04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

7 <strong>UCS</strong> Directory service<br />

Contents<br />

7.1 Overview<br />

7.1 Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181<br />

7.2 Logging of LDAP changes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181<br />

7.2.1 Installation and setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181<br />

7.2.2 Format of the log file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182<br />

7.3 Timeout for inactive LDAP connections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182<br />

7.4 Configuration of LDAP ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183<br />

7.4.1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183<br />

7.4.2 Definition of objects for which a rule applies (access to) . . . . . . . . . . . . . . . . 184<br />

7.4.3 Definition of the access permissions on the objects . . . . . . . . . . . . . . . . . . . 184<br />

7.4.4 Definition of the permission on the objects . . . . . . . . . . . . . . . . . . . . . . . . 185<br />

7.4.5 Definition of the handling of further rules with applied rules . . . . . . . . . . . . . . 185<br />

7.4.6 Delegation of the privilege to reset user passwords . . . . . . . . . . . . . . . . . . . 186<br />

<strong>Univention</strong> Corporate Server saves domain-wide data in a LDAP directory service based on OpenLDAP.<br />

This chapter describes the advanced configuration and coordination of OpenLDAP. Alongside the logging<br />

of LDAP modifications there is also the possibility of adapting the access control lists to the directory<br />

service.<br />

7.2 Logging of LDAP changes<br />

The univention-directory-logger package allows logging of all changes in the LDAP directory<br />

service. In addition, an integrated hash sum ensures that no changes can be deleted from the log file.<br />

7.2.1 Installation and setup<br />

Logging is activated as standard following installation of the package and can be deactivated using the<br />

<strong>Univention</strong> Configuration Registry variable ldap/logging (yes/no).<br />

Individual areas of the directory service can be excluded from the logging. These branches can be config-<br />

ured over the ldap/logging/exclude1, ldap/logging/exclude2 etc. variables. As standard the<br />

container is excluded in which temporary objects are stored (cn=temporary,cn=univention,Base-DN).<br />

181

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!