22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

464 Lotus Security Handbook<br />

form, giving a user Browse access to the form in the extended ACL does not<br />

override the access specified in the Readers field.<br />

Planning directory access control<br />

Use the database ACL to control the general access that users and servers have<br />

to the Domino Directory. Optionally, use an extended ACL to refine the general<br />

database ACL and further restrict access to specific portions of the directory. An<br />

extended ACL is available only for Domino Directory and Extended Directory<br />

Catalog.<br />

Some of the questions to ask when planning directory access control include:<br />

► Do you want to assign administrators to specific administration roles in the<br />

Domino Directory? If administrators in your company have specialized<br />

administrative duties, consider assigning the administrators only to the<br />

administration roles in the ACL that correspond to their duties. If your<br />

company administrators do all administrative tasks, assign them to all of the<br />

roles.<br />

► Do you want to use an extended ACL? One of the reasons to use an<br />

extended ACL is to limit cross-organizational access to a directory that<br />

contains information for multiple organizations or organizational units.<br />

► Do you want to allow Anonymous access to the directory? By default, you use<br />

the domain Configuration Settings document in the Domino Directory to<br />

control anonymous LDAP search access. By default, anonymous LDAP users<br />

have Read access to a specific list of attributes.<br />

The Anonymous entry in the directory database ACL by default is set to “No<br />

Access” and controls anonymous access for all users other than LDAP users. If<br />

you use an extended ACL, then the Anonymous entry in database ACL and the<br />

extended ACL also control anonymous LDAP access. Typically you give the<br />

Anonymous entry no more than Reader access.<br />

11.6.5 LDAP directories<br />

The Lightweight Directory Access Protocol (LDAP) is a standard Internet protocol<br />

for searching and managing entries in a directory. Domino and Notes provides<br />

LDAP support via:<br />

► The “LDAP service,” which enables a Domino server to function as an LDAP<br />

directory server and process LDAP requests.<br />

► LDAP accounts on Notes clients, which enable Notes users to do LDAP-style<br />

searches for an addresses in LDAP directories.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!