Chapter 4. Authorization: Access to what 75
Notice that in these panel shots, there are buttons in each named Create, Delete, Add Users,
Add Groups and Remove. The ability for these buttons to function will be tied to the read/write
privileges of the account you used as the “Bind distinguished name” when configuring the
LDAP repository in the Integrated Solutions Console. The LDAP account you specified
obviously needs read-access to the LDAP, but it is very uncommon for the LDAP administrator
team to give out LDAP accounts that have read/write privileges. In the more common case
where the account is read-only, these buttons will have no effect on your LDAP, and the
Create button results in a new account being defined within the defaultWIMFilebasedReal ...