适用于: Exchange Server 2007 SP3, Exchange Server 2007 SP2, Exchange Server 2007 SP1, Exchange Server 2007
上一次修改主题: 2007-03-19
早期版本的 Microsoft Exchange Server 并不很依赖于属性集在域分区中应用权限。尽管这在典型部署中并不是问题,但是对于委派所有任务的分布式环境,这可能会成为一个问题。这些环境中的管理员必须为邮件收件人的大量属性委派权限,以便可以在权限最低访问模型中委派相应的任务。根据 Active Directory 目录服务服务器的版本,可能会导致访问控制列表 (ACL) 严重膨胀,从而增大 Ntds.dit 文件的大小。
Exchange Server 2007 通过对大多数邮件收件人属性使用属性集来改善管理委派。
什么是属性集?
属性集是一组 Active Directory 属性。通过设置一个访问控制条目 (ACE),而不必设置每个属性的 ACE,就可以控制对这组 Active Directory 属性的访问权。此外,属性只能是一个属性集的成员。
在 Exchange Server 2003 中,Exchange 架构扩展进程在内置的 Active Directory 属性集(Personal Information 和 Public Information)中添加了许多与 Exchange 有关的邮件收件人属性。在域准备阶段,为 Exchange Enterprise Servers 域本地安全组委派了在域分区上访问这些属性集的权限,以便收件人更新服务 (RUS) 可以更新对象。下表列出 Personal Information 和 Public Information 属性集中的属性。
Public Information 属性集
allowedAttributes
allowedAttributesEffective
allowedChildClasses
allowedChildClassesEffective
altRecipient
altRecipientBL
altSecurityIdentities
attributeCertificate
authOrig
authOrigBL
autoReply
autoReplyMessage
cn
co
company
deletedItemFlags
delivContLength
deliverAndRedirect
deliveryMechanism
delivExtContTypes
department
description
directReports
displayNamePrintable
distinguishedName
division
dLMemberRule
dLMemDefault
dLMemRejectPerms
dLMemRejectPermsBL
dLMemSubmitPerms
dLMemSubmitPermsBL
dnQualifier
enabledProtocols
expirationTime
extensionAttribute1
extensionAttribute10
extensionAttribute11
extensionAttribute12
extensionAttribute13
extensionAttribute14
extensionAttribute15
extensionAttribute2
extensionAttribute3
extensionAttribute4
extensionAttribute5
extensionAttribute6
extensionAttribute7
extensionAttribute8
extensionAttribute9
extensionData
folderPathname
formData
forwardingAddress
givenName
heuristics
hideDLMembership
homeMDB
homeMTA
importedFrom
initials
internetEncoding
kMServer
language
languageCode
legacyExchangeDN
mail
mailNickname
manager
mAPIRecipient
mDBOverHardQuotaLimit
mDBOverQuotaLimit
mDBStorageQuota
mDBUseDefaults
msDS-AllowedToDelegateTo
msDS-Approx-Immed-Subordinates
msDS-Auxiliary-Classes
msExchADCGlobalNames
msExchALObjectVersion
msExchAssistantName
msExchConferenceMailboxBL
msExchControllingZone
msExchCustomProxyAddresses
msExchExpansionServerName
msExchFBURL
msExchHideFromAddressLists
msExchHomeServerName
msExchIMACL
msExchIMAddress
msExchIMAPOWAURLPrefixOverride
msExchIMMetaPhysicalURL
msExchIMPhysicalURL
msExchIMVirtualServer
msExchInconsistentState
msExchLabeledURI
msExchMailboxFolderSet
msExchMailboxGuid
msExchMailboxSecurityDescriptor
msExchMailboxUrl
msExchMasterAccountSid
msExchOmaAdminExtendedSettings
msExchOmaAdminWirelessEnable
msExchOriginatingForest
msExchPfRootUrl
msExchPFTreeType
msExchPoliciesExcluded
msExchPoliciesIncluded
msExchPolicyEnabled
msExchPolicyOptionList
msExchPreviousAccountSid
msExchProxyCustomProxy
msExchQueryBaseDN
msExchRecipLimit
msExchRequireAuthToSendTo
msExchResourceGUID
msExchResourceProperties
msExchTUIPassword
msExchTUISpeed
msExchTUIVolume
msExchUnmergedAttsPt
msExchUseOAB
msExchUserAccountControl
msExchVoiceMailboxID
name
notes
o
objectCategory
objectClass
objectGUID
oOFReplyToOriginator
otherMailbox
ou
pOPCharacterSet
pOPContentFormat
protocolSettings
proxyAddresses
publicDelegatesBL
replicatedObjectVersion
replicationSensitivity
replicationSignature
reportToOriginator
reportToOwner
securityProtocol
servicePrincipalName
showInAddressBook
sn
submissionContLength
supportedAlgorithms
systemFlags
targetAddress
telephoneAssistant
textEncodedORAddress
title
unauthOrig
unauthOrigBL
unmergedAtts
userPrincipalName
Personal Information 属性集
assistant
c
facsimileTelephoneNumber
homePhone
homePostalAddress
info
internationalISDNNumber
ipPhone
l
mobile
mSMQDigests
mSMQSignCertificates
otherFacsimileTelephoneNumber
otherHomePhone
otherIpPhone
otherMobile
otherPager
otherTelephone
pager
personalTitle
physicalDeliveryOfficeName
postalAddress
postalCode
postOfficeBox
preferredDeliveryMethod
primaryInternationalISDNNumber
primaryTelexNumber
publicDelegates
registeredAddress
st
street
streetAddress
telephoneNumber
teletexTerminalIdentifier
telexNumber
thumbnailPhoto
userCert
userCertificate
userSharedFolder
userSharedFolderOther
userSMIMECertificate
x121Address
但是,在通过委派权限来管理邮件收件人之后,许多 Active Directory 管理员没有使用这些属性集为 Exchange 管理员委派权限,因为这些属性集提供对许多其他与 Exchange 无关的属性的访问权限。
Exchange 2007 中的属性集
Exchange 2007 通过为 Exchange Server 单独创建两个新的属性集(而不是依赖于现有的 Active Directory 属性集)来利用属性集。Exchange 2007 中进行了下列多项改进:
不再依赖于默认的 Active Directory 属性集。Exchange 特定的属性集可以应对以后的 Active Directory 属性集版本中进行潜在更改的不确定性。