Hi,
I am configuring identity in the S160 WSA for Novell eDirectory.
I've created an Authentication Realm configured for eDir, added my ldap server etc - and it works.
Now I want to do some access based on eDirectory group membership.
I have read the documentation, but my mind can't string it together ! Hopefully someone hear can explain or give me some working settings....
Under Group Authorization, I can choose either Group Object or User Object. My understanding is for Edir I could use either (user object lists group membership and group object lists users in group).
Q1. Is my understanding correct - i.e. I can user either ?
Q2. If so, which is the preferred and more efficient method ?
Q3. What settings would I need for either when running against eDirectory ?
Going back to my basic User Authentication section, the Base DN is currently root of tree, with User Name Attribute of "cn" and User Filter Query set to "none". I would like to narrow this down as a the tree has lots of non-User objects.
Q4. Can I add multiple Base DNs ?
Q5. Is the User Filter Query to set what TYPE of object to query for ? If so, any ideas for requried setting for eDirectory ?
Sorry for all the questions, but as this is heavily used production, I don't want to get there by trial and error. It could mean my trial..... 🙂
Thanks in Advance,
Ian