13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

semicolon-separated base-scope-filter triples. These base-scope-filter triples are used todefine searches only for the specific service <strong>and</strong> are searched in order. If multiplebase-scope-filters are specified for a given service, then when that service looks for aparticular entry, it will search in each base with the specified scope <strong>and</strong> filter.Note – The default location is not searched for a service (database) with an SSD unlessit is included in the SSD. Unpredictable behavior will result if multiple SSDs are givenfor a service.In the following example, the Solaris <strong>LDAP</strong> naming service client performs a one-levelsearch in ou=west,dc=example,dc=com followed by a one-level search inou=east,dc=example,dc=com for the passwd service. To look up the passwd datafor a user’s username, the default <strong>LDAP</strong> filter (&(objectClass=posixAccount)(uid=username)) is used for each BaseDN.serviceSearchDescriptor: passwd:ou=west,dc=example,dc=com;ou=east,dc=example,dc=comIn the following example, the Solaris <strong>LDAP</strong> naming service client would perform asubtree search in ou=west,dc=example,dc=com for the passwd service. To look upthe passwd data for user username, the subtree ou=west,dc=example,dc=comwould be searched with the <strong>LDAP</strong> filter (&(fulltimeEmployee=TRUE)(uid=username)).serviceSearchDescriptor: passwd:ou=west,dc=example,dc=com?sub?fulltimeEmployee=TRUEIt is also possible to associate multiple containers with a particular service type. In thefollowing example, the service search descriptor specifies searching for the passwordentries in three containers.ou=myuser,dc=example,dc=comou=newuser,dc=example,dc=comou=extuser,dc=example,dc=comNote that a trailing ’,’ in the example implies that the defaultSearchBase isappended to the relative base in the SSD.defaultSearchBase: dc=example,dc=comserviceSearchDescriptor: \passwd:ou=myuser,;ou=newuser,;ou=extuser,dc=example,dc=comChapter 9 • <strong>LDAP</strong> Basic Components <strong>and</strong> Concepts (Overview) 135

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!