WebSphere Application Server Network Deployment, Version 6.0.x     Operating Systems: AIX, HP-UX, Linux, Solaris, Windows

Configuring dynamic and nested group support for the IBM Tivoli Directory Server

Before you begin

When creating groups, ensure that nested and dynamic group memberships work correctly.

Steps for this task

  1. In the administrative console for WebSphere Application Server, click Security > Global security.
  2. Under User registries, click LDAP.
  3. On the Lightweight Directory Access Protocol (LDAP) user registry configuration panel, select IBM Tivoli Directory Server for the LDAP server.
  4. Under Additional properties, click Advanced Lightweight Directory Access Protocol (LDAP) user registry settings.
  5. Change the Group filter value to (&(cn=%v)(|(objectclass=groupOfNames)(objectclass=groupOfUniqueNames)(objectclass=groupOfURLs))).
  6. Change the Group member ID map value to ibm-allGroups:member;ibm-allGroups:uniqueMember.
  7. Verify that Auxiliary object class field on the Add an LDAP entry panel for your IBM Tivoli Directory server has the appropriate value. When you create a nested group, the Auxiliary object class value is ibm-nestedGroup. When you create a dynamic group, the Auxiliary object class value is ibm-dynamicGroup.



Related concepts
Dynamic groups and nested group support
Dynamic and nested group support for the SunONE or iPlanet Directory Server
Locating a user's group memberships in Lightweight Directory Access Protocol
Dynamic groups and nested group support for the IBM Tivoli Directory Server
Lightweight Directory Access Protocol user registries

Related tasks
Configuring dynamic and nested group support for the SunONE or iPlanet Directory Server
Using specific directory servers as the LDAP server
Configuring Lightweight Directory Access Protocol user registries

Task topic    

Terms of Use | Feedback

Last updated: Dec 11, 2005 4:07:15 PM CST
http://publib.boulder.ibm.com/infocenter/wasinfo/v6r0/index.jsp?topic=/com.ibm.websphere.nd.doc/info/ae/ae/tsec_dynamicnestedgroupibm.html

© Copyright IBM Corporation 2004, 2005. All Rights Reserved.
This information center is powered by Eclipse technology. (http://www.eclipse.org)