Sun Java logo     �W�@��      �ؿ�      �d�      �U�@��     

Sun logo
Sun Java(TM) System Directory Server 5 2004Q2 �޲z��n 

�� 1 ��
Directory Server �޲z����

Directory Server ���~�]�t�F�޲z�h���ؿ� Directory Server�BAdministration Server�A�H�γz�L�ϧΤ����޲z��Ӧ�A���� Server Console�C����������� Directory Server �����׸�T�A�H�αz�n�Ұʺ޲z�ؿ�A�ȩһݪ��̰򥻤u�@�C

�����Ҥ��Ъ���� Directory Server 5.2 �s�W�\��O Plug-in ñ�W�M DSML-over-HTTP �q�T��w�C���� Plug-in ñ�W�O�B�~���w���ʥ\��A���A���i����Ψ���g���v�� Plug-in ��J�CDirectory Server Markup Language (DSML) �O�@�إH XML ����¦���s�榡�A�Ω�ǰe�n�D���ؿ��A���C

�����]�t�U�C���`�G


�Ƶ�

�p�G���b���@�Ӫ����H�W�� Directory Server�A�Ъ`�N���������Ҧ��d�ҳ����] Directory Server 5.2 �O�w�]�����C�p�G���O�o�ر��p�A�z�������@���U�C��O�A�N 5.2 �]�w���w�]�����G

# /usr/sbin/directoryserver -d 5.2

�Φb�C����� directoryserver ��O�H��w�����ɥ[�J -useversion �ﶵ�A�Ҧp�G

# /usr/sbin/directoryserver -useversion 5.2 start



Directory Server �޲z����

Directory Server ��í�w�B�㩵�i�ʪ���A���A�]�p�Ӻ޲z��~�����ϥΪ̩M�귽�ؿ�C���O�H�٬����q���ؿ�s��q�T��w (Lightweight Directory Access Protocol�ALDAP) ���}�񦡨t�Φ�A���q�T��w����¦�CDirectory Server �|�H ns-slapd �B�z�{�ǩΪA�Ȧb�z����W���C��A���|�޲z�ؿ�e�æ^3�Τ�ݪ��n�D�C

�z�i�z�L Sun Java System ���Ѩ�U�z�޲z Directory Server (�M�ƺب�L Sun Java System ��A��) ���ĤG��A���A�Y Administration Server�A�H���j���*� Directory Server �޲z�u�@�CServer Console �O Administration Server ���ϧΤƤ����FDirectory Server Console �O Server Console ���@���!A�M��]�p�ӷf�t Directory Server �ϥΡC

�z�i�H�z�L Directory Server Console ���j���*� Directory Server �޲z�u�@�C�z�]�i�H�Q�νs��պA�ɡA�ΨϥΫ�O�椽�ε{����ʰ��޲z�u�@�C�p����� Server Console ���ԲӸ�T�A�аѾ\�mAdministration Server Administration Guide�n�C


�Ƶ�

�p�G���b�ϥ� Directory Server ��ƪA�Ȫ� Sun Cluster HA�A�b�޲z Directory Server �M�Ӧ۫�O��ɡA�z�����ϥ� directoryserver(1M) ��O�Ψ�l��O�C

�ФŪ����ϥγ�W���{���ɩM�G�i���ɮ׽X�C



�ҰʩM���� Directory Server

�p�G���ϥΦw���q�T�ݶ��h (Secure Sockets Layer�ASSL)�A�z�i�H�Q�ΦC�ܩ󦹳B����k�ҰʩM���� Directory Server�C�p�G�z�ϥ� SSL�A�аѾ\�u�Ұʱҥ� SSL ����A���v�C

�q��O��ҰʩM�����A��

�q��O��ҰʩM�����A���C���U�C��O�G

 

# /usr/sbin/directoryserver -useversion 5.2 start

��

 

# /usr/sbin/directoryserver -useversion 5.2 stop

�u�� Directory Server 5.2 ���O�w�]�����ɡA�~�ݭn useversion �ﶵ�C��� directoryserver ��O������y�k�A�аѾ\�mDirectory Server Administration Reference�n�� Chapter 1 "Command-Line Tools Reference"�C

�o�ǫ�O�����@���ڰ��A�p�G�G

�_�h�A��ӫ�O�����P Directory Server �ۦP�� UID �M GID �@�_���C�Ҧp�A�p�G Directory Server �H nobody ���A�h�����H nobody ��� start �M stop ���ε{���C

��� Directory Server ���e�������ϥΪ̡A�Ъ`�N�w�L�k�b�ѷӼҦ����Ұʦ�A���C�z�i�H�ϥ� Directory Server Console �]�w����ѷӡC���{�Ǧb�u�]�w�w�]�ѷӡv��������C

�q�D���x�ҰʩM�����A��

Directory Server Console ���b���ɡA�z�i�H�z�L��ϧΤ����ҰʡB����M���s�Ұ� Directory Server�C�p�ݰ��D���x������A�аѾ\�u�Ұ� Directory Server Console�v�C

  1. �b Directory Server Console �̤W�h�� [�u�@] ���ҤW�A��@�U��3�� [�Ұʥؿ��A��]�B[����ؿ��A��] �� [���s�Ұʥؿ��A��] �Ǫ���s�C

��z���\�a�q Directory Server Console �Ұʩΰ��� Directory Server �ɡA�D���x�|

�T����ܡA����w�g�Ұʦ�A�������A���C�p�o�Ϳ�~�A�D���x�N��ܦ���ӿ�~���Ҧ��T���C


�Ұʱҥ� SSL ����A��

�ҥ� SSL ���e�A�z�����b�z����A���W�w�˻P�t�m���ҡC�p�ݺ޲z���Ҥαҥ� SSL ������A�аѾ\�� 11 ���u�޲z���ҩM�[�K�v�F�p�������ҡB���Ҹ�Ʈw�Ψ�o��A�����Ҫ���T�A�аѾ\�mAdministration Server Administration Guide�n���� Chapter 9 "Using SSL and TLS with Sun Java System Servers"�C

�Y�n�Ұʤw�ҥ� SSL ����A���A�z�����q��O��Ұʦ�A���A�ӥB���ѫO�@��A�����Ҫ��K�X�C

�Ϊ̡A�z�i�H�إ߱K�X�ɮץH�x�s�z�����ұK�X�C�z�L�N�z�����Ҹ�Ʈw�K�X��m�b�ɮפ��A�i�H�q��A���D���x�Ұʦ�A���A�åB���\��A���b�L�H���ɡA�۰ʭ��s�ҰʡC


�p��

�b�K�X�ɮפ��O�H�¤�r�x�s�ӱK�X�A�]����ϥΥN��F���j���w���ʭ��I�C�p�G�z����A���O�b���w������Ҥ����A�h�ФŨϥαK�X�ɮסC


�K�X�ɮץ�����m�b�U�C��m���G

serverRoot/alias/slapd-serverID-pin.txt

�䤤 serverID �O�z�b�w�ˮɬ���A����w���ѧO�X�C

�b�ɮפ��]�t�w�� Token ���W�٤Ψ�K�X�A�p�U�G

deviceName Token:password

���d����ܤ������Ҹ�Ʈw���˸m�W�� (�j�p�g�ΪŮ楲�������̷Ӧp�U���)�G

Internal (Software) Token:password

�p�G�N�����x�s�b�%N�˸m�W�A�ШϥΦ�b [�޲z����] ��ܤ��W�誺�U�Ԧ��\��?���˸m�W�١C�Y�n�إ߾��Ҹ�Ʈw�A�z�����ϥκ޲z��A���� [���ҳ]�w���F]�C�p����� Directory Server �ϥ� SSL ����T�A�аѾ\�� 11 ���u�޲z���ҩM�[�K�v�C


�ϥ� Directory Server Console

Directory Server Console �O�z�H Server Console ����W��s�����C�z�i��ӤU�C�{�ǩҭz�A�q Server Console �Ұ� Directory Server Console�C

�Ұ� Directory Server Console

  1. ���ˬd�T�{ Directory Server �`�n�{�� slapd-serverID ���b��椤�C�Y�S���A�ХH root �κ޲z�ϥΪ̨����J�U�C��O�ӱҰʥ��G

     

    # /usr/sbin/directoryserver -useversion 5.2 start

  2. ���ˬd�T�{�޲z��A���`�n�{�� ns-httpd ���b��椤�C�Y�S���A�ХH root �κ޲z�ϥΪ̨����J�U�C��O�ӱҰʥ��G

     

    # /usr/sbin/directoryserver -useversion 5.2 start-admin

  3. ��J�U�C��O�Ұ� Server Console�G

     

    # /usr/sbin/directoryserver -useversion 5.2 startconsole

  4. �p�G�n�b���O�w�� Administration Server ���q����� Server Console�A�i��ݭn�̡mAdministration Server Administration Guide�nChapter 6 �� "Network Settings" �ҭz�t�m Administration Server �W���s�u����C

    ��� [�D���x] �n�J��C�Ϊ̡A�p�G�z���պA�ؿ� (�]�t o=NetscapeRoot �=X���ؿ�) �x�s�b��W�� Directory Server ��Ҥ��A�h�|��ܵ�A�n�D�ӥؿ��A�����t�κ޲z��ϥΪ� DN�B�K�X�� Administration Server �� URL�C

  5. �ϥγs�� DN �ΨϥΪ̱K�X�n�J�A�ӨϥΪ̥����֦��R�*��s����v�i���z�Ʊ��檺�@�~�C
  6. ��� Server Console�C

  7. �b�����O���𪬥ؿ�A�s���M�z�� Directory Server �D��A�M���@�U��W�٩ιϥ���ܨ�@�뤺�e�C
  8. �� 1-1 Sun Java System Server Console
    Sun ONE Server Console

    �Y�n�s�� Directory Server �W�٩M�y�z�A�Ы�@�U [�s��] ��s�C�b��r����J�s���W�٩M�y�z�C��@�U [�T�w]�A�]�w�s�W�٩M�y�z�C�W�ٷ|��ܦb���䪺�𪬥ؿ�A�p�W�ϩҥܡC

  9. �s���U�𪬥ؿ� Directory Server �W�١A�Ϋ�@�U [�}��] ��s�A��ܺ޲z���ؿ��A���� Directory Server Console�C

�s�� Directory Server Console

Directory Server Console ���Ѥ����A�i�b Directory Server ��ҤW�s��ΰ��޲z�@�~�C�������l����ܥ|�Ӽ��ҡA�i�q�䤤�s��Ҧ� Directory Server �\��G

[�u�@] ����

�}�� Directory Server Console �ɡA[�u�@] ���ҬO�Ĥ@����ܪ������C���]�t�Ҧ��D�n�޲z�u�@����s�A�Ѧp�U�ϩҥܪ��Ұʩΰ��� Directory Server�C�Y�n�˵�Ҧ��u�@�Ψ��s�A�z�γ\�ݭn���ʲM��C

�� 1-2 Directory Server Console �� [�u�@] ����

Directory Server console �̤W�h�� [�u�@] ���ҧt���ҰʡB���s�ҰʩM����ؿ��A���M��L�\�઺��s

���F���o�Ǥu�@�A�z�����H�֦��t�κ޲z���v�����ϥΪ̨���n�J�C�v���������ϥΪ̵L�k�ݨ� [�u�@] ��s�C

[�պA] ����

Directory Server Console �� [�պA] ���Ҵ��Ѥ����M��ܤ��A�Ψ��˵�έק�Ҧ��ؿ�]�w�ȡA�p�=X�B�ƻs�B���c�B�O��� Plug-in �]�w�ȡC�u���b�z�H�֦��t�κ޲z���v�����ϥΪ̨���n�J�ɡA�o�ǹ�ܤ��~���ϥΩΥͮġC

�����Ҫ�����t���Ҧ��պA�\�઺�𪬥ؿ�A�ӥk��h��ܱM��ΨӺ޲z�U�\�઺�����C�o�Ǥ����q�`�]�t��L���ҡB��ܤ��Χ���\���C�Ҧp�A�U����ܾ�ӥؿ�@��]�w�ȡC

�� 1-3 Directory Server Console �� [�պA] ����

Directory Server console �̤W�h�� [�պA] ������ܧ@����A���պA�`�I [�]�w] ���Ҫ��d�ҡC

��z��ܥ��𪬥ؿ�i�]�w���خɡA�Ӷ��إثe���]�w�ȷ|��ܦb�k���O���@�Φh�Ӽ��Ҥ��C�p�ݳo�dz]�w�Ȫ�����M�欰�A�аѾ\����n���y�z�U�\�઺���`�C��]�w�����P�A�Y���ܧ�b�x�s�ɷ|�ߧY�ͮġA��L���h�n���쭫�s�Ұʦ�A���ɤ~�|�ͮġC���A���������s�ҰʮɡA�D���x�N��ܹ�ܤ��q���z�C

���Ҥ����x�s���ܧ�|�b���ҦW�ٮǥH���аO�q���C�Y�ϱz�t�m�t�@�Ӷ��ة��˵��L�D�n���Ҥ��@�A���ҤW�٬O�|�O���x�s���ܧ�C[�x�s] �� [���]] ��s�i�M�Φܫ�w�i�]�w���ت��Ҧ����ҡA��O���|�v�T��L���ت����x�s�]�w�ȡC

�j�h�Ƥ�r���u���\�z��J�㦳�ӳ]�w�����T�y�k���ȡC�̾ڹw�]�A�b�y�k���T�H�e�A�]�w���һP�z��J���ȷ|�H���ϥ���ܡC�b�Ҧ��]�w�ȧ������Ļy�k�e�A[�x�s] ��s�|���ΡC�z�i�H��ܥα���r���N��ϥ���ܪ���~�ȡA�p�u��ı�պA�ߦn�]�w�v�ҭz�C

[�ؿ�] ����

�D���x�� [�ؿ�] ���Ҭ��F��K�s��A�H�𪬥ؿ���ܥؿ�ءC�b�����Ҥ��A�z�i�H�s��B��ܤνs��]�t���Ҧ����ةM�ݩʡC


�Ƶ�

�p�G�w�p�s��Ƥd�Ӷ��ت��M��A�Ыإ��s��dޥH�K�i��ֳt�s��C�p�ݫ�O�A�аѾ\�u�D���x���s��dޡv�C


�� 1-4 Directory Server Console �� [�ؿ�] ����

Directory Server Console �̤W�h�� [�ؿ�] ������ܥ����O�����𪬥ؿ�M�k���O�����ݩʭ�

�p�G�n�J�ɴ��Ѫ��s�� DN �㦳�R�*��s���v���A�h�i�H�N�պA���ص�@�붵�ب��˵�A�åB�i�H�����ק�C��O�A�z3�өl�רϥγz�L [�պA] ���ҥi�Ϊ���ܤ��Ӧw���ܧ�պA�]�w�ȡC

�z�L [�˵�] �\���A���ƭӥi�Ϊ��ﶵ�i�Ψ��ܧ� [�ؿ�] ���Ҫ��G���M���e�C�s�G���ﶵ�]�A�i�˵��@�𪬥ؿ�[�\�����ئb�����Ҧ����ءA�ӥB�]�i�H�b�k���椤����ݩʡC�w�]�O�b�k���˵��ءA�ӫD�b���𪬥ؿ�C

[�˵�] > [���] �ﶵ�i�ҥξ𪬥ؿ�Ҧ����ت� ACI ���ơB���⦸�Ƥΰ��Ϊ��A�ϥܡC�b �� 1-4 ���AACI ���ƩM��������ܩ󥪾𪬥ؿ�A�ӿ�ܶ��ت��ݩʭ���ܩ�k���椤�C�p�ݸԲӸ�T�A�аѾ\�u�𪬥ؿ��˵�ﶵ�v�C

[���A] ����

[���A] ������ܦ�A���έp��ƩM��x�ɰT���C���𪬥ؿ�C�X�Ҧ������A���ءA�b��ܮɡA�U���ت����e�|��ܦb�k���椤�C�Ҧp�A�U����ܤ�x�ɶ��ت�C

�� 1-5 Directory Server Console �� [���A] ����

Directory Server console �̤W�h�� [���A] ������ܰO���ɤ��e���d��

�q�D���x�˵�ثe���s�� DN

�z�i�H�˵�Ψӵn�J Directory Server Console �� �s�� DN�A��@�U�����ܥ��U�����n�J�ϥܧY�i�C�M��ثe���s�� DN �|��ܩ�n�J�ϥܮǡA�p���B�ҥܡG

��ܥثeô�� DN ���n�J�ϥ�

�ܧ�z���n�J����

��z�q Directory Server Console �إߩκ޲z���خɡA�H�η�z�����s�� Server Console �ɡA�t����z���ѳs�� DN �αK�X�ﶵ�A�H�n�J�D���x�C�p���i�ѧO���b�s��𪬥ؿ�ϥΪ̡A�H�M�w�ݭn�»P���@�~���s����v�C

�����Ұ� Server Console �ɡA�z�i�H�ؿ�޲z�� DN �n�J�C�b���ɭԡA�z����ܥH���P���ϥΪ̨���n�J�A�Ӥ������A���s�ҰʥD���x�C

�Y�n�b Server Console ���ܧ�z���n�J�G

  1. �b Directory Server Console �W�A�п�� [�u�@] ���ҡA�M���@�U [�H�s�ϥΪ̵n�J�ؿ��A��] ���ҮǪ���s�C�Ϊ̡A�b�t�@�ӥD���x���Ҥ��ɡA�п�� [�D���x] > [�n�J���s�ϥΪ�] �\��?�ءC
  2. ��ܵn�J��ܤ��C

  3. �п�J�s DN �M�K�X�A�M���@�U [�T�w]�C
  4. �п�J�z�Q�n�Ψӳs����A�������ت������O�W�١C�Ҧp�A�p�G�z�Q�n�H�ؿ�޲z���s���A�h�Цb [��O�W��] ��r����J�U�C DN�G

    cn=Directory Manager

�H�U���`�A�|�i�@�B�ѻ��ؿ�޲z�� DN �M�K�X�C

�ϥνu�W����

�u�W���� Directory Server Console ���j���<��ҩM��ܤ��ѤW�U������T�C[����] ��s�q�`��b�o�Ǥ������k�U���C�Y�n�b���ù�W�ҰʤW�U������A����L�ֳt��l�׬� Alt-P�C

�Ұʽu�W����|�b�D���x�������s����� HTML �榡�������C�z�i�H�b�o�ӭ����W��@�U [�b�s��Ұ�] ��s�A�b�~���s�� (�p Mozilla) ����ܦP�@�����C�u�W����W����ԲӸ�T���s���A�]�|�}�ҥ~���s���C

�C�ӽu�W����|���ѹ�3�����ҩι�ܤ��ҥ]�t�U���Ϋ�s������C��z�z�L�D���x���!B��J�έק�ȮɡA�o�Ǹ�T�i�H��ޱz�C

Directory Server ������t�Ψ̦s�� Administration Server�C�p�G�b Administration Server �����ݹq���W��� Directory Server Console�A�z�����T�{�U�C�U���G

�D���x�ŶKï

Directory Server Console �ϥαz���t�ΰŶKï�ƻs�B�ŤU�ζK�W��r�C�Y�n��ֿ�J�r���A��z�b [�ؿ�] ���Ҥ��s��ɡA�i�H�N���ت� DN �� URL �ƻs��ŶKï�C

�}�ҥ����b��r��줤�K�J DN �� URL ����ܤ��Υt�@�Ӽ��Ҥ��e�G

  1. �b Directory Server Console �̤W�h�� [�ؿ�] ���ҤW�A�s���Ӿ𪬥ؿ�A��� (��@�U�ƹ�����) �n�ƻs�� DN �� URL �����ءC
  2. �M���ܥ\��?�� [�s��] > [�ƻs DN] �� [�s��] > [�ƻs URL]�C

�D���x�]�w��

Directory Server Console ���ѳ\�h�]�w�ȡA�i�ۭq [�պA] �� [�ؿ�] ���Ҥ���T����ܤ覡�C

��ı�պA�ߦn�]�w

��z�b�̤W�h [�պA] ���ҤW����줤�ק�պA�ѼƻP��J�ȮɡADirectory Server Console �|�ϥαm���r��ܦ��Ŀ�J�C�Ҧp�A�p�G�ҥάY���\��A�ӥ\��n�D��J�i�@�B���պA�ȡA�h���n��쪺���ҷ|�H�����ܡA���z��J���ĭȤ���h�|�ܦ��Ŧ�C

�̹w�]�ȡA�D���x�ϥά��M�Ŧ�A��z�i�H�̤U�C�覡�ק惡�欰�G

  1. �b Directory Server Console ����N���ҤW�A��� [�s��] > [�ߦn�]�w] �\��?�ءC�b [�D���x�ߦn�]�w] ��ܤ��A��� [��L] ���ҡC
  2. ��ܱz�ߦn����ı�պA�аO������s�C�z�i�H��ܱm�⪺�r���Φr���~�[�A�ΦP�ɿ�ܨ�̡C
  3. �p�� [�D���x�ߦn�]�w] ��ܤ���L���ҤW�U���]�w�Ȫ��y�z�A�аѾ\�mAdministration Server Administration Guide�nChapter 2 �� "Customizing Server Consol"�C
  4. �M���@�U [�T�w] �H�x�s�ܧ�C

  5. ���� Server Console ���Ҧ���A�A���s�ҰʡC

�𪬥ؿ��˵�ﶵ

�b Directory Server Console �̤W�h�� [�ؿ�] ���ҤW�A[�˵�] �\��?���إi��z��ܾ𪬥ؿ��L��T�A�åi��ܥk���O����ܪ����e�C

�U�C [�˵�] �ﶵ�|�v�T [�ؿ�] ���Ҫ����e�G


�t�m LDAP �Ѽ�

LDAP �ѼƬO�ؿ��A�������򥻳]�w�ȡA�Ҧp�ؿ�޲z���O�W�� (DN)�B�����Ū�]�w�B�s����պA�ί�_�l�ܩҦ��ؿ�ק�ɶ����C

�t�m�ؿ�޲z��

�ؿ�޲z���O���v������A���t�κ޲z��A�۷�� UNIX �� root �ϥΪ̡C�s���|�M�Φܱz�w�q���ؿ�޲z���ءC�z�w�b�w�˹L�{����w�q�F�����ءC�w�]�� cn=Directory Manager�C

�ؿ�޲z�� DN �x�s�b nsslapd-rootDN �ݩʤ��A�K�X�x�s�b cn=config �$䪺 nsslapd-rootpw �ݩʤ��C

�ϥ� Directory Server Console �ܧ�ؿ�޲z�� DN�B�K�X�H�Φ��K�X�ҨϥΪ��[�K���c�G

  1. �H�ؿ�޲z���n�J�D���x�C
  2. �Y�z�w�g�n�J�D���x�A�p�ݦp��H���P�ϥΪ̨���n�J������A�аѾ\�u�ܧ�z���n�J����v�C

  3. �b�̤W�h�� [�պA] ���ҤW�A����s��𪬥ؿ�ڳ�����A���`�I�A�æb�k���O����� [�]�w��] ���ҡC
  4. �b [�ؿ�޲z�� DN] ��줤��J�s����O�W�١C�w�]�ȬO�w�˴v��ҩw�q���ȡC
  5. �q [�޲z��K�X�[�K] �U�Ԧ��\��?�A����x�s���c�A���A���Ψ��x�s�ؿ�޲z��K�X�C
  6. �ШϥΩҴ��Ѫ���r���A��J�s�K�X�ð��T�{�C
  7. ��@�U [�x�s]�C

�ܧ�ؿ��A���s���𸹽X

�z�i�Q�� Directory Server Console ���ܧ� cn=config ���ؤU�� nsslapd-port �ݩʭȡA�ק�ϥΪ̥ؿ��A�����s����Φw���s���𸹽X�C

�p�G�z�Q�n�ק�]�t Sun Java System �պA��T (o=NetscapeRoot �𪬤l�ؿ�) �� Directory Server �s����Φw���s����A�i�H�z�L Directory Server Console �i��ק�C

�p�G�z�ܧ�պA�ؿ�ΨϥΪ̥ؿ�s����Φw���s���𸹽X�A3���A�ѤU�C�v�T�G

�ϥΤU�C�{�ǭק� Directory Server �b��ť�ǤJ LDAP �n�D�ɡA�ҨϥΪ��s����Φw���s����C�Y�n�ק� DSML �n�D���s����A�аѾ\�u�t�m DSML�v�C

  1. �b Directory Server Console �̤W�h�� [�պA] ���ҤW�A��ܧt����A���W�٪��ڸ`�I�A�M��b�k���O����� [���] ���ҡC
  2. ������ܦ�A���ثe�� LDAP �q�T��w���s����]�w�ȡC

  3. �b [�s����] ��줤��J�z�n��A���Ω�i��D SSL �q�T���s���𸹽X�C�w�]�ȬO 389�C
  4. �p�G�w���� 11 ���u�޲z���ҩM�[�K�v�ҭz�b����A���W�ҥ� SSL�A�z�i�H���\�w���s����W���s�u�G
    1. ��ܭn�ϥΦw���s����M�D�w���s���𪺿ﶵ�C
    2. �b [�w���s����] ��줤��J�z�n��A���Ω�i�� SSL �q�T���s���𸹽X�C�w�]�ȬO 636�C
    3. �z��w���[�K�s���𸹽X���i�H�P�z�Ω�@�� LDAP �q�T���s���𸹽X�ۦP�C

  5. ��@�U [�x�s]�A�M��A���s�Ұʦ�A���C

�p�ݸ�T�A�аѾ\�u�ҰʩM����ؿ��A���v�C

�]�w�����Ū�Ҧ�

�b�z���ؿ�A�C�@�ӧ=X���i�H��m�W�ߪ���Ū�Ҧ��A�ӥB�p�G�w�q�F�S�w�ѷӤ]�i�H�Ǧ^���ѷӡCDirectory Server �]���ѥi�M�ΦܩҦ��=X�������Ū�Ҧ��A�ӥB��w�q�F����ѷӮɡA�]�i�H�Ǧ^���ѷӡC

�����Ū�Ҧ��O�]�p����t�κ޲z���b���p���s�s�s�=X���dޮɡA�P�ɭק�F�ؿ�e�C���o�ӭ�]�A�����Ū�Ҧ����|�M�ΦܤU�C�պA�$�G

�L�װ�Ū�]�w�p��A�u�s����O�v(Access Control Instructions�AACI) ��3�ӫO�@�o�Ǥ$�A�H���D�޲z�ϥΪ̶i��ק� (�аѾ\�� 6�u�޲z�s���v)�C�����Ū�Ҧ��i����ؿ�Ҧ���L�=X����s�@�~�A�]�A�ѥؿ�޲z��Ұʪ���s�@�~�C

�p�G�ҥΤF��Ū�Ҧ��A�]�|���_�=X�W���ƻs�C�D��ƥ��N���A�ܧ���ƻs�A���ޥ��|����ƻs�b�Ұʰ�Ū�Ҧ��e�ҧ@���Ҧ��ܧ�C�b���ΰ�Ū�Ҧ��e�A�Τ�ƥ����|�����s�C�h���D��ƻs�ť����D��|�ܧ���ƻs�A�]�L�k�����L�D���s�C

�Y�n�ҥΩΰ��Υ����Ū�Ҧ��G

  1. �b Directory Server Console �̤W�h�� [�պA] ���ҤW�A��ܲպA�𪬥ؿ�ڸ`�I�A�M��b�k���O����� [�]�w��] ���ҡC
  2. ��ܩΨ���� [��A������Ū] �֨���C
  3. ��@�U [�x�s]�C�ܧ�N�ߧY�ͮġC

�p�����N�ӧO�=X��m�b��Ū�Ҧ�����T�A�аѾ\�u�]�w�=X��Ū�Ҧ��v�C

�l�ܥؿ�ت��ק�

�z�i�N��A���t�m�����@�s��إߩέקﶵ�ت��S���ݩʡG

�Y�n�ҥ� Directory Server �l�ܦ���T�G

  1. �b Directory Server Console �̤W�h�� [�պA] ���ҤW�A��ܲպA�𪬥ؿ�ڸ`�I�A�M��b�k���O����� [�]�w��] ���ҡC
  2. ��� [�l�ܶ��حק隸��] �֨���C
  3. ��A���|�N creatorsName�BcreateTimestamp�BmodifiersName �M modifyTimestamp �ݩʥ[�J�ܨC�@�ӷs�ةέק諸���ءC�{�����ؤ��|�]�t�إ��ݩʡC

  4. ��@�U [�x�s]�A�M��A���s�Ұʦ�A���C
  5. �p�ݧ�h��T�A�аѾ\�u�ҰʩM����ؿ��A���v�C


���� Plug-in ñ�W

���� Plug-in ñ�W�O Directory Server 5.2 ���s�W�\��CDirectory Server �Ҵ��Ѫ� Plug-in �U���@�ӼƦ�ñ�W�A�i�b�ҰʮɥѦ�A�����H���ҡC�̹w�]�ȡA��A���N�|���� Plug-in ñ�W�A��L��ñ�W�O�_�s�b�Φ��ĻP�_�A�����|��J�C�@�� Plug-in�C

����ñ�W���U�C�u�I�G

�t�m Plug-in ñ�W������

  1. �b Directory Server Console �̤W�h�� [�պA] ���ҤW�A��ܲպA�𪬥ؿ� [Plug-in] �`�I�C�ثe��ñ�W���ҭ�h��ܦb�k���O���C
  2. ��ܤU�C�䤤�@�ӿﶵ�G
    • ���n���� Plug-in ��ñ�W - ��A���պA���w�q���Ҧ� Plug-in�A����ñ�W�p�󳣤��H��J�C���|�]�� Plug-in ñ�W����ܥ��ĵ�i�ο�~�C
    • �Хܧt�L��ñ�W�� Plug-in - ��A���պA���w�q���Ҧ� Plug-in ���|��J�A���A���N�T�{�C�� Plug-in ��ñ�W�C�p�G Plug-in �G�i���ɮ׽X�w�g�D����}�a�Añ�W�N���A���ġA�ӥB��A���N�b�Ұʮɦb�M��~��x�ɤ���ܿ�~�T���C�S��ñ�W�� Plug-in �]�|�[�W�мm�C

      �p�G�z���ۭq�B���g�Lñ�p�� Plug-in�A�o�O��ij���ﶵ�C�z�� Plug-in �N�|��J�A��z�٬O����˵�Ҧ��wñ�p Plug-in �����A�C

    • �ڵ��t�L��ñ�W�� Plug-in - ��A���N�T�{��A���պA���w�q���Ҧ� Plug-in ��ñ�W�A�ӥB�u��J�t����ñ�W�� Plug-in�C��A���N�b�Ұʮɦb�M��~�O����ܿ�~�T���A��X���� Plug-in �t�L��ñ�W�εLñ�W�C

      �o�O�̦w�����ﶵ�A��z�N�L�k��J�ۭq�B���g�Lñ�p�� Plug-in�C

  3. ��@�U [�x�s]�A�M��p�u�ҰʩM����ؿ��A���v���ҭz���s�Ұ� Directory Server�C

�˵� Plug-in �����A

  1. �b Directory Server Console �̤W�h�� [�պA] ���ҤW�A�i�}�պA�𪬥ؿ� [Plug-in] �`�I�A�ÿ�ܭn�T�{�� Plug-in�CPlug-in �ثe���պA��ܦb�k���O���C
  2. [ñ�W���A] ������ Plug-in ��ñ�W���Ҫ��A�A�å]�t�U�C�Ȥ��@�G
    • ���� - �N��A���t�m�������� Plug-in ñ�W�ɡA�Ҧ� Plug-in ���B��ñ�W���A�C�u���n���� Plug-inñ�W�ɡA�~�|��ܤU�C���A�C
    • ����ñ�W - Plug-in �պA����ñ�W�A�Ӹ�ñ�W�ŦX Plug-in �G�i���ɮ׽X���`�M�ˬd�X�F�� Plug-in �������䴩�C�u���n��ñ�W�[�W�мm��ڵ��L��ñ�W�ɡA�~�|��ܤU�C���A�C
    • �L��ñ�W - Plug-in �պA����ñ�W�A���ñ�W���ŦX Plug-in �G�i���ɮ׽X���`�M�ˬd�X�F�o�Ӫ��A��� Plug-in �i��w�g�D��«��C
    • �Lñ�W - Plug-in �պA������ñ�W�Ѧ�A�����ҡC


�t�m DSML

���F�b���q���ؿ�s��q�T��w (Lightweight Directory Access Protocol�ALDAP) ���B�z�n�D�~�ADirectory Server �{�b�]�^3�ϥΥؿ�A�ȼаO�y������ 2 (Directory Service Markup Language version 2�ADSMLv2) �ǰe���n�D�CDSML ���Τ�ݽs�X�ؿ�@�~���t�~�@�ؤ覡�A��O��A���|�H�Ҧ��ۦP���s���Φw���ʥ\��A�N DSML ��P����L�n�D�ӳB�z�C�ƹ�W�ADSML �B�z�{�Ǥ��\�ܦh��L�������Τ�ݥi�H�s��z���ؿ�e�C

Directory Server �䴩�z�L�W��r�ǿ�q�T��w (Hypertext Transfer Protocol�AHTTP/1.1) �ϥ� DSMLv2�A�H�Ψϥ�²�檫��s��q�T��w (Simple Object Access Protocol�ASOAP) ���� 1.1 �@���{���]�p�q�T��w�A�H�ǿ� DSML ���e�C�p�ݦ���o�dzq�T��w�M DSML �n�D�d�Ҫ��ԲӸ�T�A�аѾ\�u�ϥ� DSMLv2 �s��ؿ�v�C

�ҥ� DSML �n�D

�ѩ� LDAP ���s��ؿ�зdzq�T��w�A�̹w�]�A�w�� Directory Server ��A���|�ҥ� DSML �n�D�C�p�G�z�Q�n�ۤv����A�����^3�z�L HTTP/SOAP �ǰe�� DSML �n�D�A�����T��ҥγo���\��C

�Y�n�z�L�D���x�b�z����A���W�ҥ� DSML �n�D�G

  1. �b Directory Server Console �̤W�h�� [�պA] ���ҤW�A��ܲպA�𪬥ؿ�ڸ`�I�A�ÿ�ܥk���O���� [���] ���ҡC
  2. ��� [�ҥ� DSML] �֨���A�ÿ�ܤU�C�䤤�@�Ӧw���ﶵ�G�u���w�ҥ� SSL �ɤ~�i�ϥΦw���s����ﶵ�A�p�� 11 ���u�޲z���ҩM�[�K�v�ҭz�C
    • �ȫD�w���s���� - �u����D�w���s����W�z�L���[�K HTTP �� DSML �n�D�C
    • �Ȧw���s���� - �u����w���s����W�z�L HTTPS �� DSML �n�D�C
    • �w���M�D�w���s���� - ��ӳs���𳣧@�Τ��A�Τ�ݥi��ܥ�@�ӡC
  3. �M��s��U�C���@�����G
    • �s���� - �Ω󱵦� DSML �n�D�� HTTP �s����C
    • �[�K�s���� - �ϥ� SSL �����[�K DSML �n�D�� HTTP �s����C
    • �۹� URL - �۹諸 URL�A�b���[�W�D��M�s����ɡA�M�w�Τ�ݥ����ΨӶǰe DSML �n�D������ URL�C
    • �̾ڹw�]�A�Ӧ�A���|�B�z�ǰe�ܤU�C URL ���n�D�G

         http://host:80/dsml

  4. ��@�U [�x�s]�A�N�|����z�������s�ҰʸӦ�A���A�H�}�l�^3 DSML �n�D�C

�Y�n�z�L��O��ҥ� DSML �n�D�G

  1. �а��U�C ldapmodify ��O�A�ҥ� DSML �e�� Plug-in �íק��]�w�ȡC�ק� ds-hdsml-port�Bds-hdsml-secureport �� ds-hdsml-rooturl �ݩʬO��Ϊ��G
  2. % ldapmodify -h host -p LDAPport -D "cn=Directory Manager" -w passwd
    dn:cn=DSMLv2-SOAP-HTTP,cn=frontends,cn=plugins,cn=config
    changetype:modify
    replace:nsslapd-pluginEnabled
    nsslapd-pluginEnabled:on
    -
    replace:ds-hdsml-port
    ds-hdsml-port:DSMLport
    -
    add:ds-hdsml-secureport
    ds-hdsml-port:secureDSMLport
    -
    replace:ds-hdsml-rooturl
    ds-hdsml-root:relativeURL
    -
    ^D

  1. �ק粒�� DSML �e�� Plug-in ��A�z�������s�Ұʦ�A�����ܧ�ͮġC���L�A�b�z���s�Ұʦ�A���e�A�γ\�|�Q�n�t�m DSML ���Ҫ��w���ʩM�ѧO��M�A�p�U�C���`���ҭz�C

�t�mDSML �w����

���F��e���`���ҭz���w���s����]�w�H�~�A�z�]�i�H�t�m���� DSML �n�D�ɩһݭn���w���h�šCDSML �e�� Plug-in �� ds-hdsml-clientauthmethod �ݩʡA�M�w�Τ�ݩһݭn�����Ҥ�k�C���ݩʥi�H�֦��U�C���ȡG

�p�G HTTP �n�D���J�L���Ҥ]�S�����ѱ��v���Y�A�h��A���|�H�ΦW�s����� DSML �n�D�C�U�C���p���]�|�ϥΰΦW�s���G

���� ds-hdsml-clientauthmethod �ݩʭȬ���A�p�G���ѤF���ҡA��O�����ҫo�L�k��3�ܥ�󶵥ءA�Ϊ̦p�G�w��w�F HTTP ���v���Y�A��O�L�k��M�ܨϥΪ̶��ءA�h�N�|�ڵ� DSML �n�D�åX�{��~�T�� 403:�u�T��v�C

�Y�n�z�L�D���x�]�w DSML �w���ݨD�G

  1. �b Directory Server �D���x�̤W�h�� [�պA] ���ҤW�A��ܲպA�𪬥ؿ�ڸ`�I�A�ÿ�ܥk���O���� [�[�K] ���ҡC
  2. �z�����w�g���� 11 ���u�޲z���ҩM�[�K�v�ҭz�t�m�αҥ� SSL�C

  3. �b [DSML �Τ������] ��줤�A�q�U�Ԧ��\����ܨ䤤�@�ӿﶵ�C
  4. ��@�U [�x�s]�A���ۭ��s�Ұʦ�A���H�j����s���w���]�w�C

�Y�n�z�L��O��]�w DSML �w���ݨD�G

  1. �а��U�C ldapmodify ��O�A�s�� DSML �e�� Plug-in ���ݩʡG
  2. % ldapmodify -h host -p LDAPport -D "cn=Directory Manager" -w passwd
    dn:cn=DSMLv2-SOAP-HTTP,cn=frontends,cn=plugins,cn=config
    changetype:modify
    replace:ds-hdsml-clientauthmethod
    ds-hdsml-clientauthmethod:httpBasicOnly or
     clientCertOnly or clientCertFirst
    ^D

  3. �ק粒�� DSML �e�� Plug-in ��A�z�������s�Ұʦ�A���A�j���榹�s���w���]�w�C

DSML �ѧO��M

�b���S�����Ҫ������ҮɡADirectory Server �|�ϥκ٬��ѧO��M�����ӨM�w���� DSML �n�D��3�ϥΪ��s�� DN�C�����|�q HTTP �n�D�� Authorization ���Y���^���T�A�M�w�n�Ω�s�����ѧO�C�p�ݦ�������y�z�A�аѾ\�u�ѧO��M�v�C

��A���պA�����U�C���ءA���� DSML-over-HTTP ���w�]�ѧO��M�G

dn:cn=default,cn=HTTP-BASIC, cn=identity mapping, cn=config
objectclass:top
objectclass:nsContainer
objectclass:dsIdentityMapping
cn:default
dssearchbasedn:ou=People,userRoot
dssearchfilter:(uid=${Authorization})

����M�|�b ou=People,userRoot �𪬤l�ؿ�j�M�� uid �ݩʲŦX Authorization ���Y����w���ϥΪ̦W�٪����ءCuserRoot �O�z�b�w�˥ؿ�ɩw�q���=X�A�Ҧp dc=example,dc=com�C

�b��M�����ݩʤ��A�z�i�H�ϥ� ${header} �榡���w�d��m�A�䤤 header �O HTTP ���Y���W�١CDSML ��M���̱`�ϥΪ����Y���G

�Y�n�� DSML �n�D��椣�P���ѧO��M�A�Ь� HTTP ���Y�w�q�s���ѧO��M�G

  1. �s��w�]�� DSML-over-HTTP �ѧO��M�A�ά����q�T��w�إߦۭq����M�C�p���ѧO��M���ؤ��U�ݩʪ��w�q�A�аѾ\�u�ѧO��M�v�C�o�ǹ�M�������U�C���ؤ��U�G
    cn=HTTP-BASIC, cn=identity mapping, cn=config.

�z�i�H�̷ӤU�C��ؤ覡���@�إ߷s��M�G

�t�η|����ۭq��M�A�Ӧp�G�ۭq��M�������\�A�h�A���w�]��M�C�p�G�Ҧ���M�b�M�w DSML �n�D���s�� DN �ɳ����ѤF�A�h�|�T��éڵ� DSML �n�D (��~ 403)�C



�W�@��      �ؿ�      �d�      �U�@��     


Copyright 2004 Sun Microsystems, Inc. All rights reserved.