
2-70 SPARC Enterprise Mx000 Servers XSCF User’s Guide • December 2010
2.2.5 LDAP/SSL Administration
LDAP/SSL administration is used to specify items relating to LDAP/SSL clients. The
LDAP/SSL server, loading of server certificate, group name, privileges, user domain, log,
and so on are set. In the LDAP/SSL server, the XSCF user information is managed.
Note – This section does not cover LDAP/SSL configuration and administration. An
administrator who is familiar with LDAP/SSL should perform the LDAP/SSL design.
TABLE 2-9 lists terms used in LDAP/SSL Administration.
LDAP/SSL provides both authentication of user credentials and authorization of the user
access level to networked resources. LDAP/SSL uses authentication to verify the identity of
users before they can access system resources, and to grant specific access privileges to users
in order to control their rights to access networked resources.
User privileges are either configured on XSCF or learned from a server based on each user's
group membership in a network domain. A user can belong to more than one group. User
domain is the authentication domain used to authenticate a user. LDAP/SSL authenticates
users in the order in which the users' domains are configured.
Once authenticated, user privileges can be determined in the following ways:
In the simplest case, user's privileges are determined directly through the LDAP/SSL
configuration on the XSCF. There is a defaultrole parameter for LDAP/SSL. If this parameter
is configured or set, all users authenticated via LDAP/SSL are assigned privileges set in this
parameter. Setting up users in an LDAP/SSL server requires only a password with no regard
to group membership.
If the defaultrole parameter is not configured or set, user privileges are learned from the
LDAP/SSL server based on the user's group membership. On XSCF, the group parameter
must be configured with the corresponding group name from the LDAP/SSL server. Each
group has privileges associated with it which are configured on the XSCF. A user's group
membership is used to determine the user's privileges once authenticated.
TABLE 2-9 LDAP/SSL Administration Terms
Term Description
LDAP/SSL LDAP/SSL is a distributed directory service like Active Directory. LDAP/SSL
offers enhanced security to LDAP users by way of Secure Socket
Layer (SSL) technology. Like an LDAP directory service, it is used to
authenticate users.
Comentarios a estos manuales