LDAP-UX Client Services B.04.15 with Microsoft Windows Active Directory Server Administrator's Guide (edition 8)

Table Of Contents
1. Use Authorization Manager to create dynamic groups. See the “Step 1: Creating a Dynamic
Group (LDAP Query Group)” section for details.
2. Use ADSI Edit to add the POSIX group ID to the dynamic group entry created in step 1. See
the “Step 2: Add POSIX Attributes to a Dynamic Group” section for details.
3. Configure the proxy user the read permissions to search dynamic groups in Windows ADS.
See the “Step 3: Setting Read Permissions for the Proxy user” section for details.
Step 1: Creating a Dynamic Group ( a LDAP Query Group)
You can use Authorization Manager to create dynamic groups (LDAP query groups) for your
applications. Membership in an LDAP query group is determined using an LDAP query on a
given user object. For detailed information on how to create LDAP query groups using
Authorization Manager, refer to Dynamic Groups in Windows Server 2003 Authorization Manager
available at the following web site:
http://msdn2.microsoft.com/en-us/library/ms952382.aspx
An Example
The following shows an example of a dynamic group entry (LDAP query group) created using
Authorization Manager:
dn: CN=group1,CN=AzGroupObjectContainer-dyngroup,CN=dyngroup,
DC=hp,DC=com
objectClass: top
objectClass: group
cn: group1
description: my dynamic group
distinguishedName: CN=group1,CN=AzGroupObjectContainer-dyngroup,
CN=dyngroup,DC=hp,DC=com
instanceType: 4
whenCreated: 20060313181428.0Z
whenChanged: 20060313182629.0Z
uSNCreated: 16588
uSNChanged: 16597
name: group1
objectGUID:: 2qO9YxkqAUuwCmkMJ371DA==
objectSid:: AQUAAAAAAAUVAAAAuEKpalCWUfgTN3lpVwQAAA==
sAMAccountName: $N21000-OA67EGECFDSP
sAMAccountType: 1073741825
groupType: 32
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=hp,DC=com
msDS-AzLDAPQuery: (cn=p*)
Step 2: Adding POSIX Attributes to a Dynamic Group
To create an HP-UX POSIX dynamic group, you must use ADSI Edit to add one of the following
attributes with POSIX group ID information to the dynamic group entry created in Step 1: Creating
a Dynamic Group.
msSFU30GidNumber attribute for Windows 2003 ADS
GidNumber attribute for Windows 2003 R2 ADS
An Example for Window 2003 ADS
For Windows 2003 ADS, the following shows an example of an HP-UX POSIX dynamic group
entry with msSFU30GidNumber information added to the above dynamic group entry:
dn: CN=group1,CN=AzGroupObjectContainer-dyngroup,CN=dyngroup,DC=hp,DC=com
objectClass: top
objectClass: group
cn: group1
82 Dynamic Group Support