376
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
Setting Referrals for Other Operations
The historical referral option setting only applied to the search operation. To provide a comparable
option for other operations, the ldapOtherReferralOption attribute is used. This attribute allows the
same values and controls the behavior for non-search operations (excluding bind, which never sends
a referral).
Referral Flitering
If you have multiple replica servers running in a tree and have configured LDAP server(s) to return
referrals using the Prefer Referrals/Always Refer option, then the LDAP server will return referrals
if the object identified by DN in the requested operation is not present locally. In such a case, LDAP
client sends a request to the server, and the server returns a referral list of all the LDAP servers
holding that object. Using this referral list, LDAP clients will follow any of these referrals to
perform the operation. If the client chooses to follow the referral to a lresouce starved server or a
server that is located across a slow link, clients would see a slow response from the server. This in
turn affects the performance of the LDAP client.
Since LDAP application developers will not have complete knowledge about the servers and
network configurations, the solution for this problem is to provide a referral filtering mechanism at
the LDAP server to return the referrals of specific server(s). Administrators would have the requisite
knowledge, e.g. the nature of LDAP servers in the network and network link speeds to make
appropriate configuration of referral filtering.
Set up the referral filter on the LDAP Group object using the attributes “referralIncludeFilter” and
“referralExcludeFilter”. Setting these filters in these attributes will be applicable to all the LDAP
servers belonging to this LDAP Group object. The LDAP server will return all the LDAP referrals
matching with the referralIncludeList filter and drop the ones that match the referralExcludeFilter
filter.
If only referralIncludeFilter is specified, the LDAP referrals which match the referralIncludeFilter
values will be returned to the LDAP clients and all other referrals will be excluded from the referral
list. Similarly, if only referralExcludeFilter is specified, the LDAP referrals which do not match the
referralExcludeFilter values will be returned to the LDAP clients. If both filters exist and the referral
does not match any of these filters, it will be excluded.
If all available referrals are disallowed by the filter, the server will behave as if no referrals are
available and return LDAP_OTHER (80), which some client tools report as "Unknown error". After
adding or modifying these filter attributes, if the LDAP server is not refreshed, changes will take
place after the subsequent automatic refresh.
Currently, adding or modifying these filter attributes can be done only with ther tab in ConsoleOne®
and iManager.
Format to Specify LDAP Referral Filtering
—The LDAP referral filter format is a simple IP
address format:
[ldap://] | [ldaps://]
IPAdress
[:port]
Here, specifying the clear text port or TLS port will be same as pre-pending ldap:// or ldaps://
strings. If neither ldap or ldaps is specified, the match filter is applicable for both clear text as well as
TLS referrals.
Examples:
Summary of Contents for EDIRECTORY 8.8 SP5
Page 4: ...4 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 118: ...118 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 130: ...130 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 188: ...188 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 222: ...222 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 240: ...240 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 264: ...264 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 290: ...290 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 322: ...322 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 540: ...540 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 548: ...548 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 616: ...616 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...