622
Novell eDirectory 8.8 Administration Guide
no
vd
ocx
(e
n)
6 Ap
ril 20
07
E.3.4 Editing Foreign Principals
You can add Kerberos principal names to the eDirectory users using iManager.
1
In iManager, click
Kerberos Management
>
Edit Foreign Principals
to open the Edit Foreign
Principals page.
2
Specify the FDN of a valid User object or use the
Object Selector
icon to select the User object
reference.
3
Click
OK
.
4
Specify the foreign principal names, then click
Add
.
The principal name must be in the format principalname@
REALMNAME
.
To delete the foreign principal name, select the name and then click Delete .
5
Click
OK
.
E.4 Creating a Login Sequence
For information on creating a login sequence, refer to the Managing Login Sequences section in the
NMAS 3.0 Administration Guide
(http://www.novell.com/documentation/beta/nmas30/
index.html?page=/documentation/beta/nmas30/admin/data/a49tuwk.html#a4)
.
E.5 How Does LDAP Use SASL-GSSAPI?
Once you have configured SASL-GSSAPI, it is added along with the other SASL methods to the
supportedSASLMechanisms attribute in rootDSE.
The LDAP server queries SASL for the installed mechanisms when it gets its configuration, and
automatically supports whatever is installed. The LDAP server also reports the current supported
SASL mechanisms in its rootDSE by using the supportedSASLMechanisms attribute.
Therefore, once you configure GSSAPI, it becomes the default mechanism.
However, to specifically do an LDAP operation over the SASL GSSAPI mechanism, you can
mention GSSAPI at the commandline.
For example, in OpenLDAP to do a search using the GSSAPI mechanism, enter the following:
ldapsearch -Y GSSAPI -h 164.99.146.48 -b "" -s base
E.6 Error Messages
The SASL-GSSAPI error messages are logged into the following locations:
Linux and UNIX:
ndsd.log
For more information, refer to “
Error Messages
” in the
eDirectory 8.8 Troubleshooting Guide
(http:/
/www.novell.com/documentation/edir88/index.html)
.
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...