Claims
- 1. A computer system comprising:
a lightweight directory access protocol directory; and a management server separate from said directory but providing services integrated therewith, said management server having a private data store outside of the directory that stores authorization/personalization data, said management server querying said directory and applying additional authorization/personalization rules to enhance directory services and override inherited attributes without requiring modification of said directory.
- 2. A method of authorizing a computer system user comprising:
receiving a request related to said user; referencing said user in an LDAP directory and, if a corresponding user entry is found, obtaining information pertaining to said user; associating authorization and/or personalization data pertaining to said user with a protected resource; and saving said authorization and/or personalization in a private data store separate from said LDAP directory.
- 3. A storage medium storing executable instructions providing an authorization service for authorizing users to access protected resources, said storage medium storing the following instructions:
first instructions that query and receive user information from a directory database; second instructions that create authorization associations with respect to user information received from said directory database; third instructions that store, retrieve said associations to/from a private data store separate from said directory database to override inherited attributes.
- 4. A computer operating method comprising:
querying an LDAP directory during computer user logon; traversing an organizational hierarchy of directory information while overriding inherited attributes with explicitly mapped ones; accessing a private data store separate from said directory, said private data store not replicating substantial user/group directory data to eliminate need for detailed synchronization between the directory and the private data store; and restricting access to protected resources based on private data store authorization/personalization data contents.
- 5. A method of logging a user onto a computer system comprising:
receiving a user identification during a log on process; in response to said received user identification, querying a directory for a list of associated groups and/or organizational units associated with the user; traversing an organizational hierarchy of directory groups/OU's; and overriding inherited attributes with explicitly associated attributes obtained from a private data store outside of the directory.
- 6. The method of claim 5 wherein said directory is an LDAP directory.
- 7. The method of claim 5 wherein said querying is performed by a management server.
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority from provisional application No. 60/483,008 filed Jun. 27, 2003 entitled “Utilizing LDAP Directories For Application Access Control And Personalization” (Atty. Dkt. 2452-32), the entire contents of which are incorporated herein by reference.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60483008 |
Jun 2003 |
US |