Sun Java ¼Ð»x     ¤W¤@­¶      ¥Ø¿ý      ¯Á¤Þ      ¤U¤@­¶     

Sun ¼Ð»x
Sun Java System Communications Services 6 2005Q1 Delegated Administrator «ü«n 

ªþ¿ý A
ªA°È´£¨ÑªÌºÞ²z­û¤ÎªA°È´£¨ÑªÌªÀ¹Î²Õ´

Delegated Administrator ¥D±±¥x´£¨Ñ¤F¯à¦b¥Ø¿ý¤¤«Ø¥ß¤§·sªººÞ²z­û¨¤¦â¡AªA°È´£¨ÑªÌºÞ²z­û (SPA)¡A¥H¤Î·sªºªÀ¹Î²Õ´Ãþ«¬¡C

¥»ªþ¿ý´y­z¤U¦C¥DÃD¡G

¥»ªþ¿ý´y­zªA°È´£¨ÑªÌºÞ²z­û¨¤¦â¤Î·sªºªÀ¹Î²Õ´Ãþ«¬¡A¨Ã¥B»¡©ú¦p¦ó¦b Delegated Administrator ¤¤«Ø¥ß¥¦­Ì¡C


ªA°È´£¨ÑªÌºÞ²z­û

Delegated Administrator ¥D±±¥xÅý±z©e°UºÞ²z§@·~µ¹·sªºªA°È´£¨ÑªÌºÞ²z­û (SPA) ¨¤¦â¡A³o­Ó¨¤¦â¯à°÷«Ø¥ß¤ÎºÞ²z¤U¼hªÀ¹Î²Õ´ªº·sÃþ«¬¡C

SPA ªºÅv­­½d³ò¤¶©ó³»¼hºÞ²z­û (TLA) ©MªÀ¹Î²Õ´ºÞ²z­û (OA) ¤§¶¡¡C

±z¥i¥H¨Ï¥Î SPA «Ø¥ß¤T¼h¦¸ªººÞ²z¶¥¼h¡A¦p²Ä 1 ³¹¡uDelegated Administrator ²¤¶¡v¤¤ªº¡u¤T¼h¦¸¶¥¼h¡v©Ò­z¡C

¦b©e°Uµ¹²Ä¤G¼h¯Å«á¡A¥i´î»´¥Ñ¤j«¬ LDAP ¥Ø¿ý©Ò¤ä´©ªº¤j«¬«È¤á°ò©³ªººÞ²z§@·~¡C¨Ò¦p¡AISP ¥i¯à·|´£¨ÑªA°Èµ¹¤W¦Ê©Î¤W¤d­Ó¤p«¬¥ø·~¡A¦Ó¨C¤@­Ó³£»Ý­n¥¦­Ì¦Û¤vªºªÀ¹Î²Õ´¡C¨C¤@¤Ñ¥i¯à³£·|¦³³\¦hªº·sªÀ¹Î²Õ´·s¼W¦Ü¥Ø¿ý¤¤¡C

¦pªG±z¨Ï¥ÎÂù¼h¦¸¶¥¼h¡ATLA ¥²¶·«Ø¥ß©Ò¦³³o¨Ç·sªºªÀ¹Î²Õ´¡C²{¦b TLA ¥i¥H©e°U³o¨Ç§@·~µ¹ SPA¡C

SPA ¥i¥H¬°·s«È¤á«Ø¥ß¤U¼hªÀ¹Î²Õ´¡A¨Ã«ü©w OA ¨ÓºÞ²z¨º¨ÇªÀ¹Î²Õ´¤¤ªº¨Ï¥ÎªÌ¡C

¹Ï A-1 Åã¥Ü¤@­Ó¤T¼h¦¸²Õ´¶¥¼hªºÅÞ¿èÀ˵ø½d¨Ò¡C

¹Ï A-1

¨Ï¥ÎªA°È´£¨ÑªÌºÞ²z­û¤§¥Ø¿ý (ÅÞ¿èÀ˵ø)

¨Ï¥ÎªA°È´£¨ÑªÌºÞ²z­û¤§¥Ø¿ý¡GÅÞ¿èÀ˵ø

¹Ï A-1 ¤¤ªº½d¨ÒÅã¥Ü¤@­Ó´£¨ÑªÌªÀ¹Î²Õ´¡C¦ý¬O¡A¤@­Ó¥Ø¿ý¥i¥H¥]§t¦h­Ó´£¨ÑªÌªÀ¹Î²Õ´¡C

¦b³o­Ó½d¨Ò¤¤¡AºÞ²z§@·~¤§©e°U¦p¤U¡G

¦p»Ý´£¨ÑªÌ¤Î¤U¼hªÀ¹Î²Õ´ªº©w¸q¡A½Ð°Ñ¾\¡uªA°È´£¨ÑªÌºÞ²z­û©ÒºÞ²zªºªÀ¹Î²Õ´¡v¡C

ªA°È´£¨ÑªÌºÞ²z­û¨¤¦â

SPA ¥i¥H°õ¦æ¤U¦C§@·~¡G

SPA ¥i¥H¨Ï¥Î Delegated Administrator ¥D±±¥x¨Ó°õ¦æ³o¨Ç§@·~¡C¦b¦¹µo¦æª©¥»¤¤¡ADelegated Administrator ¤½¥Îµ{¦¡¤£¥]§t°õ¦æ³o¨Ç§@·~ªº«ü¥O¿ï¶µ¡C


³Æµù

TLA ¥i¥H­×§ï©Î§R°£¥ô¦ó²{¦³ªº¦@¥ÎªÀ¹Î²Õ´©Î§¹¾ãªÀ¹Î²Õ´¡CTLA ¤]¥i¥HºÞ²z¨º¨ÇªÀ¹Î²Õ´¤¤ªº¨Ï¥ÎªÌ¡C

TLA ¥i¥H³z¹L¥D±±¥x±q¤@­Ó¨Ï¥ÎªÌ¤W²¾°£ SPA ¨¤¦â¦ý¤£¯à«ü©w SPA ¨¤¦â¡C¦p»Ý¦¹ Delegated Administrator µo¦æª©¥»¤¤ªº­­¨î²M³æ¡A½Ð°Ñ¾\¡u¦¹µo¦æª©¥»ªºª`·N¨Æ¶µ¡v¡C

¦p»Ý TLA ©Ò°õ¦æªººÞ²z§@·~¤§§¹¾ã´y­z¡A½Ð°Ñ¾\²Ä 1 ³¹¡uDelegated Administrator ²¤¶¡v¤¤ªº¡uºÞ²z­û¨¤¦â©M¥Ø¿ý¶¥¼h¡v¡C


«ü©w SPA ¨¤¦âµ¹¤@­Ó¨Ï¥ÎªÌ

SPA ¨¤¦â¥²¶·«ü©wµ¹¬£©wµ¹ SPA ªºªÀ¹Î²Õ´¥H¤Î SPA ©ÒºÞ²zªº´£¨ÑªÌªÀ¹Î²Õ´¤§¤U¼hªÀ¹Î²Õ´¤¤ªº¨Ï¥ÎªÌ¡C

¦b¹Ï A-1 ¤¤Åã¥Üªº½d¨Ò¤¤¡A°²³]±z¥²¶·¬°´£¨ÑªÌªÀ¹Î²Õ´«Ø¥ß¤@­Ó¦W¬° VIS ªº SPA¡C±z¥i¥H«ü©w SPA ¨¤¦âµ¹ªÀ¹Î²Õ´ DEF ¤¤ªº¨Ï¥ÎªÌ1¡C

SPA ¥²¶·±`¾n¦b¤U¼hªÀ¹Î²Õ´¤¤¡A¦]¬°´£¨ÑªÌªÀ¹Î²Õ´¸`ÂI¤£¥]§t¥ô¦ó¨Ï¥ÎªÌ¡C

¦]¦¹¡A¦b SPA ¯à°÷ºÞ²z´£¨ÑªÌªÀ¹Î²Õ´¤§«e¡A¦b¥¦¤U­±¦Ü¤Ö¥²¶·«Ø¥ß¤@­ÓªÀ¹Î²Õ´¡C¦¹ªÀ¹Î²Õ´À³¸Ó¬£©w¬°«O¯d³Q«ü©w¬° SPA ¨¤¦âªº¨Ï¥ÎªÌ¡C¦p»Ý¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\¦¹ªþ¿ý«á­±ªº¡u«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¤ÎªA°È´£¨ÑªÌºÞ²z­û¡v¡C

¦¹µo¦æª©¥»ªºª`·N¨Æ¶µ

¦b¦¹ Delegated Administrator µo¦æª©¥»¤¤¡A±z¤£¯à¨Ï¥Î Delegated Administrator ¥D±±¥x©Î¤½¥Îµ{¦¡¨Ó«Ø¥ß SPA ©Î´£¨ÑªÌªÀ¹Î²Õ´¡C

­Y­n«Ø¥ß SPA ©Î´£¨ÑªÌªÀ¹Î²Õ´¡A±z¥²¶·¤â°Ê­×§ï¦Û­qªºªA°È´£¨ÑªÌ½d¥»¡Ada.provider.skeleton.ldif¡C

¦p»Ý¨Ï¥Î¦Û­qªA°È´£¨ÑªÌ½d¥»¨Ó°õ¦æ³o¨Ç§@·~ªº»¡©ú¡A½Ð°Ñ¾\¦¹ªþ¿ý«á­±ªº¡u«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¤ÎªA°È´£¨ÑªÌºÞ²z­û¡v¡C


ªA°È´£¨ÑªÌºÞ²z­û©ÒºÞ²zªºªÀ¹Î²Õ´

SPA ¥i¥H«Ø¥ß¡B­×§ï¤Î§R°£ SPA ´£¨ÑªÌªÀ¹Î²Õ´¤U¼hªº¤U¦CªÀ¹Î²Õ´Ãþ«¬¡G

´£¨ÑªÌªÀ¹Î²Õ´¡B§¹¾ãªÀ¹Î²Õ´¤Î¦@¥ÎªÀ¹Î²Õ´©ó¤U¦C¦U¸`¤¤´y­z¡C

´£¨ÑªÌªÀ¹Î²Õ´

´£¨ÑªÌªÀ¹Î²Õ´¬O LDAP ¥Ø¿ý¤¤¦bÅÞ¿è¤W¥]§t§¹¾ãªÀ¹Î²Õ´¤Î¦@¥ÎªÀ¹Î²Õ´ªº¸`ÂI¡C´£¨ÑªÌªÀ¹Î²Õ´¸`ÂI¦³¤¹³\ SPA ºÞ²z¤U¼hªÀ¹Î²Õ´ªºÄÝ©Ê¡C

¦b LDAP ¥Ø¿ý¤¤¡A´£¨ÑªÌªÀ¹Î²Õ´¥²¶·¦ì©ó¶l¥óºô°ì¤§¤U¡C¦p»Ý½d¨Ò¡A½Ð°Ñ¾\¦¹ªþ¿ý«á­±ªº¡u½d¨ÒªA°È´£¨ÑªÌªÀ¹Î²Õ´¸ê®Æ¡v¡C

´£¨ÑªÌªÀ¹Î²Õ´¤£¯à¥]§t¨Ï¥ÎªÌ¶µ¥Ø¡C¦Ó¬O¥Ñ¦b´£¨ÑªÌªÀ¹Î²Õ´¤U«Ø¥ßªºªÀ¹Î²Õ´¤¤©Ò´£¨Ñ¡C

´£¨ÑªÌªÀ¹Î²Õ´Àx¦sÃö©ó¦b¨ä¤U«Ø¥ßªºªÀ¹Î²Õ´¤§¥Ø¿ý¸ê°T¡C¨Ò¦p¡G

§¹¾ãªÀ¹Î²Õ´

§¹¾ãªÀ¹Î²Õ´¦³¤U¦C¯S©Ê¡G

¦@¥ÎªÀ¹Î²Õ´

¦@¥ÎªÀ¹Î²Õ´¦³¤U¦C¯S©Ê¡G


«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¤ÎªA°È´£¨ÑªÌºÞ²z­û

¦b¦¹ Delegated Administrator ªºµo¦æª©¥»¤¤¡A±z¥²¶·¨Ï¥Î Delegated Administrator ©Ò´£¨Ñªº¦Û­qªA°È´£¨ÑªÌ½d¥» (da.provider.skeleton.ldif) ¨Ó«Ø¥ß±z¦Û¤vªº´£¨ÑªÌªÀ¹Î²Õ´¤Î SPA¡C


³Æµù

±z¤]¥i¥H¦b°õ¦æ Delegated Administrator °t¸mµ{¦¡®É¡A¦b¥Ø¿ý¤¤¦w¸Ë´£¨ÑªÌªÀ¹Î²Õ´ªº½d¨Ò (¦³¤U¼hªÀ¹Î²Õ´ªº) ¤Î SPA ½d¨Ò¡C±z¥i¥H¦b°t¸mµ{¦¡¤¤¿ï¾Ü [¸ü¤J½d¨ÒªÀ¹Î²Õ´] ¨Ó°õ¦æ¦¹¾Þ§@¡C

¦ý¬O¡A½d¨ÒªÀ¹Î²Õ´½d¥» (da.sample.data.ldif) ¬O¥Î¨Ó§@¬°½d¨Òªº¡A¦Ó¤£¬O«Ø¥ß±z¦Û¤vªº´£¨ÑªÌªÀ¹Î²Õ´¤§½d¥»¡C¦p»ÝÃö©ó¦¹½d¨Òªº¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\¦¹ªþ¿ý«á­±ªº¡u½d¨ÒªA°È´£¨ÑªÌªÀ¹Î²Õ´¸ê®Æ¡v¡C


¤@¦ý±z«Ø¥ß¤F´£¨ÑªÌªÀ¹Î²Õ´¤Î SPA¡ASPA ¥i¥Hµn¤J Delegated Administrator ¥D±±¥x¡B«Ø¥ß¤ÎºÞ²z¤U¼hªÀ¹Î²Õ´¡B¨Ã¥B«ü©w SPA ¨¤¦âµ¹ SPA ªÀ¹Î²Õ´¤¤ªº¨ä¥L¨Ï¥ÎªÌ¡C¦ý¬O¡A³o¨Ç SPA ¥u¯à°÷ºÞ²z¬Û¦Pªº´£¨ÑªÌªÀ¹Î²Õ´¡C

­Y­n«Ø¥ß¥t¤@­Ó´£¨ÑªÌªÀ¹Î²Õ´¤Î SPA ¨ÓºÞ²z¥¦¡A±zÀ³¸Ó¦A¨Ï¥Î¤@¦¸¦Û­qªA°È´£¨ÑªÌ½d¥»¡C

¥»¸`´y­z¤U¦C¥DÃD¡G

½d¥»©Ò«Ø¥ßªº¶µ¥Ø

·í±z¦b¥Ø¿ý¤¤¦w¸Ë½s¿è¹Lª©¥»ªº¦Û­qªA°È´£¨ÑªÌ½d¥»®É¡A·|«Ø¥ß¤U¦C¶µ¥Ø¡G

¹Ï A-2 Åã¥Ü¦w¸Ë½d¥»©Ò«Ø¥ßªº¶µ¥Ø¤§½d¨Ò¡C¥¦¬O³o­ÓªÀ¹Î²Õ´ªº¥Ø¿ý¸ê°T¾ð (DIT) À˵ø¡C

¹Ï A-2 ¥u¬O¤@­Ó½d¨Ò¡C±zªºªÀ¹Î²Õ´¦WºÙ¡BSPA ¨Ï¥ÎªÌ¦WºÙ¤Î DIT µ²ºcÀ³¸Ó¬°±z¦Û¤vªº¦w¸Ë©Ò¯S¦³ªº¡C

¹Ï A-2

¦Û­qªA°È´£¨ÑªÌ½d¥» (¥Ø¿ý¸ê°T¾ðÀ˵ø)

¦Û­qªA°È´£¨ÑªÌ½d¥»¡G¥Ø¿ý¸ê°T¾ðÀ˵ø

½d¨Ò¤¤¦w¸Ë¤F¦Û­qªA°È´£¨ÑªÌ½d¥»ªº¸`ÂI

¹Ï A-2 ¤¤Åã¥Üªº½d¨Ò¤¤¤§¸`ÂI¦p¤U¡G

«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¡B¤U¼hªÀ¹Î²Õ´¤Î SPA ©Ò»Ýªº¸ê°T

­Y­n«Ø¥ß¤@­Ó´£¨ÑªÌªÀ¹Î²Õ´¡B¤@­Ó¤U¼hªÀ¹Î²Õ´¤Î¤@­Ó SPA¡A¥²¶·¥H±z¦w¸Ë¯S¦³ªº¸ê°T¨ú¥N¦b¦Û­qªA°È´£¨ÑªÌ½d¥»¤¤ªº°Ñ¼Æ¡C

¦b±z¾\ŪÃö©ó³o¨Ç°Ñ¼Æªº¦P®É¡A±z¥i¥H°Ñ¾\¡u¦Û­qªA°È´£¨ÑªÌ½d¥»¡v©ÒÅã¥Üªº da.provider.skeleton.ldif ²M³æ¡C©Î¶}±Ò¹ê»Úªº ldif ÀɮסA¦ì©ó¤U¦C¥Ø¿ý¤¤¡G

da_base/lib/config-templates

¦p»Ý»P³o¨Ç°Ñ¼Æ¬ÛÃöÁp¤§Äݩʪº©w¸q¡A½Ð°Ñ¾\¡uSun Java System Communications Services Schema Reference¡v¤¤ªº²Ä 5 ³¹¡uClasses and Attributes Used by Communications Services Delegated Administrator (Schema 2)¡v¤Î²Ä 3 ³¹¡uAttributes¡v¡C

©w¸q´£¨ÑªÌ¤Î¤U¼hªÀ¹Î²Õ´¤§°Ñ¼Æ

­Y­n«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¤Î¤U¼hªÀ¹Î²Õ´¡A½Ð½s¿è¤U¦C°Ñ¼Æ¡G

©w¸q SPA ªº°Ñ¼Æ

­Y­n«Ø¥ß SPA¡A½s¿è¤U¦C°Ñ¼Æ¡G

¦p»Ý¦p¦ó½s¿è¦Û­qªA°È´£¨ÑªÌ½d¥»©M¦b±zªº¥Ø¿ý¤¤¦w¸Ë¸ê°Tªº»¡©ú¡A½Ð°Ñ¾\¡u«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¤ÎªA°È´£¨ÑªÌºÞ²z­ûªº¨BÆJ¡v¡C

«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¤ÎªA°È´£¨ÑªÌºÞ²z­ûªº¨BÆJ

­Y­n«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´©MªA°È´£¨ÑªÌºÞ²z­û¡A½Ð¿í´`³o¨Ç¨BÆJ¡G

  1. ¦b¥Ø¿ý¤¤«Ø¥ß¶l¥óºô°ì¡C
  2. ¦pªG±z©|¥¼¦p¦¹°µ¡A«h½Ð¦b±zªº¥Ø¿ý¤¤«Ø¥ß¶l¥óºô°ì¡C´£¨ÑªÌªÀ¹Î²Õ´¤Î¥¦ªº¤U¼h¦@¥ÎªÀ¹Î²Õ´±N·|¨Ï¥Î¦¹¶l¥óºô°ì¡C

  3. ½Æ»s¨Ã­«·s©R¦W da.provider.skeleton.ldif ÀɮסC
  4. ·í±z¦w¸Ë Delegated Administrator ®É¡Ada.provider.skeleton.ldif Àɮצw¸Ë¦b¤U¦C¥Ø¿ý¤¤¡G

    da_base/lib/config-templates

  5. ¦b±zªº da.provider.skeleton.ldif Àɮ׽ƥ»¤¤½s¿è¤U¦C°Ñ¼Æ¡C¥Î¥¿½Tªº°Ñ¼Æ­È¨Ó¶i¦æ±zªº¦w¸Ë¡C
  6. ¦p»Ý³o¨Ç°Ñ¼Æªº©w¸q¡A½Ð°Ñ¾\¡u«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¡B¤U¼hªÀ¹Î²Õ´¤Î SPA ©Ò»Ýªº¸ê°T¡v¡C

    ¬Y¨Ç°Ñ¼Æ¦b ldif Àɮפ¤¨Ï¥Î¶W¹L¤@¦¸¡C±z¥²¶··j´M¨Ã¨ú¥N¨C¤@­Ó°Ñ¼Æªº¥þ³¡¹ê¨Ò¡C

    ¤@¨Ç°Ñ¼Æ¥Nªí¦h­«­ÈÄݩʤ§­È¡C±z¥i¥H½Æ»s©M½s¿è³o¨Ç°Ñ¼Æ¡A¥H¤Î»P¥¦­Ì¬ÛÃöÁpªºÄݩʦWºÙªº°Ñ¼Æ¡A¥H¤¹³\³o¨ÇÄݩʪº¦h­Ó¹ê¨Ò¦b±zªº ldif Àɮפ¤¡C¦h­«­Èªº°Ñ¼Æ¦b¤U­±³Æµù¡C

    • <ugldapbasedn>
    • <maildomain_dn>
    • <maildomain_dn_str>
    • <providerorg>
    • <servicepackage> (¦h­«­È)
    • <domain_name> (¦h­«­È)
    • <provider_sub_org>
    • <preferredmailhost>
    • <available_domain_name> (¦h­«­È)
    • <available_services> (¦h­«­È)
    • <spa_uid>
    • <spa_password>
    • <spa_firstname>
    • <spa_lastname>
    • <spa_servicepackage>
    • <spa_mailaddress>
    • ¦p»Ý»P³o¨Ç°Ñ¼Æ¬ÛÃöÁp¤§Äݩʪº©w¸q¡A½Ð°Ñ¾\¡uSun Java System Communications Services Schema Reference¡v¤¤ªº²Ä 5 ³¹¡uClasses and Attributes Used by Communications Services Delegated Administrator (Schema 2)¡v¤Î²Ä 3 ³¹¡uAttributes¡v¡C

  7. ¨Ï¥Î LDAP ldapmodify ¥Ø¿ý¤u¨ã¨Ó¦w¸Ë´£¨ÑªÌªÀ¹Î²Õ´¤Î SPA ¨ì¥Ø¿ý¤¤¡C
  8. ¨Ò¦p¡A±z¥i¥H°õ¦æ¤U¦C«ü¥O¡G

    ldapmodify -D <directory manager> -w <password>
    -f <da.provider.finished.ldif>

    ¨ä¤¤

    <directory manager> ¬O Directory Server ºÞ²z­ûªº¦WºÙ¡C

    <password> ¬O Directory Server ºÞ²z­ûªº±K½X¡C

    <da.provider.finished.ldif> ¬O§@¬°·sªº´£¨ÑªÌªÀ¹Î²Õ´¤Î SPA ¨ì¦w¸Ë¥Ø¿ý¤¤¤§½s¿è¹Lªº ldif ÀɮצWºÙ¡C

¦Û­qªA°È´£¨ÑªÌ½d¥»

¦¹½d¥» (da.provider.skeleton.ldif) ¥]§t±z«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¤Î SPA ©Ò¥²¶·­×§ïªº°Ñ¼Æ¡C

¤U­±¦CªíÅã¥Ü ldif Àɮצ³°Ñ¼Æªº°Ï¬q¡C¦¹¦Cªí¤£¥]§t¾ã­ÓÀɮסC¤ä´© Access Manager ¥²»Ýªº¶µ¥Ø©M ACI ¤£¥]§t¦b³o¸Ì¡C

±zÀ³¸Ó¥u­×§ï ldif Àɮפ¤ªº°Ñ¼Æ¡C½Ð¤Å­×§ïÀɮפ¤»P Access Manager ¬ÛÃöªº°Ï¬q¡C

da.provider.skeleton.ldif ÀÉ®× (¬ÛÃöªº°Ï¬q)

#
# The following parameterized values must be replaced.
#
# <ugldapbasedn> :: Root suffix for user/group data
# <maildomain_dn>         :: Complete dn of the mail domain underneath which the
#                            provider organization will be created.
# <maildomain_dn_str>     :: The maildomain dn with all ',' replaced by '_'. E.g.
#                            dn --> o=siroe.com,o=SharedDomainsRoot,o=Business,
#                            dc=red,dc=iplanet,dc=com
#                            dn_str --> o=siroe.com_o=SharedDomainsRoot_o=Business_
#                            dc=red_dc=iplanet_dc=com
# <providerorg>            : Organization value for provider node.
# <servicepackage>        :: One for each service package to include.
#                            All service packages in the system may be assigned
#                            by leaving this value empty.
# <domain_name>           :: One for each DNS name which may be assigned to a
#                            subordinate organization.
#                            These names form a proper subset (some or all) of the
#                            names listed in the <maildomain> organization's
#                            sunpreferreddomain and associateddomain attributes.
# <provider_sub_org>      :: Organization value for the shared subordinate
#                            organization in which the Provider Administrator resides.
# <preferredmailhost> :: Name of the preferred mail host for the provider's
#                            subordinate organization.
# <available_domain_name> :: one for each DNS name that an organization allows an
#                            organization admin to use when creating a user's mail
#                            address. This is a proper subset of the values given
#                            for <domain_name> (sunAssignableDomains attribute).
# <available_services>    :: One for each service packags available to an
#                            organization (sunAvailableServices attribute). These
#                            service packages form a proper subset of the ones
#                            assigned to a provider organization - <servicepackage> #                            (sunIncludeServices attribute). Form is
#                            <service package name>:<count>
#                            where count is an integer. If count is absent then
#                            default is unlimited.
# <spa_uid>               :: The uid for the service provider administrator.
# <spa_password>          :: The password for the service provider administrator.
# <spa_firstname>         :: First name of the service provider administrator.
# <spa_lastname>          :: Last name of the service provider administrator.
# <spa_servicepackage>    :: Service package assigned to the service provider
#                            administrator.
# <spa_mailaddress>       :: The spa's mail address. The domain part of the mail
#                            address must be one of the values used for
#                            <available_domain_name>.
#


#
# Provider Organization
#
dn: o=<providerorg>,<maildomain_dn>
changetype: add
o: <providerorg>
objectClass: top
objectClass: sunismanagedorganization
objectClass: sunmanagedorganization
objectClass: organization
objectClass: sunManagedProvider
sunAllowBusinessOrgType: full
sunAllowBusinessOrgType: shared
sunBusinessOrgBase: o=<providerorg>domainsroot,<ugldapbasedn>
sunIncludeServices: <servicepackage>
sunAssignableDomains: <domain_name>
sunAllowMultipleDomains: true
sunAllowOutsideAdmins: false
sunProviderOrgDN: o=<provider_sub_org>,o=<providerorg>,<maildomain_dn>
# .
# .
# [Entries and ACIs required by Access Manager]
# .
# .

#
# Full Organizations node
#
dn: o=<providerorg>DomainsRoot,<ugldapbasedn>
changetype: add
o: <providerorg>DomainsRoot
objectClass: top
objectClass: organization
objectClass: sunmanagedorganization
# .
# .
# [Entries and ACIs required by Access Manager]
# .
# .

#
# Provider Admin Role shared organizations
#
dn: cn=Provider Admin Role,o=<providerorg>,<maildomain_dn>
changetype: add
cn: Provider Admin Role
objectClass: ldapsubentry
objectClass: nssimpleroledefinition
objectClass: nsroledefinition
objectClass: nsmanagedroledefinition
objectClass: iplanet-am-managed-role
objectClass: top
iplanet-am-role-description: Provider Admin

#
# Provider Admin Role full organizations
#
dn: cn=Provider Admin Role,o=<providerorg>DomainsRoot,<ugldapbasedn>
changetype: add
cn: Provider Admin Role
objectClass: ldapsubentry
objectClass: nssimpleroledefinition
objectClass: nsroledefinition
objectClass: nsmanagedroledefinition
objectClass: iplanet-am-managed-role
objectClass: top
iplanet-am-role-description: Provider Admin

#
# Shared Subordinate Organization. Includes 1 users who is the Provider Administrator.
#
dn: o=<provider_sub_org>,o=<providerorg>,<maildomain_dn>
changetype: add
preferredMailHost: <preferredmailhost>
sunNameSpaceUniqueAttrs: uid
o: <provider_sub_org>
objectClass: inetdomainauthinfo
objectClass: top
objectClass: sunismanagedorganization
objectClass: sunnamespace
objectClass: sunmanagedorganization
objectClass: organization
objectClass: sunDelegatedOrganization
objectClass: sunMailOrganization
sunAvailableDomainNames: <available_domain_name>
sunAvailableServices: <available_services>
sunOrgType: shared
sunMaxUsers: -1
sunNumUsers: 1
sunMaxGroups: -1
sunNumGroups: 0
sunEnableGAB: true
sunAllowMultipleServices: true
inetDomainStatus: active
sunRegisteredServiceName: GroupMailService
sunRegisteredServiceName: DomainMailService
sunRegisteredServiceName: UserMailService
sunRegisteredServiceName: iPlanetAMAuthService
sunRegisteredServiceName: UserCalendarService
sunRegisteredServiceName: iPlanetAMAuthLDAPService
sunRegisteredServiceName: DomainCalendarService
# .
# .
# [Entries and ACIs required by Access Manager]
# .
# .

dn: ou=People,o=<provider_sub_org>,o=<providerorg>,<maildomain_dn>
changetype: add
ou: People
objectClass: iplanet-am-managed-people-container
objectClass: organizationalUnit
objectClass: top

dn: ou=Groups,o=<provider_sub_org>,o=<providerorg>,<maildomain_dn>
changetype: add
ou: Groups
objectClass: iplanet-am-managed-group-container
objectClass: organizationalUnit
objectClass: top
# .
# .
# [Entries and ACIs required by Access Manager]
# .
# .

#
# User - provider administrator
#
dn: uid=<spa_uid>,ou=People,o=<provider_sub_org>,o=<providerorg>,<maildomain_dn>
changetype: add
sn: <spa_lastname>
givenname: <spa_firstname>
cn: <spa_firstname> <spa_lastname>
uid: <spa_uid>
iplanet-am-modifiable-by: cn=Top-level Admin Role,<ugldapbasedn>
objectClass: inetAdmin
objectClass: top
objectClass: iplanet-am-managed-person
objectClass: iplanet-am-user-service
objectClass: iPlanetPreferences
objectClass: person
objectClass: organizationalPerson
objectClass: inetuser
objectClass: inetOrgPerson
objectClass: ipUser
objectClass: inetMailUser
objectClass: inetLocalMailRecipient
objectClass: inetSubscriber
objectClass: userPresenceProfile
objectClass: icsCalendarUser
mailhost: <preferredmailhost>
mail: <spa_mailaddress>
maildeliveryoption: mailbox
mailuserstatus: active
inetCos: <spa_servicepackage>
inetUserStatus: Active
nsroledn: cn=Provider Admin Role,o=<providerorg>,<maildomain_dn>
userPassword: <spa_password>


½d¨ÒªA°È´£¨ÑªÌªÀ¹Î²Õ´¸ê®Æ

·í±z°õ¦æ Delegated Administrator °t¸mµ{¦¡ config-commda ®É¡A±z¥i¥H¿ï¾Ü¦w¸Ë½d¨ÒªÀ¹Î²Õ´¸ê®Æ (©ó¤@­Ó ldif Àɮפ¤©w¸q) ¦Ü±zªº¥Ø¿ý¤¤¡C(·í±z°õ¦æ°t¸mµ{¦¡®É¡A¦b [ªA°È®M¸Ë³nÅé¤ÎªÀ¹Î²Õ´½d¨Ò] ­±ªO¤¤¿ï¨ú [¸ü¤J½d¨ÒªÀ¹Î²Õ´]¡C)°t¸mµ{¦¡±N da.sample.data.ldif ÀÉ®×·s¼W¦Ü LDAP ¥Ø¿ý¾ð¤¤¡C

¦¹ ldif Àɮ׬O¥Î¨Ó°µ¬°½d¨Ò¡A¤£¬O°µ¬°«Ø¥ß±z¦Û¤vªº´£¨ÑªÌªÀ¹Î²Õ´¤§½d¥»¡C­Y­n«Ø¥ß·sªº´£¨ÑªÌªÀ¹Î²Õ´¡A½Ð°Ñ¾\¡u«Ø¥ß´£¨ÑªÌªÀ¹Î²Õ´¡B¤U¼hªÀ¹Î²Õ´¤Î SPA ©Ò»Ýªº¸ê°T¡v¡C

½d¨Ò¸ê®Æ©Ò´£¨ÑªºªÀ¹Î²Õ´

¹Ï A-1 Åã¥Ü½d¨Ò ldif ÀɮשҴ£¨Ñªº²Õ´µ²ºc¤§ÅÞ¿èÀ˵ø¡C(¹Ï A-1 ·s¼W¤@­Ó¤£¦s¦b¦¹Àɮפ¤ªº¦@¥ÎªÀ¹Î²Õ´ HIJ¡C)

½d¨Ò ldif ÀÉ®×¥]§t¤U¦C¦b®Ú§À½X¸`ÂI¤§¤UªºªÀ¹Î²Õ´¡G

ldif Àɮ׬°³o¨ÇªÀ¹Î²Õ´©w¸q¤U¦CºÞ²z­û¨¤¦â¡G

Å޿趥¼hµ²ºc©M¥Ø¿ý¸ê°T¾ð

¦b¤T¼h¦¸¥Ø¿ý¶¥¼hµ²ºc¤¤¡A¥Ø¿ý¸ê°T¾ð (DIT) ¬Ý°_¨Ó©M¹Ï A-1 ¤¤©ÒÅã¥ÜªºÅÞ¿èÀ˵ø¨Ã¤£§¹¥þ¤@¼Ë¡CªÀ¹Î²Õ´¦b DIT ¤¤¹ê¦æ©ó¤@­Óµy·L¤£¦Pªº¶¥¼hµ²ºc¤¤¡C

¨Ò¦p¡ADIT ¤º§¹¾ãªººô°ì¥²»Ýª½±µ¦ì©ó®Ú§À½X¤§¤U¡C¦]¦¹¡Aºô°ì¸`ÂI·s¼W¦Ü®Ú§À½X¤U­±¨Ó¬°¦@¥Îºô°ì (¬°¦@¥ÎªÀ¹Î²Õ´©Ò¨Ï¥Î) ¤Î§¹¾ãªÀ¹Î²Õ´ (¦³¥¦­Ì¦Û¤vªººô°ì) Àx¦s LDAP ¸ê°T¡C

½d¨ÒªÀ¹Î²Õ´¸ê®Æ¡G¥Ø¿ý¸ê°T¾ðÀ˵ø

¹Ï A-3 Åã¥Ü½d¨ÒªÀ¹Î²Õ´¸ê®Æªº¥Ø¿ý¸ê°T¾ð (DIT) À˵ø¡C

¹Ï A-3 ¤¤Åã¥Üªº½d¨Ò¤¤¡A¦p¦P¹Ï A-1 ¤¤Åã¥ÜªºÅÞ¿èÀ˵ø¡A¥]§t¤U¦CªÀ¹Î²Õ´¡G

½d¨Ò¥Ø¿ý¸ê°T¾ðÀ˵ø¤¤ªº¸`ÂI

½d¨ÒªÀ¹Î²Õ´ÀÉ®× (da.sample.data.ldif) ¤¤ªº¸`ÂI¦p¤U¡G

½d¨Ò¥Ø¿ý¸ê°T¾ðÀ˵ø¤¤ªº¨Ï¥ÎªÌ DN

¹Ï A-3 ½d¨ÒªÀ¹Î²Õ´Àɮפ¤Åã¥Üªº¤@¨Ç¨Ï¥ÎªÌ DN ¦p¤U¡G




¤W¤@­¶      ¥Ø¿ý      ¯Á¤Þ      ¤U¤@­¶     


¤å¥ó¸¹½X¡G819-1104¡C  Copyright 2005 Sun Microsystems, Inc. ª©Åv©Ò¦³¡C