![]() |
Online Help |
Sun Java System Directory Proxy Server 5 2004Q2 | |
Network Group Encryption View
Directory Proxy Server network groups describe how to identify an LDAP client, and the restrictions to enforce for clients that match that group. Clients are initially identified into a group based on the network address from which they connect. They may change their group after a successful bind.
Network groups are tested in the descending order of priority, specified by their placement in the Network Group window. In this window, groups on the bottom of the list have less priority than those towards the top. If no groups are found to match a client, the client's request will be rejected. There must be at least one group entry in the configuration specification.
Clients are identified to belong to this network group based on their IP address and/or domain name.
Group name. Enter the group name that specifies the name of the group. This value must be unique within the set of groups. This value must be present as it forms the RDN of entries of this class.
Enable. By default, this option is selected for you. Deselect it to disable a group in a configuration. For a group to be part of Directory Proxy Server configuration, this option must be selected.
Client SSL Policy. Configure the client SSL policy.
Do not use SSL. Select this option if you do not wish to use SSL encryption.
Clients are able to request an SSL session. Select this option if the clients in the group will establish an SSL session requesting SSL.
Clients MUST establish an SSL session. Select this option if the clients in the group must establish an SSL session before performing any operation. Referral SSL policy. Configure the SSL policy while following referrals.
Do not use SSL. Select this option if you do not wish to use SSL encryption.
Establish an SSL session if client has done so. If this option is enabled, DAR will only initiate SSL for clients in that group if the client already has an SSL session established with DAR.
Establish an SSL session for all referrals. Enable this option, if, upon a referral, DAR will initiate an SSL session before the operation is forwarded.
Copyright 2004 Sun Microsystems, Inc. All rights reserved.