Directory Assistance / LDAP Problem

Having a problem with an address book showing up in the “Choose AddressBook” dropdown list on Notes clients.

Directory assistance appears to be properly setup as I have a local (on

server) address book which is shared and appears to be working properly.

This local (server) address book does show up on the drop down list.

I have a LDAP server defined (properly I think) within the directory

assistance documents for the server. It has both LDAP and Notes Clients

check marked. When you do a “show x” on the console, it shows the address

book, secondary LDAP, Notes & LDAP, and points to the outside ldap server.

When you type a name in the “To” on a new memo and hit F9 to search, it IS

using the LDAP to pull up names in the drop down list from that LDAP

server.

The only problem seems to be the address book not showing up in the

original drop down list.

Servers are iSeries, 6.5.2 CF1 AND 6.5.4 FP1 — clients are either 6.5.2

CF1 or 6.5.4…

Subject: Directory Assistance / LDAP Problem

This excerpt from the admin help database explains how LDAP is expected to work. btw… I agree it would be nice to be able to browse an LDAP directory…

“To enable Notes users to address mail easily to users registered in a remote LDAP directory, you can set up directory assistance for the directory on the users’ mail servers or directory servers. Then, a Notes user can press F9 to resolve an address for a name from the LDAP directory entered in an addressing field of a Notes message. If the user doesn’t resolve the address, either the Notes client uses directory assistance to resolve the address when the user sends the mail or, if the client doesn’t resolve the address, the Router uses directory assistance to resolve the address. A Notes client doesn’t use type-ahead addressing to find names in a remote LDAP directory, and Notes users can’t use the “Select Addresses” dialog box to browse and select names from a remote LDAP directory.”

Subject: Right on Mike…

… and Dale,

If you want the LDAP address book to appear for all your end users’ Notes clients, you CAN do it… but the solution to the problem is client-side, not server-side.

Reference “LDAP Account Record” in the documentation. Once you’ve created one of those that you’d like every client to have, you can push your copy down to all the end users via a Domino policy.

+Josh+

Subject: RE: Directory Assistance / LDAP Problem

This excerpt from the admin help database explains how LDAP is expected to work. btw… I agree it would be nice to be able to browse an LDAP directory…

“To enable Notes users to address mail easily to users registered in a remote LDAP directory, you can set up directory assistance for the directory on the users’ mail servers or directory servers. Then, a Notes user can press F9 to resolve an address for a name from the LDAP directory entered in an addressing field of a Notes message. If the user doesn’t resolve the address, either the Notes client uses directory assistance to resolve the address when the user sends the mail or, if the client doesn’t resolve the address, the Router uses directory assistance to resolve the address. A Notes client doesn’t use type-ahead addressing to find names in a remote LDAP directory, and Notes users can’t use the “Select Addresses” dialog box to browse and select names from a remote LDAP directory.”

Thanks for citing the excerpt. This slide from the ID107: Getting Started With Active Directory Integration presentation that Josh and I are giving at Lotusphere next week summarizes what you can and cannot do with DA-LDAP (the last column is labelled “Name in LDAP secondary (e.g., AD)”).

Having browse capability going through your Domino server to the LDAP server would be rather expensive.

As an alternative, you can configure the Notes clients go directly to the LDAP servers (don’t overlook its desktop policies section) …

“Setting up clients to use the LDAP server”

http://www-12.lotus.com/ldd/doc/domino_notes/Rnext/help6_admin.nsf/0/50f62b71185c6cf885256c1d00393a2a?OpenDocument

This tip may be found in the “Domino Directory FAQ” (google it)

Subject: RE: Directory Assistance / LDAP Problem

We authenticate all of our web applications against LDAP and as it is very frustrating for us when entering LDAP accounts into Domino groups, too great a possibility for fat fingering account info, we are currently working on a server-side solution that would allow you to include LDAP accounts via the address dialog box. It is designed primarily for admins to perform group maintenance on the hub (or any) server but it sounds like there are environments out there where it might be deployed throughout a domain. Our management will probably make this a salable shrinkwrap once we have it fully tested and packaged but we would probably be interested in some beta users when we reach the final stages of testing if anyone would be interested in that.