匿名 LDAP 搜索访问权和从前发行版升级

如果升级服务器,LDAP 服务仍将使用前发行版的 LDAP 匿名访问配置。

关于此任务

如果在使用新的 PUBNAMES.NTF 设计升级目录后创建或编辑域“配置设置”文档,那么将不包含表中显示的允许匿名访问的属性列表。

这些属性未列在前发行版中,因为您不能防止对这些属性进行匿名 LDAP 访问。在前发行版中,匿名 LDAP 用户对这些属性始终具有搜索权限。从 V6 开始,您可以拒绝对表中属性的匿名 LDAP 搜索访问权,但缺省情况下允许对这些属性的匿名搜索访问权,以与前发行版的匿名搜索行为相一致。

表 1. 早于 V6 的发行版中未列出的匿名访问属性

属性

属性

属性

属性

altServer

ditContentRules

namingContexts

subschemasubentry

attributeTypes

extendedAttributeInfo

o

supportedControl

c

extendedClassInfo

objectClass

supportedExtension

cn

l

objectClasses

supportedLDAPVersion

createTimestamp

ldapSyntaxes

ou

supportedSASLMechanisms

creatorsName

modifiersName

st

vendorname

dc

modifyTimestamp

street

vendorversion