We use LDAP to authenticate users to various servers: subversion, dokuwiki, webdav. Since ZCS includes an LDAP server, it seems logical to try and use that ZCS LDAp server to authenticate users of these other servers against it.
Some of the users of the other servers are 'internal' users, and will have a ZCS account. Authenticating a non-ZCS server against these is presumably feasible. My concern is with other users, who don't need such an account in a ZCS-managed domain. They certainly won't need an email address in one of our domains. In our current (non-ZCS) setup, we enter them as LDAP inetOrgPerson entries, put them in a groupOfUniqueNames, and give that group the appropriate access rights.
I am trying to replicate this approach, by entering these users as contacts in an address book, then creating an LDAP group. However, I don't see where and how I can create a group in the ZCS LDAP server, not can I see the filter to reach the cotnacts in the ZCS address books. Even dumping the LDAP data into an ldif file doesn't show the address book entries ! Where are these entries ?
Any help would be appreciated.