
21.7
InForm OS Version 2.2.4 Command Line Interface Reference
user-dn-base
When using simple binding, the authentication process attempts to
bind the user to an entry in the server's directory information tree
(DIT). The distinguished name (DN) of the entry is a concatenation of
the value of
user-attr, “=”, the username, “,” and the value of the
user-dn-base.
user-attr
Indicates the attribute used to form a DN for simple binding. When
the attribute ends with a back slash, the DN is the concatenation of
the value of the
user-attr variable and the username. When the
attribute does not end with a back slash, it is as described for the
user-dn-base variable.
sasl-mechanism
When the binding is SASL, the SASL mechanism must be one
supported by the LDAP server. The InServ allows the mechanisms of
PLAIN, DIGEST-MD5, and GSSAPI.
kerberos-server
Indicates the numeric IP address of the Kerberos server if different
from the LDAP server.
kerberos-realm
The Kerberos realm.
allow-ssh-key
Set this value to 1 to allow LDAP users to set a public SSH key with the
setsshkey command (default 0). Clearing or setting the variable to 0
disables the setting of new keys for LDAP users but any existing keys
remain until they are removed with the
removesshkey variable. This
parameter only affects LDAP users, not local users.
groups-dn
Indicates the base of the subtree in the DIT in which to search for
objects that hold group information. It functions mutually exclusively
with the
accounts-dn variable.
group-obj
Indicates the objectClass attribute of a group object.
group-name-attr
The attribute in the group object that holds the group's name.
member-attr
The attribute that holds the names of users in the group.
Table 21-1. Values for Specifiers <param> and <value>
<param> <value>
Comentarios a estos manuales