25.06.2013 Views

Lotus Domino Administrator 7 Help - Lotus documentation

Lotus Domino Administrator 7 Help - Lotus documentation

Lotus Domino Administrator 7 Help - Lotus documentation

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

By default, the LDAP service can refer a client to one LDAP directory only. If the client specifies a search<br />

base, the LDAP service refers the client only to an LDAP directory that is enabled for LDAP clients and<br />

has a naming rule that matches the search base. If there is more than one such directory, the LDAP<br />

service refers the client to the one with the lowest search order.<br />

If the client doesn’t specify a search base, the LDAP service refers the client to an LDAP directory that is<br />

enabled for LDAP clients, and if there is more than one, it refers the client to the one assigned the lowest<br />

search order.<br />

If there is more than one host name specified in the Directory Assistance document for the LDAP<br />

directory that the LDAP service picks for a referral, the LDAP service refers the client to the first host<br />

name listed.<br />

If you increase the number of referrals the LDAP service can return to a client, the LDAP service follows<br />

the logic described above to pick the first directory referral. If there is more than one host name specified<br />

in the Directory Assistance document for this directory, the LDAP service uses the additional host<br />

name(s) as the additional referral(s), up to the maximum number of referrals the LDAP service<br />

configuration allows. If there is no additional host name specified for the first directory picked for<br />

referrals, then LDAP service can refer the client to an LDAP directory with a different Directory<br />

Assistance document.<br />

Naming rules as LDAP naming contexts: Some LDAP client applications, for example the IBM WebSphere ®<br />

Application Server, can discover naming contexts configured for an LDAP directory server by searching<br />

the directory server’s root directory server entry (DSE). When an LDAP user doesn’t specify a search<br />

base, these applications can use the naming contexts configured on the server to contruct one to apply to<br />

the LDAP client searches.<br />

The LDAP service uses naming rules configured in the directory assistance database to define naming<br />

contexts in its root DSE.<br />

Directory assistance and domain names<br />

When you configure directory assistance for a directory you must configure a domain name for the<br />

directory that is unique within the directory assistance database. You use the ″Domain name″ field on the<br />

Basics tab of a Directory Assistance document to configure a directory’s domain name.<br />

If the directory is a remote LDAP directory, make up a unique domain name for the directory that is not<br />

the name of any <strong>Domino</strong> domain.<br />

If the directory is the <strong>Domino</strong> Directory for a <strong>Domino</strong> domain -- <strong>Domino</strong> server setup created it -- specify<br />

the name of the directory’s <strong>Domino</strong> domain.<br />

If you created the directory manually from the PUBNAMES.NTF template, and so it is not associated<br />

with a <strong>Domino</strong> domain -- for example the directory is an Extended Directory Catalog, or a <strong>Domino</strong><br />

Directory used to track Web user information -- do one of the following to specify a domain name for the<br />

directory:<br />

v If you want servers with Configuration directories to use the directory as their remote primary <strong>Domino</strong><br />

Directory, specify the <strong>Domino</strong> domain of the servers with the Configuration directories.<br />

v If servers won’t use the directory as a remote primary <strong>Domino</strong> Directory, make up a unique domain<br />

name for the directory.<br />

Note: If the domain name you specify for a <strong>Domino</strong> Directory or Extended Directory Catalog is the same<br />

as the domain of the servers that use the directory assistance database, the servers can use the directory<br />

automatically for client authentication, group lookups for database authorization, and Notes mail<br />

addressing, regardless if you select ″Make this domain available to: Notes clients and Internet<br />

Authentication/Authorization.″ In addition, servers search a directory in the same domain first,<br />

regardless of the search order specified for the directory.<br />

576 <strong>Lotus</strong> <strong>Domino</strong> <strong>Administrator</strong> 7 <strong>Help</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!