Secure Global Desktop 4.31 Administration Guide > Applications, documents and hosts > Mirroring your LDAP organization in ENS
If you have configured Secure Global Desktop to authenticate users with either the LDAP
login authority, the Active Directory login authority or web server/third party authentication (using the LDAP search methods), all users have the same webtop content (defined by the default LDAP profile object o=Tarantella System Objects/cn=LDAP Profile)
and have the same Secure Global Desktop-specific settings.
In order to customize webtop content and/or Secure Global Desktop-specific settings, you have to mirror some of your LDAP organization in ENS by creating the person objects that will be used as login profiles. These login profiles can then be used to control the following:
Note Directory Services Integration offers a more efficient and flexible way of customizing webtop content.
For details of how the login profiles are determined, see the LDAP login authority, the Active Directory login authority or web server/third party authentication.
When you create person objects as login profiles:
The objects you create, depend on the type of LDAP directory being used.
If you are using Sun ONE Directory Server, the LDAP names are:
ou=IT,o=indigo-insurance.com
for ITou=Sales,o=indigo-insurance.com
for Salesou=Finance,o=indigo-insurance.com
for Financeou=Marketing,o=indigo-insurance.com
for Marketinguid=Sid Cerise,ou=Finance,o=indigo-insurance.com
for Sid CeriseTo give users the webtops they need, you could create the following objects in the organizational hierarchy:
Note You must create the person object using a uid=
prefix.
Use BACKSPACE to delete the Secure Global Desktop default cn=
prefix for person objects
and then type uid=
. You can only do this when you
create the object. Once the object has been created, you cannot amend the cn=
part of the name.
With this organizational hierarchy:
cn=LDAP
Profile
objects. They also inherit webtop content
and other settings from parent OU objects in the organizational hierarchy. o=tarantella System Objects/cn=LDAP Profile
object. If you are using Microsoft Active Directory, the LDAP names are:
cn=IT,dc=indigo-insurance,dc=com
for ITcn=Sales,dc=indigo-insurance,dc=com
for Salescn=Finance,dc=indigo-insurance,dc=com
for Financecn=Marketing,dc=indigo-insurance,dc=com
for Marketingcn=Sid Cerise,cn=Finance,dc=indigo-insurance,dc=com
for Sid CeriseTo give users the webtops they need, you could create the following objects in the organizational hierarchy:
Note You must use domain component and Active Directory container objects to mirror your LDAP organization.
With this organizational hierarchy:
cn=LDAP
Profile
objects. o=tarantella System Objects/cn=LDAP Profile
object. Note It is not possible to inherit webtop content or other settings from domain component and Active Directory container objects.
Copyright © 1997-2007 Sun Microsystems, Inc. All rights reserved.