Configuring LDAP Services for Novell eDirectory
369
no
vd
ocx
(e
n)
6 Ap
ril 20
07
An operation is sent to the eDirectory LDAP server with a base DN of OU=Dev,O=Digital
Airlines,C=US. A referral is returned pointing to the servers holding that entry or to servers that
have knowledge of the servers holding that entry.
Likewise, a subtree search rooted at O=Digital Airlines,C=US results in a referral to the root DSA.
The root DSA in turn returns referrals to the DSAs mastering OU=Sales and OU=Dev.
So that the eDirectory server can participate in this tree, LDAP Services allows eDirectory to hold
the hierarchical data above it in a partition marked “nonauthoritative.” The objects in the
nonauthoritative area consist only of those entries needed to build the correct DN hierarchy. These
entries are analogous to X.500 “Glue” entries.
In this scenario, the Root, C=US, and O=Digital Airlines objects are held on the eDirectory server in
a nonauthoritative area.
eDirectory allows knowledge information (referral data) to be placed within nonauthoritative
areas.This information is used to return referrals to the LDAP client.
When an LDAP operation takes place in a nonauthoritative area of the eDirectory tree, the LDAP
server locates the correct reference data and returns a referral to the client.
14.8.2 Creating a Nonauthoritative Area
The following figure illustrates the actual data held on the eDirectory server in the federated tree
shown in
“Scenario: Superior Referrals in a Federated Tree” on page 368
.
Notice that entries are placed above OU=Sales, even though these entries are mastered by another
DSA. This placement is necessary to provide the proper DNs for the entries mastered by the
eDirectory server.
To create a nonauthoritative area:
1
Segregate the nonauthoritative data from the authoritative data.
Create a partition boundary at the top of the authoritative area. An eDirectory server considers
itself authoritative for all data that it holds unless otherwise specified.
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...