050-696 · Question #46
Your company has three regional offices. Each office has its own network administrator. Each administrator's user object has been assigned the Supervisor right to their respective Organizational…
The correct answer is D. No, the administrator will lose her rights because the new user object has a new value assigned. eDirectory tracks trustee rights by each object's unique internal identifier, not by name or context, so a recreated user object loses all previously assigned rights.
Question
Options
- ANo, eDirectory requires globally unique object names and LMorgan has already been used.
- BNo, the LMorgan user name will be retained in the server's eDirectory cache for 72 hours.
- CYes, LMorgan will have all the rights she had before because the same object name and context
- DNo, the administrator will lose her rights because the new user object has a new value assigned
How the community answered
(34 responses)- A12% (4)
- B9% (3)
- C3% (1)
- D76% (26)
Why each option
eDirectory tracks trustee rights by each object's unique internal identifier, not by name or context, so a recreated user object loses all previously assigned rights.
eDirectory requires unique names only within the same container, not across the entire tree, so recreating an object with the same name in the same container is fully permitted.
eDirectory does not retain deleted object names in a server cache for any period; this behavior does not exist in eDirectory and does not affect the ability to recreate the object.
Having the same name and context does not restore rights because eDirectory uses the object's unique internal identifier - not its distinguished name - to associate trustee assignments.
When an eDirectory object is created, it is assigned a globally unique internal identifier that eDirectory uses to track that object as a trustee in Access Control Lists. Deleting LMorgan's user object removes that identifier permanently, and recreating the object - even with the same name and context - generates an entirely new identifier. Because the Supervisor right was assigned to the old identifier, the new LMorgan object has no rights and must be explicitly reassigned.
Concept tested: eDirectory object identity and trustee rights loss on recreation
Source: https://www.netiq.com/documentation/edirectory-92/edir_admin/data/a5hiqb4.html
Topics
Community Discussion
No community discussion yet for this question.