4.1 eDirectory Administration

eDirectory™ administration involves the management of objects in your directory tree. You can create, edit, and organize objects. You can also set up user accounts and assign rights, grant equivalence, and block inheritance. When you configure Role-Based Services, you can define administrator roles for specific administrative applications through the Role-Based Services object.

4.1.1 Copy Object

You can either create a new object with the same attribute values as an existing object, or copy attribute values from one object to another.

  1. In Roles and Tasks, select eDirectory Administration > Copy Object.

  2. In the Object to Copy From field, type the name and context of the object or use the search feature to find it.

  3. Select one of the following options:

    • Create New Object and Copy Attribute Values
    • Copy Attribute Values to an Existing Object
  4. Select the Copy ACL Rights check box if you want to copy access control list rights to this object. This step might take additional processing time, depending on your system and networking environment.

4.1.2 Create Object

  1. In Roles and Tasks, select eDirectory Administration > Create Object.

  2. Select the object class from the list that appears and click OK.

  3. Enter the requested information that appears according to the object class you selected, and click OK.

  4. A confirmation message appears: The Create Object request succeeded. Click OK, Repeat Task, or Modify.

4.1.3 Delete Object

  1. In Roles and Tasks, select eDirectory Administration > Delete Object.

  2. Type the name and context of the object, or use the search feature to find it, and click OK.

  3. A confirmation message appears: The Delete Object request succeeded.

4.1.4 Modify Object

  1. In Roles and Tasks, select eDirectory Administration > Modify Object.

  2. Type the name and context of the object, or use the search feature to find it, and click OK. The Modify Objects screen appears, displaying a set of tabs which are specific to the object you selected. Tabs and their features are described below this task.

  3. Complete the modification based on the tabs you select and click OK.

General

The General tab displays the Identification page.

  1. Complete the form with the following information:

    • Other Name
    • Owner
    • Location
    • Department
    • Organization
    • Description

      Modify your description using the add, delete, and edit features.

  2. Click OK.

The See Also page displays the search feature (Object Selector) to help you locate the object to modify.

The Other page displays the Valued Attributes and Unvalued Attributes list boxes. You can move, edit, or delete attributes for the object.

Security

The Security tab displays one or both of the following options, according to the object selected. The following attributes are used in rights calculation for eDirectory.

  • Security Equal To Me

    This attribute specifies other objects that are security equivalent to this object.

  • Security Equal To

    This attribute specifies objects that this object is security equivalent to.

Restrictions

Use the Limit Grace Login option to force users to change their passwords after a number of logins using an expired password.

Set the maximum number of concurrent connections a user is allowed.

Dynamic

Use the Member Query page to specify the search criteria when looking for members of a Dynamic Group object.

  1. Select the Dynamic Group check box to make a static group dynamic.

    After a static group becomes dynamic, it can be converted back to static status by clearing the Dynamic Group check box.

  2. Complete the Start Search at (Base dn) text box with the location that you are searching from.

  3. Specify the search scope. If you do not specify, the base scope is assumed.

    • Search Base DN, searches only the base object.
    • Search One Level, searches the direct subordinates of the base object, but the base object itself is not searched.
    • Search Sub Containers, searches the base object and all objects in the subtree below it.
  4. Choose whether the search for Dynamic Members should involve multiple servers or only the server containing the Dynamic Group object.

    • Yes, the server communicates with other servers while searching for Dynamic Members.
    • No, the search for Dynamic Members returns only local results.
  5. Use the two Search Filter icons to refine the search and manually edit the string if you know the syntax.

  6. Click Apply to update the Query Results.

Use the Settings page to establish an identity object and other object-related search parameters.

  1. Select the Identity Object. This is the object that the LDAP server uses to log in to the tree as, to query.

  2. Leave the Time Out blank unless you give iManager a reasonable amount of time to load the objects it finds.

    If you do not allow enough time for iManager to load and it times out, the object becomes unusable. You must delete the object and start over.

  3. Select Allow Duplicates to reduce the load on the server while listing dynamic group members.

    Unless you fully understand the implications of this feature, leave it unchecked.

  4. Leave Allow Unknowns unselected unless you fully understand the implications of this feature.

    Allow Unknowns determines the inclusion or exclusion of members in the dynamic group when the membership cannot be correctly determined.

RPM

This configuration task applies only to NDPS® printers. iPrint printers are not affected.

  1. Select Do Not Update Workstations if Remote Printer Management is disabled and printers are not installed or removed from workstations.

  2. Select Allow Only Specified Printers to Reside on Workstations to allow only the printers specified in Remote Printer Management.

    All other NDPS printers on the workstation are removed. This does not remove any iPrint printers.

  3. Select Show the Results Window on Workstations to display a window on the workstation that shows the printers that were installed and removed.

  4. Select the printers to install.

  5. Set a default printer.

  6. Indicate printers to be removed, if, any, and click OK, or Apply.

4.1.5 Move Object

  1. In Roles and Tasks, select eDirectory Administration > Move Object.

  2. Type the name and context of the object, or use the search feature (Object Selector) to find it, and click OK.

  3. In the Move To field, select the container you want to move the object to.

  4. Select Create an Alias in Place of Moved Object if you want to create an alias in an old location for each object being moved.

  5. Click OK. A confirmation message appears: The Move Object request succeeded.

4.1.6 Rename Object

  1. In Roles and Tasks, select eDirectory Administration > Rename Object.

  2. Type the name and context of the object, or use the search feature to find it.

  3. Type only the name of the new object; do not include a context.

  4. Select to save the old name if you want to save it.

    This saves the old name as an additional unofficial value of the Name property. Saving the old name lets users search for the object based on that name. After renaming the object, you can view the old name in the Other Name field on the General Identification tab for that object.

  5. Select Create an Alias in Place of Renamed Object if you want to create an alias for the object being named.

    This allows any operations that are dependent on the old object name to continue uninterrupted until you can update those operations to reflect the new name.

  6. Click OK. A confirmation message appears: The Rename Object request succeeded.