22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Alternate names<br />

An alternate name is an optional alias name that an administrator assigns to a<br />

registered Notes user. You can add alternate names to an ACL. An alternate<br />

name provides the same level of security as the user's primary hierarchical<br />

name. For a user whose primary name is Sandra Brown/West/Sales/Acme, an<br />

example of an alternate name format would be Sandra<br />

Smith/ANWest/ANSales/ANAcme, where AN is an alternate name.<br />

LDAP users<br />

You can use a secondary LDAP directory to authenticate Internet users. You can<br />

then add the names of these Internet users to database ACLs to control user<br />

access to databases.<br />

You can also create groups in the secondary LDAP directory that include the<br />

Internet user names and then add the groups as entries in Notes database<br />

ACLs. For example, an Internet user may try to access a database on a Domino<br />

Web server. If the Web server authenticates the user, and if the ACL contains a<br />

group named “Web,” the server can look up the Internet user's name in the group<br />

“Web” located in the foreign LDAP directory, in addition to searching for the entry<br />

in the primary Domino Directory. Note that for this scenario to work, the Directory<br />

Assistance database on the Web server must include an LDAP Directory<br />

Assistance document for the LDAP directory with the Group Expansion option<br />

enabled. You can also use this feature to look up the names of Notes users<br />

stored in foreign LDAP directory groups for database ACL checking.<br />

When you add the name of an LDAP directory user or group to a database ACL,<br />

use the LDAP format for the name, but use a forward slash (/) rather than a<br />

comma (,) as a delimiter. For example, if the name of a user in the LDAP<br />

directory is:<br />

uid=Sandra Smith,o=Acme,c=US<br />

enter the following in the database ACL:<br />

uid=Sandra Smith/o=Acme/c=US<br />

To enter the name of a nonhierarchical LDAP directory group in an ACL, enter<br />

only the attribute value, not the attribute name. For example, if the<br />

nonhierarchical name of the LDAP group is:<br />

cn=managers<br />

in the ACL enter only:<br />

managers<br />

Chapter 11. Domino/Notes 6 security features 503

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!