Index     Next     
iPlanet Delegated Administrator 4.5 Deployment and Customization Guide



Contents



Part 1 Introduction & Deployment Planning



Chapter 1 Introduction

Overview of Delegated Administrator
Delegating Administration
Architecture
Customization
What's New in This Release
What's New in This Manual


Chapter 2 Deployment Planning
Determining Your Delegated Administrator Needs
The Delegated Administrator DIT
Guidelines for Optimal Performance
Provisioning a User Directory for the First Time
Using an Existing User DIT
Upgrading an Existing Delegated Administrator Installation
Flexible DIT Options
Nested Containers
Customized Administrator Types
Options to Consider Before Installation
Directory Server Configuration and User Data
Optimizing Directory Searches
Messaging Server Support
Certificate-based Authentication
Class of Service
Other Configuration Options
Implications of Customizing Delegated Administrator

Part 2 Installation & Configuration



Chapter 3 Basic Installation and Configuration

System Requirements
Server Requirements
Supported Platforms
Software Compatibility
Web Browser Requirements
Before You Begin
Step 1: Install or Upgrade to iPlanet Directory Server 4.12
Step 2: Configure the Directory Server Plug-ins
Step 3: Configure the Directory Server
Optimizing Page Handling and Search Performance
Modifying an Existing User Directory
Step 4: Install or Upgrade to iPlanet Web Server 4.1
Step 5: Create a Web Server Instance
Step 6: (Optional) Install or Upgrade to Netscape Messaging Server 4.1
Step 7: Install Delegated Administrator
Step 8: Configure Netscape Messaging Server
Creating a Postmaster Group
Changing the Messaging Server Configuration
Step 9: (Optional) Disable Anonymous Access to Your User Tree
To Disable Anonymous Access
Changing the NDAUser Password
Silent Installation
Saving the Cache File
To Use the Cache File for Installation
Getting Started
To Use the Start Page
Using the Default Organization
Uninstalling Delegated Administrator


Chapter 4 Enabling Optional Features
The Sample LDIF Data File
Secure Sockets Layer (SSL)
To Use SSL-based LDAPS Connections
UserID Uniqueness
The UserID Uniqueness Plug-In
User Directory Failover
Setting up the Directory Servers
Enabling User Directory Failover in Delegated Administrator
Password Reset Policy
To Modify the Password Policy
To Modify the Delegated Administrator Configuration
Single Sign-On
Before You Begin
Configuring SiteMinder
Configuring the Directory Server
Configuring Delegated Administrator
Restarting the Web Server


Chapter 5 Certificate-Based Authentication
Before You Begin
Step 1: (Optional) Install and Configure Certificate Management System
Installing Certificate Management System
Configuring Certificate Management System
Step 2: Configure Web Server 4.1
Enabling SSL
Configuring Web Server to Work with Directory Server
Modifying the certmap.conf File
Restricting Access to Delegated Administrator Servlets
Defining a Servlet Alias
Restart the Web Server
Step 3: Issue Certificates for Delegated Administrator Users
Step 4: Configure the Directory Server
Creating a Proxy User Account
Step 5: Configure Delegated Administrator
Step 6: Restart the Web Server


Chapter 6 Class of Service
How CoS Works
Class of Service Definition
Templates
Interaction with Stored Attribute Values
Configuration and Management
Setting Up CoS in Delegated Administrator
Adding COS Schema
Modifying Existing User Entries
Adding CoS Templates

Part 3 User Data Management



Chapter 7 Top-level Administrators

Logging In
Using the Start Page
Using the Login Window
The Top-level Administration Page
Using the Location Bar
Using the Search Feature
Managing the Top Level
Adding Top-level Administrators
Removing Top-Level Administrators
Adding Top-Level Help Desk Administrators
Removing Top-Level Help Desk Administrators
Managing Organizations
Creating a New Organization
Creating a Suborganization
Adding Organization Administrators
Removing Organization Administrators
Adding Organization Help Desk Administrators
Removing Organization Help Desk Administrators
Deleting an Organization
Managing Groups
Creating a New Group
Creating a Subgroup
Adding a User to a Group
Adding Group Administrators
Removing Group Administrators
Removing a User from a Group
Deleting a Group
Managing User Accounts
Creating a New User Account
Deleting a User Account
Mail Lists
Mail List Owners
Moderated Mail Lists
Managing Mail Lists
Top-level and Organization Administrators' Mail Lists
Help Desk Administrator's Mail Lists
Group and User Account Administrators' Mail Lists
My Account
To Modify Information in Your Own User Account
Modifying Configuration Information


Chapter 8 Top-level Help Desk Administrators
Logging In
Using the Start Page
Using the Login Window
The Top-level Help Desk Administration Page
Using the Search Feature
Changing a User's Password
To Change a User's Password
My Account
To Modify Information in Your Own User Account
Mail Lists
Mail List Owners
Moderated Mail Lists


Chapter 9 Organization Administrators
Logging In
Using the Start Page
Using the Login Window
The Organization Administration Page
Using the Location Bar
Using the Search Feature
Exceeding the Search Results Size Limit
Managing Organizations
Creating a New Organization
Limiting the Number of Objects in an Organization
Creating a Suborganization
Adding Organization Administrators
Removing Organization Administrators
Adding Organization Help Desk Administrators
Removing Organization Help Desk Administrators
Deleting an Organization
Managing Groups
Creating a New Group
Limiting the Number of Objects in an Group
Creating a Subgroup
Adding a User to a Group
Adding Group Administrators
Removing Group Administrators
Removing a User from a Group
Deleting a Group
Managing User Accounts
Creating a New User Account
Deleting a User Account
My Account
To Modify Information in Your Own User Account
Modifying Configuration Information
Mail Lists
Mail List Owners
Moderated Mail Lists
Managing Mail Lists
Organization Administrators' Mail Lists
Help Desk Administrators' Mail Lists
Group and User Account Administrators


Chapter 10 Organization Help Desk Administrators
Logging In
Using the Start Page
Using the Login Window
The Organization Help Desk Administration Page
Using the Search Feature
Changing a User's Password
To Change a User's Password
My Account
To Modify Information in Your Own User Account
Mail Lists
Mail List Owners
Moderated Mail Lists


Chapter 11 Group Administrators
Logging In
Using the Start Page
Using the Login Window
My Groups and The Group Administration Page
Using the Location Bar
Using the Search Feature
Exceeding the Search Results Size Limit
Managing Groups
Creating a New Group
Limiting the Number of Objects in an Group
Creating a Subgroup
Adding a User to a Group
Adding Group Administrators
Removing Group Administrators
Removing a User from a Group
Deleting a Group
Managing User Accounts
Limited Access to Higher-level Administrators
Creating a New User Account
Deleting a User Account
My Account
To Modify Information in Your Own User Account
Mail Lists
Mail List Owners
Moderated Mail Lists
Managing Mail Lists


Chapter 12 End Users as Administrators
Logging In
To View Basic Information
To View Class of Services
Modifying User Account Information
To Change Your Password
To Modify Personal Information
Mail Delivery Options
Setting Vacation Auto-Responder Rules
Mail Lists
Mail List Owners
Moderated Mail Lists
Managing Mail Lists

Part 4 Customizing Delegated Administrator



Chapter 13 Customizing the User Interface

HTML Templates
How the Templates Work
Creating Templates for a New Organization
Configuration Data
Datatype Identifiers
Matchtype Identifiers
Macros
Supported Directives
NDAGetPage Servlet
Determining the Appropriate Template
Setting Macro Values
Searching a Datatype
Customizing the Display of Search Results
Sorting on Multiple Attributes
Customizing HTML Templates
To Change the Banner or Logo on the Login Page
Adding a Field to an HTML Template
Adding a JPEG Image to a Template
Changing an Error Message
Changing Search Criteria


Chapter 14 Customizing Configuration in the Directory
Default Configuration Information
cn=mainconf
cn=servletsconf
cn=opconf
cn=macrosconf
Customizing Configuration Information
Customizing the Default Configuration
Customizing Configuration for an Organization
The domain.map File
The Lookup Algorithm
Configuration Management Utilities
Using the Configuration Management Tab
Using Directory Server Console and Command-Line Utilities


Chapter 15 Extending Servlets
iPlanet Delegated Administrator 4.5 Servlets
Servlet Architecture
What You Can Customize
Accessing the Session Object
Methods and Keys
Accessing the TaskData Object
Constructor and Fields
Extending Authentication and Logout Servlets
What Extending NDAServlet Involves
Creating a Java Source File
Extending Task Servlets
What Extending a Task Servlet Involves
Creating a Java Source File
Compiling and Packaging Your Java Classes
Compiling Your Source Files
Modifying Properties Files
Packaging and Copying Your Classes
Restarting the Web Server

Part 5 Appendixes



Appendix A Using an Existing User Directory

Modifying Your User Directory
Step 1: Create a Top-level Administrator
Step 2: Modify user entries.
Step 3: Modify Organization Entries.
Step 4: Create Start and Login Pages for Each Organization.
Step 5: Modify the Root Entry.
Step 6: Create Group Containers.
Step 7: Add New Administrator Groups.
Step 8: Update the Containers for People.
Step 9: Create Non-Administrator Groups.
Step 10: Initialize the Object Counters.
Configuring Delegated Administrator for Other Tree Structures
The Delegated Administrator Directory Information Tree (DIT)
Defining Object Types


Appendix B Upgrading from Delegated Administrator Version 4.11
Changes from Version 4.11 to Version 4.5
Modifying the User Directory
Step 1: Modify Entries at the Top Level
Step 2: Modify Entries at the Organization Level
Add New Objectclasses and Attributes
Step 1: Modify the Top-level Entry
Step 2: Modify Each Organization Entry
Step 3: Modify the NDAUser Entry
Step 4: Modify Administrator Group Entries
Step 5: Modify OrgUnit Entries
Step 6: Modify Department or Group Entries
Step 7: Modify User Entries
Importing New Configuration Information
To Import Configuration Changes
Changing Container Names
Step 1: Change the Version 4.11 Container Names
Step 2: Change the Version 4.5 Container Names
Initializing the Object Counters
To Initialize the Object Counters


Appendix C Delegated Administrator Schema
LDAP Overview
How LDAP Works
Object Classes
Attributes
Object Identifiers (OIDs)
Delegated Administrator Object Classes
inetAdmin
nsManagedDept
nsManagedDeptAdminGroup
nsManagedDomain
nsManagedFamilyGroup
nsManagedISP
nsManagedMailList
nsManagedOrgUnit
nsManagedPerson
nsUniquenessDomain
Delegated Administrator Attributes
adminRole
memberof
nsdaCapability
nsDADomain
nsdaModifiableBy
nsDefaultMaxDeptSize
nsMaxDepts
nsMaxDomains
nsMaxMailLists
nsNumUsers
nsMaxUsers
nsNumDepts
nsNumDomains
nsNumMailLists
nsSearchFilter
owner


Appendix D Delegated Administrator Access Control Instructions (ACIs)
Overview of Delegated Administrator ACIs
How Group Administrator ACIs Work
ACIs for Adding a User to a Group
Limited Access to Higher-level Administrators
ACIs for Modifying Own Entries
Managing Subgroups
ACI Implementation and Scalability Issues
Top-level Administrators
Organization Administrators
Delegated Admininstrator ACIs Explained
Top-level ACIs
Organization-level ACIs
Tips on Customizing Delegated Administrator ACIs
Index


Index     Next     
Copyright © 2000 Sun Microsystems, Inc. Some preexisting portions Copyright © 2000 Netscape Communications Corp. All rights reserved.

Last Updated May 24, 2001