Search DominoPower's 11,437 Lotus-related article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
Integrating a Notes Connector database with Google Enterprise Search (continued)

FIGURE G


Here you can see the authentication process. Roll over picture for a larger image.

Other forms of authentication
Use of Domino authentication is not a requirement. The system can use any other authentication scheme also available to the GSA such as LDAP or client certificates to obtain a user's identity. Regardless of how the user's identity is obtained, the GSA can still use the Access Control database for authorization. The system provides the ability to map a user's Notes name to a foreign name through the use of fields in the Person document, or through a formula, which can be evaluated at run time.

Authorization of search results
When a secure document is found in the search results, the GSA will pass the username to the Authorization service URL, which is a Notes agent in the Access Control database.

For Notes URLs, the system will determine whether the user is allowed to see the original document. When considering a user's access, the system takes into account not only the database ACL but also any document level security fields, and database roles. The system also respects nested groups within the Domino directory. The system responds to the incoming request with either a "Permit" or a "Deny" message to the GSA so that it knows whether to show the document in the search results.

For non-Notes URLs, the system can return an "Indeterminate" response. This allows the GSA to fallback onto a secondary authorization scheme such as user impersonation against file share documents.

The Access Control database allows you to log all incoming authentication and authorization requests. This feature was added during development as a way of tracking the conversation during the Domino server and the GSA, but it has also proven to be very useful during product evaluation and demonstration to show that security of Notes documents is really being respected so I decided to leave this in the final product.

FIGURE H


Here's a record of the incoming authentication and authorisation requests from the Google Search Appliance. Roll over picture for a larger image.

It's probably worth pointing out that every index entry has a flag that tells the GSA whether the entry should be subject to authorization checks. The connector determines whether a document can be seen by all authenticated Domino users at crawl time by combining the database ACL with any document level security restrictions and flags each document as required for the GSA. In turn, the GSA will only seek authorization against documents that have been marked as secure by the connector.

Wrap-up
Well, that just about concludes this discussion about the Domino Connector and the Google Search Appliance. I hope you have enjoyed the read. It was great fun to be part of this project and I have learned a great deal about the GSA in the process.

For me, the exciting part is seeing what might happen next. Google is making enhancements and adding new features all the time. I am currently looking at using parametric search techniques to allow results to be easily filtered and categorised, and it's worth keeping an eye on the Google labs as they bring out new features such as integrated public search, and "fast as you type" search results.

Bain McKay is Executive Vice President and Chief Scientist of CIRI Lab Inc. where he and his research team build advanced Knowledge Management technology using the latest methods in Cognitive Science and computing technology. Bain can be reached at bmckay@cirilab.com or at http://www.cirilab.com.


« Previous  ·  1  ·  2  ·  3
Other articles you might like
Home > Strategies > Interoperability (15 articles)
   A Sametime plugin for Trillian
   Integrating Twitter with an IBM internal social network
   Fun with Sametime and Skype
Home > Lotus Technologies > Notes (84 articles)
   A walk down Memory Lane with Lotus Notes
   An application for scanning physical mail and distributing it virtually
   Managing Notes deployments with Teamstudio Build Manager
Home > Lotus Technologies > Application Development (48 articles)
   An application for scanning physical mail and distributing it virtually
   How hide-whens in Rich Text can ruin your whole day (and what to do about it)
   Little known traps about Lotus Notes fields
Home > Strategies > Document Management (14 articles)
   An application for scanning physical mail and distributing it virtually
   Evaluating your Domino Document Manager (Domino.Doc) transition options
   What to look for in a Domino-based document management solution
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent DominoPower Articles
Application development, William Shatner, and the origin of the universe
Learn Domino Designer 8.5 for free
The (near) future of Sametime, Quickr, Connections, and Symphony
Inside the IBM Innovations lab
Lotusphere 2010: Hot fixes and cool news for Notes, Domino, and LotusLive
Lotusphere 2010: mobility and collaboration
2010: A Lotusphere of change
Latest Lotus Headlines
SNTT : XPages onclick Ghosts in the machine
Ports used by Lotus Sametime 8.5 servers
Exploring a Domino Date Bug
Adding Quick Highlighter support to IBM Lotus Notes Domino Wiki, Weblog, or Webpage
Remember Young Admins...there are 2 files
WebSphere Portal 6.1.0.2 and Lotus Domino 8.5
The CKEditor - with Domino
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad defenders have spoken
David Gewirtz Online: CNN commentary and analysis
OutlookPower: More about disappearing text
-- Advertisement --

Sophisticated Meets Simple For Document Management
Share. Control. Manage.
Documents, emails, and content in the context of how work is done. Native to Lotus Domino. The User Experience unseen for Lotus Domino. Do more with less. Really.

See the possibilities Docova unleashes for Lotus Domino.
-- Advertisement --

Struggling with exporting Notes data to spreadsheets? No More!
Try IntelliPRINT, The world's leading Reporting, Dashboards, and Analysis solution for Notes & Domino

  • Don't spend unproductive time maintaining different versions of the same spreadsheet
  • Preserve data integrity and security in multi-user environments
  • Create reports in minutes INSIDE Notes
  • Get freedom from iterative report requests, deliver self-serve capabilities

Experience Reporting, Dashboards, and Analysis INSIDE Notes.

Try IntelliPRINT NOW!

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Editor's Login