×

ATTRIBUTE RULE ENFORCER FOR A DIRECTORY

  • US 20110071992A1
  • Filed: 11/30/2010
  • Published: 03/24/2011
  • Est. Priority Date: 08/01/2001
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus comprising:

  • a rule validator of an attribute rule enforcer for a directory, the rule validator being interposed between a client and a directory access server for providing access to the directory, the rule validator being capable of determining whether an attribute of a client request complies with a first rule governing content of data that is permissible to be forwarded to the directory access server and a second rule governing structure of data that is permissible to be forwarded to the directory access server, the first and second rules including a data addition rule when the request includes a request to add data to the directory, the first and second rules including a data modification rule when the request includes a request to modify data in a directory, and the first and second data rules including a data deletion rule when the request includes a request to delete data from the directory;

    the rule validator further being capable of forwarding the request to the directory access server if the attribute complies with one of the first rule and the second rule and being further capable of rejecting the request to the directory access server and returning an error message to a source of the request if the attribute does not comply with the first rule and the second rule; and

    a configuration file for use by said rule validator, the configuration file containing a plurality of parameters including one of an add rules parameter, a modify rules parameter, a modrdn parameter where modrdn relates to modifying a relative distinguished name, a delete rules parameter, a log directory parameter, a service port parameter, a debug level parameter and a directory access protocol error parameter.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×