Professional Documents
Culture Documents
Adminguide-8.8.15 44
Adminguide-8.8.15 44
All attributes of the account can be retrieved from the account object.
2. Set the domain attribute zimbraAuthKerberos5Realm to the Kerberos5 realm in which users in this
domain are created in the Kerberos database. When users log in with an email password and
the domain, zimbraAuthMech is set to kerberos5, the server constructs the Kerberos5 principal by
{localpart-of-the-email}@{value-of-zimbraAuthKerberos5Realm} and uses that to authenticate to
the kerberos5 server.
For each Zimbra Collaboration domain you can configure GAL to use:
• Both external LDAP server and Zimbra Collaboration LDAP in GAL searches
The Zimbra Collaboration Web Client can search the GAL. When the user searches for a name, that
name is turned into an LDAP search filter similar to the following example, where the string %s is
the name the user is searching for.
(|(cn = %s*)(sn=%s*)(gn=%s*)(mail=%s*))
(zimbraMailDeliveryAddress = %s*)
(zimbraMailAlias=%s*)
(zimbraMailAddress = %s*)
The Attributes Mapped to Zimbra Collaboration Contact table maps generic GAL search attributes
to their Zimbra Collaboration contact fields.
34