|Sun ONE Meta-Directory 5.1 Configuration and Administration Guide|
Chapter 20 Managing Servers and Permissions
In order to access Directory Server or an Oracle database through the Meta-Directory interface, it needs to be configured as part of Meta-Directory's navigation tree. As well, access permissions need to be set or modified. This chapter contains the following sections:
Configuring Data Servers
Meta-Directory has the ability to connect to a number of servers for a number of functions. These servers can be added as external data sources or to hold LDAP-configured connector views or meta views. Installing a Directory Server or an Oracle database as an addition to the Meta-Directory navigation tree is accomplished from the Data Servers panel. Typically, you would choose the server type and then configure it.
Accessing the Data Servers Window
- From the Meta-Directory console, choose the Configuration tab.
- Select Meta-Directory in the navigation tree.
- Click the Data Servers tab.
The Data Servers window appears.
To Add a New Data Server
- In the Data Servers window, click New.
The Data Server Type dialog box appears.
- Select the type of server (Directory Server or Oracle) you want to add and click OK.
The server appears in the list box and, by default, it is selected. Depending on the type of server being added, either four (Directory Server) or five (Oracle) additional tabs appear at the bottom of the panel. These tabs enable you to name and configure the new server.
- On the General tab, provide values or change the defaults as needed for the following fields:
Enter the fully-qualified name of the machine where the data source is stored, such as Server.company22.com. This is a required field.
Enter the port on which the join engine connects to the host machine (normally port 389). This is a required field.
Enter the DN of a user that has full administrator access to the Directory Server, such as cn=directory manager. This is a required field.
Enter the administrator password. This is a required field.
Enter a brief description to inform other users of the purpose of this data server. This is an optional field.
- Click Save.
The name of the new server appears under the Name column in the top window of the panel.
- Select the new server, and click Test to test the connection.
A Test Connect Succeeded message appears if the connection was successful. If the test was unsuccessful, make sure the connection information is correct.
- From the Tuning tab, provide values or change the defaults as needed for the following operational fields:
Maximum Operation Result Time
Enter the maximum amount of time allowed before timing-out an LDAP search with no LDAP results. The suggested minimum value is 3600.
Maximum Number of Retries
Enter the maximum number of times you want the server to attempt to connect after an initial failure. A value of 0 indicates an infinite number of times. This field is associated with the Retry Intervals field.
Enter a comma-separated list of numbers, each representing the number of seconds to wait before the next retry should begin. For example, if you provided a value of 10 for Maximum Number of Retries, and 30,300,600,3600 for Retry Intervals, the system would respond as follows:
"If the LDAP server or database becomes unavailable, retry at most 10 times, beginning 30 seconds after the loss of connection is noted, then 5 minutes later, then 10 minutes later, then hourly. If the 10th retry fails, report an error."
Enter the time, in seconds, that should pass before retries are abandoned if the server is idle.
- Click the Data Change Notification System (DCNS) Schedule tab. This option allows you to schedule when the join engine will look for changes in the change log. Provide values or change the defaults for the following fields:
Enter a value from 0 to 59.
Enter a value from 0 to 59.
Enter a value from 0 to 23.
Enter a value from 1 to 31.
Enter a value from 1 to 12.
Day of the Week Specifier
Enter a value from 0 to 6, where 0 is Sunday and 6 is Saturday.
Enter the maximum number of records to be read from the changelog for each cycle.
You can use either a single number as just described or an expression as follows:
Matches any value.
Matches any value in steps. For example, */2 matches 0,2,4,6... up to the maximum allowed value for values that start with zero, or it matches 1,3,5,7... up to the maximum value allowed.
Specifies a range where:
- Both x and y are greater than or equal to the minimum allowed value.
- y is less than or equal to the maximum allowed value.
- x is less than y.
The expression matches any value in the range.
Specifies a range as above, but with a step value that is not necessarily 1.
Specifies a single number within the allowed range.
Matches any value starting at x and then at x + step, x + 2*step, and so forth.
Specifies a comma-separated list of values.
Specifies a comma-separated list of ranges.
- On the Binary Attribute window, check the binary list and, if necessary, make changes to specify which binaries you want the join engine to recognize. These are the changes you can make:
To delete an attribute, select the attribute from the drop-down list and click Delete.
Click Save to save the configuration.
To Test a Data Server Connection
- In the Data Servers window, select the data server whose connection you want to test.
- Click Test.
If the connection was successful, a message confirming this appears. If the connection was unsuccessful, check your server's host information and re-test.
To Delete a Data Server
- In the Data Servers window, select the data server you want to delete.
- Click Delete.
The data server and its associated configuration disappear from the list box.
Setting Access Permissions
From Sun ONE Console, access permissions can be set for individual servers.
To Set Access Permissions
- From Sun ONE Console, select a Meta-Directory component or server, and right-click.
A context menu appears.
- Choose Set Access Permissions.
The Set Permission Dialog appears with a list of the names of users and groups who currently have access permissions for the selected object. By default, the Configuration Administrators group has unrestricted access to all servers (but not to user data), although its name does not appear on this list.
- Edit access permission as needed:
To deny access permission to a user or group in the list, select the user or group name, then click Delete User.
When you have finished adding and deleting users, click OK.