
Chapter 4. Authorization: Access to what 67
4.2.1 LDAP groups
In the preceding chapter, we discussed the “branches” of LDAP trees. Each LDAP vendor,
and to a certain extent, each LDAP administrator, is given the flexibility to choose the nature
of these branches. These can be considered
organizational units or they can be groups with
common names. The specifics of how groups are defined in the LDAP is therefore beyond the
scope of this book, but regardless of how they are defined, the BPM product can access them
in the same way.
For more information, see
Understanding LDAP – Design and Implementation, SG24-4986.
Consider the LDAP instance in Figure ...