Configuring LDAP Services for Novell eDirectory
383
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
15.8.4 Updating Reference Information through LDAP
If you followed the steps above, in order, and used LDAP to perform the tasks, you were likely
unable to add an immediate superior reference. This is because the root partition had already been
marked nonauthoritative, so LDAP sends referrals for any operation acting on data within that
partition.
To update or interrogate information in a nonauthoritative area, the ManageDsaIT control must
accompany the LDAP request. For information on this control, see
RFC 3296 (http://www.ietf.org/
rfc/rfc3296.txt)
. This control effectively causes the LDAP server to treat the entire nonauthoritative
area as though it is authoritative.
NOTE:
The superior reference feature is only available through LDAP. Other protocols (for
example, NDAP) are not affected by the presence of the authoritative attribute. Therefore, the use of
ConsoleOne or Novell iManager to interrogate and update data in the nonauthoritative area is
unhindered.
15.8.5 Affected Operations
Nonauthoritative areas and superior referrals affect the following LDAP operations:
Search and Compare
Modify and Add
DN-syntax attribute values are not checked. Therefore, a group member attribute can contain
DNs that point to entries in a nonauthoritative area.
Delete
Rename (moddn)
Move (moddn)
If the parent DN falls within a nonauthoritative area, an error affectsMultipleDSAs should be
returned.
Extended
15.8.6 Discovering Support for Superior References
Support for superior referrals is available only in LDAP Services for eDirectory 8.7 and later. To
discover whether an eDirectory server supports this functionality, you can read the
supportedFeatures attribute on the root DSE. If the supportedFeatures attribute lists the OID
2.16.840.1.113719.1.27.99.1, these features are available. Additional discovery-related changes to
the root DSE object include the following:
namingContexts
This attribute only lists the partition roots held on the local DSA that the server is authoritative
for. No nonauthoritative partition roots are listed.
altServer
This attribute won't list other eDirectory servers that share only nonauthoritative partitions with
the local server.
Summary of Contents for EDIRECTORY 8.8 SP5
Page 4: ...4 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 118: ...118 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 130: ...130 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 188: ...188 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 222: ...222 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 240: ...240 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 264: ...264 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 290: ...290 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 322: ...322 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 540: ...540 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 548: ...548 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 616: ...616 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...