Controlling Access for Virtual Servers
202
Netscape Enterprise Server Administrator’s Guide • November 2001
This configuration allows multiple virtual servers to share the same ACL file. If
you want to require user-group authentication for a virtual server, you must add
one or more USERDB tags to its definition. These USERDB tags create a connection
between the database names in your ACL file and the actual databases found in
dbswitch.conf
.
The following example maps the ACLs with no ‘database’ attribute to the ‘default’
database in
dbswitch.conf
:
<VS>
<USERDB id="default" database="default"/>
</VS>
Accessing Databases from Virtual Servers
You can globally define user authentication databases in the
dbswitch.conf
file.
It
is only read at server startup.
The
baseDN
of the LDAP URL in
dbswitch.conf
defines the global root of all
accesses to the database. This maintains backward compatibility. For most new
installations, the
baseDN
would be empty.
dcsuffix
is a new attribute for LDAP databases in
dbswitch.conf
that defines the
root of the DC tree according to the Netscape LDAP schema. It is relative to the
baseDN
in the LDAP URL. When the
dcsuffix
attribute is present, the LDAP
database is Netscape LDAP schema compliant, and the behaviour of some
operations changes. For more information about the Netscape LDAP schema, see
the Netscape Enterprise Server NSAPI Programmer’s Guide.
For every virtual server, you can define one or more
USERDB
blocks that point to
one of the directories, and you can define additional information. The
USERDB
blocks ID can be referenced in the database parameter of the ACL. If a virtual
server has no
USERDB
blocks, user or group-based ACLs will fail.
USERDB
tags define an additional layer of indirection between the database
attribute of an ACL and
dbswitch.conf
. This layer of indirection adds the
necessary protection for the server administrator to have full control over which
databases virtual server administrators have access to.
For more information on USERDB, see the Netscape Enterprise Server NSAPI
Programmer’s Guide.
Summary of Contents for NETSCAPE ENTREPRISE SERVER 6.0 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Enterprise Server Version6 0 November 2001...
Page 18: ...18 Netscape Enterprise Server Administrator s Guide November 2001...
Page 26: ...26 Netscape Enterprise Server Administrator s Guide November 2001...
Page 48: ...Migrating a Server 48 Netscape Enterprise Server Administrator s Guide November 2001...
Page 50: ...50 Netscape Enterprise Server Administrator s Guide November 2001...
Page 146: ...146 Netscape Enterprise Server Administrator s Guide November 2001...
Page 242: ...242 Netscape Enterprise Server Administrator s Guide November 2001...
Page 294: ...294 Netscape Enterprise Server Administrator s Guide November 2001...
Page 332: ...Deleting a Virtual Server 332 Netscape Enterprise Server Administrator s Guide November 2001...
Page 378: ...378 Netscape Enterprise Server Administrator s Guide November 2001...
Page 396: ...Responses 396 Netscape Enterprise Server Administrator s Guide November 2001...
Page 414: ...Posting to JSPs 414 Netscape Enterprise Server Administrator s Guide November 2001...
Page 432: ...Further Information 432 Netscape Enterprise Server Administrator s Guide November 2001...
Page 444: ...444 Netscape Enterprise Server Administrator s Guide November 2001...