Nested groups enable the creation of hierarchical relationships that are used to define inherited group membership. A nested group is defined as a child group entry whose distinguished name (DN) is referenced by a parent group entry attribute.
Dynamic and nested groups simplify WebSphere Application Server security management and increase its effectiveness and flexibility. You only need to assign a larger parent group if all nested groups share the same privilege. Assigning a role to a single parent group simplifies the runtime authorization table.
Related concepts
Dynamic groups and nested group support for the IBM Tivoli Directory
Server
Dynamic and nested group support for the SunONE or iPlanet Directory
Server
Locating a user's group memberships in Lightweight Directory Access
Protocol
Related tasks
Configuring dynamic and nested group support for the IBM Tivoli Directory
Server
Configuring dynamic and nested group support for the SunONE or iPlanet
Directory Server
Using specific directory servers as the LDAP server