nerdexam
Novell

050-696 · Question #46

Your company has three regional offices. Each office has its own network administrator. Each administrator's user object has been assigned the Supervisor right to their respective Organizational…

The correct answer is D. No, the administrator will lose her rights because the new user object has a new value assigned. eDirectory tracks trustee rights by each object's unique internal identifier, not by name or context, so a recreated user object loses all previously assigned rights.

Novell eDirectory Management

Question

Your company has three regional offices. Each office has its own network administrator. Each administrator's user object has been assigned the Supervisor right to their respective Organizational Unit objects; allowing them to perform all administrative tasks in the container. Today, you accidentally deleted the administrator's user object (named LMorgan) for the Salt Lake City office. To fix the problem, you've decided to simply re-create the object, using the same name, in the same context where it was before. Will LMorgan still have the Supervisor right to her Organizational Unit object?

Options

  • ANo, eDirectory requires globally unique object names and LMorgan has already been used.
  • BNo, the LMorgan user name will be retained in the server's eDirectory cache for 72 hours.
  • CYes, LMorgan will have all the rights she had before because the same object name and context
  • DNo, the administrator will lose her rights because the new user object has a new value assigned

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    9% (3)
  • C
    3% (1)
  • D
    76% (26)

Why each option

eDirectory tracks trustee rights by each object's unique internal identifier, not by name or context, so a recreated user object loses all previously assigned rights.

ANo, eDirectory requires globally unique object names and LMorgan has already been used.

eDirectory requires unique names only within the same container, not across the entire tree, so recreating an object with the same name in the same container is fully permitted.

BNo, the LMorgan user name will be retained in the server's eDirectory cache for 72 hours.

eDirectory does not retain deleted object names in a server cache for any period; this behavior does not exist in eDirectory and does not affect the ability to recreate the object.

CYes, LMorgan will have all the rights she had before because the same object name and context

Having the same name and context does not restore rights because eDirectory uses the object's unique internal identifier - not its distinguished name - to associate trustee assignments.

DNo, the administrator will lose her rights because the new user object has a new value assignedCorrect

When an eDirectory object is created, it is assigned a globally unique internal identifier that eDirectory uses to track that object as a trustee in Access Control Lists. Deleting LMorgan's user object removes that identifier permanently, and recreating the object - even with the same name and context - generates an entirely new identifier. Because the Supervisor right was assigned to the old identifier, the new LMorgan object has no rights and must be explicitly reassigned.

Concept tested: eDirectory object identity and trustee rights loss on recreation

Source: https://www.netiq.com/documentation/edirectory-92/edir_admin/data/a5hiqb4.html

Topics

#object deletion#eDirectory internal ID#trustee rights#re-created objects

Community Discussion

No community discussion yet for this question.

Full 050-696 Practice