| United States-English |
|
|
|
![]() |
HP-UX AAA Server A.06.02 Administrator's Guide: HP-UX 11i v1 and 11i v2 > Part IV Integrating the HP-UX
AAA Server With External ServicesChapter 16 LDAP™ Authentication |
|
Table of Contents The Lightweight Directory Access Protocol (LDAP) authentication type provides a method for storing user profiles on an LDAP server. Because an LDAP server can handle a much larger number of user profiles with substantially higher performance than the users file, LDAP provides a more scalable repository for authentication. In addition, the LDAP server can be a policy repository. The LDAP implementation includes a check and deny list and supports more complex policy implementation. The check and deny lists are simply lists of attribute-value pairs that either must be present (check) or must not be present (deny). The complex policy allows policy conditions based on boolean expressions that are represented in a tree-structured list of Attribute-Value (A-V) pairs. The policy implementation requires writing an Lightweight Directory Interchange Format (LDIF) file. You can apply policy to many users by configuring users or realms to point to the same policy. The implementation supports caching of policy so that once the policy has been read from an LDAP directory for one user it is then in memory for any other user that is configured for that policy.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||