Datasheet

“main” (Installation and Administration) 2004/6/25 13:29 page 502 #528
i
i
i
i
i
i
i
i
The second view (‘Default Values for New Objects’) lists all attributes of the
corresponding LDAP object (in this case, group or user configuration) for
which a standard value is defined. Additional attributes and their standard
values can be added, existing attribute and value pairs can be edited, and
entire attributes can be deleted. Copy a template by changing the cn entry.
Connect the template to its module, as already described, by setting the
susedefaulttemplate attribute value of the module to the DN of the
adapted template.
Note
The default values for an attribute can be created from other at-
tributes by using a variable style instead of an absolute value.
For example, when creating a new user, cn=%sn %givenName
is created automatically from the attribute values for sn and
givenName.
Note
Once all modules and templates are configured correctly and ready to run,
new groups and users can be registered in the usual way with YaST.
Users and Groups Configuration with YaST
The actual registration of user and group data differs only slightly from the
procedure when not using LDAP. The following brief instructions relate
to the administration of users. The procedure for administering groups is
analogous.
Access the YaST user administration with ‘Security & Users’ ‘User Ad-
ministration’. An input form is displayed for the registration of the most
important user data, like name, login, and password. ‘Details’ accesses a
form for the configuration of group membership, login shell, and the home
directory. The default values were defined with the procedure described
in Section 21.8.6 on page 497. When LDAP is used, this form leads to an-
other form for the registration of LDAP-specific attributes. It is shown in
Figure 21.31 on the next page. Select all attributes for which to change the
value then click ‘Edit’. Closing the form that opens with ‘Continue’ returns
to the initial input form for user administration.
The initial input form of user administration, offers ‘LDAP Options’. This
gives the possibility to apply LDAP search filters to the set of available
users or to go to the module for the configuration of LDAP users and
groups by selecting ‘LDAP User and Group Configuration’.
502 21.8. LDAP — A Directory Service