Sun logo      Previous      Contents      Index      Next     

Sun ONE Messaging and Collaboration 6.0 Schema Reference Manual

Chapter 5
iPlanet Delegated Administrator for Messaging Classes and Attributes

This chapter describes LDAP object classes and attributes for iPlanet Delegated Administrator for Messaging implementing Sun ONE LDAP Schema v.1. The objects and attributes are listed alphabetically.

The chapter is divided into two sections:


Object Classes

This chapter describes the following object classes used by Delegated Administrator and those object classes only used in Sun ONE LDAP Schema v.1.


inetDomainOrg

Supported by

iPlanet Messaging Server 5.0

Definition

Used for Sun ONE LDAP Schema v.1. Auxiliary class for supporting a Sun ONE Delegated Manager for Messaging managed domain organization.

This object class is used in conjunction with the structural class organization to define a domain organization. A domain organization is usually created as a way of introducing hierarchy beneath a customer subtree and assigning administrators for that domain organization. To create a suborganization beneath the parent tree and designate a set of administrators for that suborganization, you would create a domain organization node by using organizationalUnit and inetDomainOrg object classes. For example, siroe.com could have a customer subtree with the DN:

ou=east,o=siroe.com,o=basedn.

How to provision a domain organization for Sun ONE LDAP Schema v.1 is described in the iPlanet Messaging Server 5.2 Provisioning Guide.

Superior Class

top

Object Class Type

auxiliary

OID

2.16.840.1.113730.3.2.132

Required Attributes

N/A

Allowed Attributes

domOrgMaxUsers, domOrgNumUsers


inetMailGroupManagement

Supported by

iPlanet Messaging Server 5.0

Definition

Used for Sun ONE LDAP Schema v.1 only. Used to extend the base entry created by groupOfUniqueNames. inetMailGroupManagement is used to store attributes for managing a distribution list by using Delegated Administrator for Messaging. This object class is used in conjunction with inetMailGroup and inetLocalMailRecipient. The attributes in this object class have no operational impact on the messaging server’s MTA or message access/message store.

Superior Class

top

Object Class Type

auxiliary

OID

2.16.840.1.113730.3.2.149

Required Attributes

N/A

Allowed Attributes

mgrpAddHeader, mgmanDenySubscribe, mgmanGoodbyeText, mgmanHidden, mgmanIntroText, mgmanJoinability, mgmanMemberVisibility, mgmanVisibility, multiLineDescription


inetManagedGroup

Supported by

iPlanet Messaging Server 5.0

Definition

Used to define a managed group. If a managed group is just a department or family group, then the structural class to use is top, but it can also be used to make a statically defined group (from groupOfUniqueNames) and make that a managed group.

Superior Class

top

Object Class Type

auxiliary

OID

2.16.840.1.113730.3.2.137

Required Attributes

cn

Allowed Attributes

description, mnggrpAdditionPolicy, mnggrpBillableUser, mnggrpCurrentUsers, mnggrpDeletionPolicy, mnggrpMailQuota, mnggrpMaxUsers, mnggrpStatus, mnggrpUserClassOfServices, nsdaModifiableBy, owner


nsManagedDept

Supported by

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Stores information for a non-administrator group.

Superior Class

groupOfUniqueNames

Object Class Type

auxiliary

OID

2.16.840.1.113730.3.2.88

Required Attributes

N/A

Allowed Attributes

nsMaxDepts, nsMaxUsers, nsNumDepts, nsNumUsers, nsdaModifiableBy, owner


nsManagedDeptAdminGroup

Supported by

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Stores information for a group of administrators for iPlanet Delegated Administrator.

Superior Class

top

Object Class Type

OID

2.16.840.1.113730.3.2.111

Required Attributes

objectClass

Allowed Attributes

N/A


nsManagedDomain

Supported by

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Used only for versions of Messaging Server using iPlanet Delegated Administrator. It contains information necessary to administer domains.

Superior Class

top

Object Class Type

OID

2.16.840.1.113730.3.2.86

Required Attributes

objectClass

Allowed Attributes

nswcalDisallowAccess, nsMaxDepts,nsMaxDomains, nsMaxMailLists, nsMaxUsers, nsNumDepts, nsNumDomains, nsNumMailLists, nsNumUsers, nsdaModifiableBy, owner


nsManagedFamilyGroup

Supported by

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Stores information for a family group managed by a delegated administrator. The family group is like a Group, with a few differences. It was added primarily to support Delegated Administrator deployments using Sun Internet Message Service (SIMS) 4.0.

Superior Class

top

OID

2.16.840.1.113730.3.2.89

Required Attribute

objectClass

Allowed Attributes

nsMaxUsers, nsNumUsers, nsdaModifiableBy, owner


nsManagedISP

Supported by

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Tracks the number of sub-organizations that can be created under this object.

Superior Class

top

OID

2.16.840.1.113730.3.2.85

Required Attribute

objectClass

Allowed Attributes

nsNumDomains


nsManagedMailList

Supported by

iPlanet Messaging Server 5.0;deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Stores information for a mail list created by enabled users. A mail list must contain this object class in order to be managed by Delegated Administrator.

Superior Class

top

Object Class Type

OID

2.16.840.1.113730.3.2.90

Required Attributes

objectClass

Allowed Attributes

nsMaxUsers, nsNumUsers, nsdaModifiableBy, owner


nsManagedOrgUnit

Supported by

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Stores information for a Delegated Administrator managed organizational unit.

Superior Class

top

OID

2.16.840.1.113730.3.2.87

Required Attributes

objectClass

Allowed Attributes

nsdaModifiableBy, owner


nsManagedPerson

Supported by

iPlanet Messaging Server 5.0; deprecated for Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2

Definition

This object class is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Stores information about a user. A user entry must contain this object class in order to be managed by Delegated Administrator.

Superior Class

top

Object Class Type

OID

2.16.840.1.113730.3.2.91

Required Attributes

objectClass

Allowed Attributes

memberOf, nsdaCapability, nsdaDomain, nsSearchFilter, nsdaModifiableBy, owner


nsUniquenessDomain

Supported by

iPlanet Messaging Server 5.0; deprecated for Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2

Definition

Sun ONE LDAP Schema v.1 object class in support of Delegated Administrator for Messaging. If you are still using Sun ONE LDAP Schema v.1, then this object is still valid; otherwise it is deprecated.

This object class is a marker to identify the subtree where the uniqueness of uid should be enforced. The uid uniqueness plugin used this to determine the scope or sphere of influence for enforcing uniqueness.

Superior Class

top

OID

2.16.840.1.113730.3.2.115

Required Attributes

objectClass

Allowed Attributes

N/A


Attributes


domainUidSeparator

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetDomainOrg

Definition

This attribute is used only for Sun ONE LDAP Schema v.1.

This attribute is used by the messaging server to override the default mailbox (MB) home. When present, this attribute specifies that compound user identifications (UIDs) are used in this domain and this attribute specifies the separator. For instance, if + is the separator, the mailbox names in this domain are obtained by replacing the right most occurrence of + in the uid with @. To map an internal mailbox name to the UID, the right most occurrence of @ is replaced with a + in the mailbox name.

While substitution of an @ for the UID separator is sufficient to generate a mailbox name, this may not be the same as any of the user’s actual email addresses.


Note  

Format of internal mailbox names is uid@domain, where “domain” is DNS domain mapping to the namespace. The only exception to this rule is mailbox names for users in default domain where only the uid is used to construct internal mailbox names. See inetCanonicalDomainName on how the default value of domain name used can be overridden in specific cases.


The MTA option used to override this attribute’s value is LDAP_DOMAIN_ATTR_UID_SEPARATOR.

Example

domainUIDSeparator: #

OID

2.16.840.1.113730.3.1.702


domOrgMaxUsers

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetDomainOrg

Definition

This attribute is used only for Sun ONE LDAP Schema v.1.

Maximum number of user entries in a domain organization.

Example

domOrgMaxUser: 500

OID

2.16.840.1.113730.3.1.697


domOrgNumUsers

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetDomainOrg

Definition

Number of current user entries in a domain organization.

Example

domOrgNumUsers: 345

OID

2.16.840.1.113730.3.1.698


memberOfManagedGroup

Origin

iPlanet Messaging Server 5.0

Syntax

dn, single-valued

Object Classes

ipUser

Definition

Family accounts are not supported in Sun ONE LDAP Schema v.2. Use this only if you are using Sun ONE LDAP Schema v.1.

Specifies the DN of the family account of which this user is a member.

Example

memberOfManagedGroup: cn=Addams Family, ou=groups,o=sesta.com,o=isp

OID

2.16.840.1.113730.3.1.704


mgmanAllowSubscribe

Origin

iPlanet Messaging Server 5.0

Syntax

cis, multi-valued

Object Classes

inetMailGroupManagement

Definition

Domain name(s) or email addresses of users allowed to subscribe to this mailing list.

Example

mgmanAllowSubscribe:sesta.com (Every user at sesta.com would be able to subscribe to the list.)

OID

2.16.840.1.113730.3.1.790


mgmanDenySubscribe

Origin

iPlanet Messaging Server 5.0

Syntax

cis, multi-valued

Object Classes

inetMailGroupManagement

Definition

Domain name(s) or email addresses of users not allowed to subscribe to this list. The mgmanDenySubscribe attribute takes precedence over mgmanAllowSubscribe.

Example

mgmanDenySubscribe:siroe.com

OID

2.16.840.1.113730.3.1.791


mgmanGoodbyeText

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single valued

Object Classes

inetMailGroupManagement

Definition

Reserved.

Example

TBD.

OID

2.16.840.1.113730.3.1.797


mgmanHidden

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetMailGroupManagement

Definition

Used with iPlanet Delegated Administrator for Messaging only.

A boolean flag specifying whether or not the group should appear in lists that are requested by people other than the group owners. A value of true corresponds with a hidden group, that is, the list is not visible. A value of false means that the list is visible. A missing value is the same as a value of false.

Example

mgmanHidden:true

OID

2.16.840.1.113730.3.1.792


mgmanIntroText

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetMailGroupManagement

Definition

Reserved.

Example

TBD.

OID

2.16.840.1.113730.3.1.796


mgmanJoinability

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetMailGroupManagement

Definition

Used for Sun ONE LDAP Schema v.1 only. Specifies who can subscribe to the group. The allowed values are ANYONE, ALL, and NONE (If this attribute is not specified, the default is NONE):

Example

mgmanJoinability:All

OID

2.16.840.1.113730.3.1.793  


mgmanMemberVisibility

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetMailGroupManagement

Definition

Only used in Sun ONE LDAP Schema v.1 with iPlanet Delegated Administrator for Messaging.

Defines who has rights to view the group membership list (expand the group). This attribute has the keyword values: none, all, true ,anyone. No matter what the setting of this attribute, group owners always retain the right to view (and modify) membership.

However, if this attribute is checked in the case of group expansion as part of an SMTP EXPN command (that is, not as part of an administrative tool that can easily identify whether or not the client is the group owner), then a value of none ends up operating as if the list is unconditionally disabled. This is because SMTP doesn’t provided a means of establishing a client’s identity, such as “owner”.

The following table lists the keywords and gives a description of each:

Table 5-1  Rights Keywords

Rights

Description

anyone

Enables anyone to expand the group (see the members in the mailing list). Also, the MTA returns the addresses of members when an EXPN is performed.

all or true

The user has to successfully authenticate to the directory (or iPlanet Delegated Administrator for Messaging) before expansion is allowed.

none

Expansion is not allowed.

Unrecognized values are interpreted as none.

If the attribute is not present, the MTA option EXPANDABLE_DEFAULT controls whether the expansion is allowed.


Note

LDAP_EXPANDABLE is the MTA option used to specify a different attribute name for this function.


Example

mgmanMemberVisibility:all

OID

2.16.840.1.113730.3.1.795


mgmanVisibility

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetMailGroupManagement

Definition
Example
OID

2.16.840.1.113730.3.1.794


mnggrpAdditionPolicy

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetOrgPerson

Definition

Reserved.

Example

TBD.

OID

2.16.840.1.113730.3.1.710


mnggrpBillableUser

Origin

iPlanet Messaging Server 5.0

Syntax

dn, single-valued

Object Classes

inetOrgPerson

Definition

DN of the user who is responsible for paying the bills for this family account or group of users.

Example

mnggrpBillableUser: uid=John,ou=people,o=sesta.com,o=isp

OID

2.16.840.1.113730.3.1.711


mnggrpCurrentUsers

Origin

iPlanet Messaging Server 5.0

Syntax

int, single-valued

Object Classes

inetOrgPerson

Definition

Current number of users allowed in the managed group. Intended for reporting purposes only. No operational impact.

Example

mnggrpCurrentUsers: 20

OID

2.16.840.1.113730.3.1.714


mnggrpDeletionPolicy

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single valued

Object Classes

inetOrgPerson

Definition

Reserved.

Example

TBD.

OID

2.16.840.1.113730.3.1.709


mnggrpMailQuota

Origin

iPlanet Messaging Server 5.0

Syntax

int, single-valued

Object Classes

inetOrgPerson

Definition

Cumulative disk quota allowed for all users in the managed group. A value of -1 specifies that there is no limit on space used by users in the managed group. Intended for reporting purposes only. No operational impact.

Example

mnggrpMailQuota:-1

OID

2.16.840.1.113730.3.1.715


mnggrpMaxUsers

Origin

iPlanet Messaging Server 5.0

Syntax

int, single-valued

Object Classes

inetOrgPerson

Definition

Maximum number of users allowed in the managed group.

Example

30

OID

2.16.840.1.113730.3.1.713


mnggrpStatus

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

inetOrgPerson

Definition

Reserved.

Example

TBD.

OID

2.16.840.1.113730.3.1.712


mnggrpUserClassOfServices

Origin

iPlanet Messaging Server 5.0

Syntax

cis, multi-valued

Object Classes

inetOrgPerson

Definition

Reserved.

Example

TBD.

OID

2.16.840.1.113730.3.1.716


nsDefaultMaxDeptSize

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Specifies the default size (in number of users) of a newly created department managed by Delegated Administrator.

Example

nsDefaultMaxDeptSize:20

OID

2.16.840.1.113730.3.1.562


nsMaxDepts

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

organization, nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Used with Delegated Administrator. Specifies the maximum number of group entries that can be created under this object.

Example

nsMaxDepts:200

OID

2.16.840.1.113730.3.1.557


nsMaxDomains

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

For use with Delegated Administrator. Specifies the maximum number of suborganizations allowed to be created under this object.

Example

nsMaxDomains:50

OID

2.16.840.1.113730.3.1.561


nsMaxMailLists

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single valued

Object Classes

nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

For use with Delegated Administrator. Specifies the maximum number of mailing lists that can be created under this entry.

Example

nsMaxMailLists:200

OID

2.16.840.1.113730.3.1.559


nsMaxUsers

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

organization

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

For use with Delegated Administrator. Specifies the maximum number of users that can be created under this entry.

Example

nsMaxUsers:750

OID

2.16.840.1.113730.3.1.555


nsNumDepts

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

organization, nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

For use with Delegated Administrator. Tracks the number of nested departments that exist under this object.

Example

nsNumDepts:35

OID

2.16.840.1.113730.3.1.556


nsNumDomains

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Used by Delegated Administrator. Tracks the number of suborganizations that exist under this object.

Example

nsNumDomains:5

OID

2.16.840.1.113730.3.1.560


nsNumMailLists

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Used by Delegated Administrator. Tracks the number of mail lists that exist under this object.

Example

nsNumMailLists:200

OID

2.16.840.1.113730.3.1.558


nsNumUsers

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

int, single-valued

Object Classes

organization, nsManagedDomain

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Tracks the number of users that can be created under this object.

Example

nsNumUsers:2000

OID

2.16.840.1.113730.3.1.554


nsSearchFilter

Origin

Not currently used; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

cis, single-valued

Object Classes

nsManagedPerson

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Reserved for future development for Delegated Administrator.

Example

OID

2.16.840.1.113730.3.1.564


nsdaCapability

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

cis, single-valued

Object Classes

nsManagedPerson

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Specifies whether a user can create a mail list. Supports Delegated Administrator.

Example

OID

2.16.840.1.113730.3.1.563


nsdaDomain

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

cis, single

Object Classes

nsManagedPerson

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Specifies the user’s organization, for Delegated Administrator.

Example

OID

2.16.840.113730.3.1.600


nsdaModifiableBy

Origin

iPlanet Messaging Server 5.0; deprecated in Sun ONE Messaging Server 6.0 with Sun ONE LDAP Schema v.2.

Syntax

dn, single-valued

Object Classes

inetOrgPerson

Definition

This attribute is deprecated for Sun ONE LDAP Schema v.2, it is supported only for Sun ONE LDAP Schema v.1.

Used by Delegated Administrator. Specifies who has modify access to the object in which this attribute appears. DN of the administrator’s group used with ACIs to grant rights to manage other groups.

Example

nsdaModifiableBy: cn=service administrators,ou=group,o=isp

OID

2.16.840.1.113730.3.1.565


preferredMailMessageStore

Origin

iPlanet Messaging Server 5.0

Syntax

cis, single-valued

Object Classes

mailDomain

Definition

Used by Sun ONE Messaging Server Delegated Administrator for Sun ONE LDAP Schema v.1 only.

Used to set the mailMessageStore attribute of newly created users. If missing, Delegate Administrator leaves the mailMessageStore attribute empty and the access server assumes that the user’s mailbox is in the default partition of the server instance.

Example

preferredMailMessageStore: primary

OID

2.16.840.1.113730.3.1.762



Previous      Contents      Index      Next     


Copyright 2003 Sun Microsystems, Inc. All rights reserved.