple applications
35
for replication 34
migrating directory data 138
multiple suffixes 77
with enterprises 80
with extranets 81
with ISPs 79
N
n+1 directory problem 13
name collision 90
avoiding 145
nested groups 71
Netscape Directory Server 11, 15-17
API 141
architecture 16
authentication 55
anonymous 58
certificate-based
56
capabilities 15
concepts 17-21
database 16
deployment advice 25
extended operations 140
extending 137, 141
load balancing 105
performance 104
plug-ins 137
security policy 54
Netscape Messaging Server
indexes, required 114
replication example 113
network names, branching to reflect 86
network sort 103
network, load balancing 106
non-person entries
naming 91
O
object class 42
adding new 47
inheritance 43
overview 43-44
standard 43
object class violation 44
organization attribute 62
organizationalPerson object class 43
organizationalUnit attribute 62
organizations, naming 91
P
passwords, NT Directory Server and
57
performance (server) 104
permissions 60
ACL and 59
allow 61
bind rules 64, 65, 66
default 60
deny 60
when to use 61
on ACIs 64
precedence rule 60
usage advice 61
persistent search 140
person entries, naming 89
planning
access-control 24
data management 24
directory contents 24
directory data 28
site survey 32-40
analyzing 34
directory tree 25
groups 25
referrals 25
replication 25
planning directory data 31
what to consider 31
plug-in 16, 137
server, writing 141
points of access 72
populating the directory 147
precedence rule 60
Q
R
RDN, See relative
distinguished name 89
referrals 77, 115-122
branching to support 86
client handling 121
handling by LDAP
client 121
overview 116
planning 25
smart referrals
client
handling 121
how to use
119
overview
116
usages 119
when returned 116
relational database 141
relative distinguished name (RDN) 89
non-person entries 91
person entries 89
replication 93-102
agreement 100
architecture 94
branching to support 86
cascading 97
consumer server 94, 95
consumer-initiated 100
directory trees 96
examples
large sites 110
load balancing
server traffic 111
local data
management 110
messaging
traffic 113
small sites 109
extranet 98
for high availability 102
initiating synchronization
100
load balancing 104
the network 106
the server 105
local availability 107
modifying data 95
multiple subtrees 98
overview 94
planning 25
single master 94
strategies 108
example
129
subtrees 98
supplier server 94, 95
supplier-initiated 100
replication master 129
root distinguished name 20
root DN 20
authentication 59
defined 59
password 59
root DSE 76
root entry 19, 124, 127
root password 59
S
schema 40, 41-52
customizing 40, 47-52
being
consistent 50
FAQ 51
deleting standard
elements 47
extending 47
overview 42-46
schema checking 45
overview 46
SDK, See software developer
kits
secure sockets layer 21, 56
security policy 38, 53
creating 69-73
overview 54
server database 16
server performance 104
server plug-in 141
site survey 32-40
analyzing 34
documenting 38
multinational enterprises
33
network capabilities 108
smart referral 77
client handling 121
example 128, 134
how to use 119
overview 116
usages 119
sn attribute 43
software developer kits (SDKs) 140
SSL (see Secure Sockets Layer)
standard object classes 43
streetAddress attribute 43
styles, in this book 10
subtree replication 98
multiple subtrees 98
suffix 18, 76, 124,
127
country root point 78
multiple 77
with extranets
81
with ISPs 79
with large
enterprises 80
planning 78
recommended 79, 144
suitespot settings, creating 146
supplier DN 101
supplier servers 94, 95
capabilities of 95
synchronization and 100
supplier-initiated replication 100
required directory entries
101
surname attribute 43
T
telephoneNumber attribute 43
terms, in this book 10
top object class 43
U
uid attribute 43, 90
user authentication 55
user IDs 145
userPassword attribute 43
X
X.500 14, 50, 82,
83
X.500, coexisting with 127