Index     Next     
iPlanet Directory Server Access Management Edition Installation and Configuration Guide



Contents


About This Guide
What You Are Expected to Know
The iPlanet Directory Server Access Management Edition Documentation Set
Documentation Conventions Used in This Manual
Typographic Conventions
Terminology
Related Information

Part 1 Read This First


Chapter 1 Introducing iPlanet Directory Server Access Management Edition

iPlanet Products Form the DSAME Solution
Directory Server
Policy Service
Management Service
Web Server
URL Policy Agent
Key Features and Benefits
Chapter 2 Deployment Considerations
Directory Issues
If You Already Have an Existing Directory
DSAME Schema
Compliant vs. Default DIT
Unsupported DITs
Directory Replications
Policy Management Issues
Roles
Policies and URL Policy Agents
Service Attributes
Installing Other Products for Use with DSAME Services
Remote Web Servers
Multiple Directory Servers for Failover and High Availability
Load-Balancing Applications
Hardware and Software Requirements
Optimal Hardware Requirements
Recommended Hardware Configurations
Operating System Requirements
Remote Web Server Requirements
Web Browser Requirements

Part 2 Solaris Installation Instructions


Chapter 3 The DSAME Installation Program for Solaris

Before You Begin
Installation Program Options
Determining Which Installation Options to Use
Starting DSAME Services
Logging In to DSAME
Uninstalling DSAME
Chapter 4 Simple Installations with No Existing Directory Server
Installing DSAME Services
To Install DSAME Services with Directory Server
Installing a Stand-Alone iPlanet Directory Server
Installing Directory Server With the DSAME Package Format
Installing Directory Server Without the DSAME Package Format
Configuring an Existing Directory Server 5.1 to Work with DSAME
To Configure an Existing Directory Server
Optimizing Directory Server for DSAME
Chapter 5 Using an Existing Directory Server
Before You Begin
Supported DITs and Unsupported DITs
Background for Examples Used in This Chapter
Step 1: Install Directory Server 5.1 and Configure it to Work with DSAME
Step 2: Install DSAME Services
Step 3: (Optional) Add Your Custom Object Classes to DSAME Schema
Step 4: (Optional) Configure Alternative Naming Attributes
Step 5: Load DSAME LDIF into Your Directory
Step 6: Load DSAME Service Attributes into Your Directory
Step 7: (Optional) Add DSAME ACIs to Your Default Organization
Step 8: Remove Unnecessary Files
Step 9: Start DSAME
Step 10: Add DSAME Object Classes and Attributes to Existing Directory Entries
Results of DSAME and Directory Modifications
Chapter 6 Installing URL Policy Agents
How URL Policy Agents Work
Protecting the Web Server That Runs DSAME Services
To Install a Policy Agent with the Policy and Management Services
Protecting Content on Remote Web Servers
Providing Failover Protection for DSAME Agents
To Install the Policy Agent on a Remote Web Server
Installing Multiple Policy Agents on the Same Computer System
To Install a Second Agent on the Same Computer (Using iPlanet Web Server 6.x)
To Install a Second Agent on the Same Computer (Using iPlanet Web Server 4.x)
Disabling URL Policy Agents
Chapter 7 Basic Configurations
Installing Multiple DSAME Instances Against the Same Directory Server
Support for Directory Replication and High Availability
Replication Considerations
Configuring DSAME to Support Directory Replication
Configuring a Load-Balancing Application to Work With DSAME
Secure Sockets Layer (SSL)
Step 1: Enable LDAP Over SSL
Step 2: Enable DSAME to Run in SSL Mode
Step 3: (Optional) Install and Configure a URL Policy Agent for SSL

Part 3 Windows 2000 Installation Instructions


Chapter 8 The DSAME Installation Program for Windows 2000

Before You Begin
Installation Program Options
Determining Which Installation Options to Use
Starting DSAME Services
Logging In to DSAME
Uninstalling DSAME
Chapter 9 Simple Installations with No Existing Directory Server
Installing DSAME Services and Directory Server
To Install DSAME Services with a New Directory Server
Installing a Stand-Alone iPlanet Directory Server
To Install a Stand-Alone iPlanet Directory Server
Optimizing Directory Server for DSAME
Configuring an Existing Directory Server 5.1 to Work with DSAME
To Configure an Existing Directory Server
Chapter 10 Using an Existing Directory Server
Before You Begin
Supported DITs and Unsupported DITs
Background for Examples Used in This Chapter
Step 1: Install Directory Server 5.1 and Configure it to Work with DSAME
Step 2: Install DSAME Services
Step 3: (Optional) Add Your Custom Object Classes to DSAME Schema
Step 4: (Optional) Configure Alternative Naming Attributes
Step 5: Load DSAME LDIF into Your Directory
Step 6: Load DSAME Service Attributes into Your Directory
Step 7: (Optional) Add DSAME ACIs to Your Default Organization
Step 8: Remove Unnecessary Files
Step 9: Start DSAME
Step 10: Add DSAME Object Classes and Attributes to Existing Directory Entries
Results of DSAME and Directory Modifications
Chapter 11 Basic Configurations
Installing Multiple DSAME Instances Against the Same Directory Server
Support for Directory Replication and High Availability
Replication Considerations
Configuring DSAME to Support Directory Replication
Configuring a Load-Balancing Application to Work With DSAME
Secure Sockets Layer (SSL)
Step 1: Enable LDAP Over SSL
Step 2: Enable DSAME to Run in SSL Mode

Part 4 Appendixes


Appendix A DSAME Object Classes and Attributes

Using DSAME Object Classes as Markers
Using Alternative Naming Attributes
DITs That Cannot Be Managed by DSAME
Limitations to Consider
Examples of Unsupported DITs
ObjectClass and Attribute Descriptions
Organization
Container (Organizational Unit)
People Container
Static Group
Assignable Dynamic Group
Filtered Group
User
Appendix B Securing Your Web Server
Requiring Authentication
Creating a Trust Database
Requesting and Installing a VeriSign Certificate
Requesting and Installing Other Server Certificates
Migrating Certificates When You Upgrade
Managing Certificates
Installing and Managing CRLs and CKLs
Setting Security Preferences
Using External Encryption Modules
Setting Client Security Requirements
Setting Stronger Ciphers
Considering Additional Security Issues
Appendix C Managing SSL
Introduction to SSL in the Directory Server
Obtaining and Installing Server Certificates
Activating SSL
Setting Security Preferences
Using Certificate-Based Authentication
Configuring LDAP Clients to Use SSL
Index

Index     Next     
Copyright 2002 Sun Microsystems, Inc. All rights reserved.

Last Updated March 27, 2002