22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

For example, if John Smith is a user in the LDAP directory and is registered as a<br />

member of places, if you change John's e-mail address in the external LDAP<br />

directory, you can use the QPTool updatemember command to update his e-mail<br />

address in places.<br />

For more information on the QPTool commands and the manner in which they<br />

can help administer the security of the QuickPlace, consult the Lotus QuickPlace<br />

3.0 Adminstrator’s Guide that came with Lotus QuickPlace, or see the Web site<br />

at the following URL:<br />

http://doc.notes.net/uafiles.nsf/docs/QP30/$File/na5d3fus.pdf<br />

Note: Distinguished names of users and groups in the user directory should<br />

be unique. If there are two distinguished names in the external LDAP directory<br />

that are the same, only one of the names can be added to a place as a<br />

member. If two distinguished names are identical, add a middle initial or other<br />

distinguishing character to one of the names to make each name unique.<br />

A QuickPlace server can connect to a user directory on any server configured to<br />

use Lightweight Directory Access Protocol (LDAP) version 3, including a Domino<br />

server that runs the LDAP service or any other LDAP directory server. However,<br />

its important to remember that a QuickPlace server is limited to connecting to<br />

only one external LDAP directory at any given time.<br />

12.1.3 QuickPlace authentication<br />

QuickPlace supports two types of authentication for Web browsers connecting to<br />

a QuickPlace server:<br />

► Basic name-and-password authentication<br />

► Multi-server single sign-on name-and-password authentication<br />

Restriction: It is important to note that QuickPlace does not support the<br />

“single server session-based name-and-password authentication” option<br />

provided by Domino, as described earlier in this chapter. However, setting up<br />

multi-server sign-on authentication on a single server achieves a similar<br />

result.<br />

Basic authentication is implemented by default in QuickPlace. An example of this<br />

authentication at work is shown in Figure 12-2 on page 540. This means that<br />

users who sign in to one “place” will be authenticated for that specific place only.<br />

Moving to another place, even if on the same server, will cause Domino to<br />

request the user’s name and password again.<br />

Chapter 12. Security features of other Lotus products 539

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!