Configure dynamic and nested group support for the Sun ONE or iPlanet Directory Server

The Sun ONE or iPlanet Directory Server uses two grouping mechanisms:

Roles and groups are defined and administered similarly, with additional function so that member entries can have a generated attribute to indicate active roles. For example, an application can read the roles of an entry rather than select a group and browse the members list. This function simplifies and eases administration.

To configure dynamic or nested group support for Sun ONE or iPlanet Directory Server, perform the following steps in the WebSphere administrative console:

  1. Expand Security --> User Registries, and click LDAP.

  2. In the Type field, select Sun ONE for the LDAP server. Select the Ignore Case option. Click OK.

  3. Under Additional Properties, click Advanced LDAP Settings.

  4. On the Advanced LDAP Settings panel, change the value in the Group Filter field to the following value:

    &(cn=%v)(objectclass=ldapsubentry)) 
  5. On the Advanced LDAP Settings panel, change the value in the Group Member ID Map field to the following value:

    nsRole:nsRole
  6. Click OK.