Using secondary address books for ACL control

I understand that in R6 one can use secondary address books declared in directory assistance to control ACL access. Specifically, we have a group database we would like for ACL control.

IS this possible? If so can you have multiple address books for this purpose? Does it have to be specified for ACL access.?

thanks

Subject: Using secondary address books for ACL control

Servers can only use one directory for group access control, in addition to the primary Domino Directory. If you need multiple directories you may want to research using an Extended Directory Catalog, which is new in ND6.

As far as using a group in an ACL, you can use either ACL or Multi-purpose groups. I’m not sure what the difference is, I have users accidentally send e-mail to ACL groups all the time so it doesn’t seem to really have any effect.

HTH,

Charles

Subject: RE: Using secondary address books for ACL control

Ok ,suppose I want to use 1 directory in addition to the names.nsf for acl control…which is ok,as you said. Where and how do I specify that second address book? IS it in directory assistance?And if I have other address books in dir asst for other purposes (mailing etc) how do I tell Domino which one is for access control?

Subject: RE: Using secondary address books for ACL control

You do configure it in Directory Assistance, but I have no clue how to tell Domino which one is to be used for ACL purposes. This might warrant a call to Lotus support, unless someone out there has some insight to how this (mostly) undocumented feature works.

Sorry I couldn’t help any more.

– Charles

Subject: Using secondary address books for ACL control

You can have several address books - say NAMES.NSF for internal people and NAMESExt.NSF for externals - but with Directory Assistance all groups must be in NAMES.NSF. That is you have groups of names from NAMESExt.NSF in NAMES.NSF and no groups in NAMESExt.NSF. Use the PubNames template for NAMESExt.NSF. Or you can use an external LDAP directory as an additional directory. By default you’d use LDAP ‘distinguishedName’ in groups and ACLs. Create an LDAP account in your client NAB to lookup LDAP names when editing ACLs. With LDAP you don’t need to put peoples’ names in a Domino address book, everyone in the LDAP directory is (or can be) able to login, assuming of course that their distinguishedName is in an web site ACL somewhere.

Subject: Not so in Domino 6, see Directory Assist. documents

There is a field for group authorization to turn on group authorizations for that directory.

Howard