
Deleting Entries
461
Table 19.3, “Group Entry Attribute Mapping between Directory Server and Active Directory”
shows
the attributes that are mapped between the Directory Server and Windows servers, and
Table 19.4,
“Group Entry Attributes That Are the Same between Directory Server and Active Directory”
shows the
attributes that are the same between the Directory Server and Windows servers.
Directory Server
Active Directory
cn
name
ntGroupAttributes
groupAttributes
ntGroupId
cn
name
sAMAccountName
ntGroupType
groupType
Table 19.3. Group Entry Attribute Mapping between Directory Server and Active Directory
cn
member
description
ou
l
seeAlso
Table 19.4. Group Entry Attributes That Are the Same between Directory Server and Active Directory
19.3.3. Deleting Entries
An Active Directory group or user account is automatically deleted from the Directory Server sync
peer server when entry is deleted. The same is true when a Directory Server account is deleted if the
deleted entry has the
ntUserDeleteAccount
or
ntGroupDeleteAccount
attribute set to
true
.
NOTE
When a Directory Server entry is synchronized over to Active Directory for the first
time, Active Directory automatically assigns it a unique ID. At the next synchronization
interval, the unique ID is sychronized back to the Directory Server entry and stored as
the
ntUniqueId
attribute. If the Directory Server entry is deleted on Active Directory
before
the unique ID is synchronized back to Directory Server, the entry
will not
be deleted
on Directory Server. Directory Server uses the
ntUniqueId
attribute to identify and
synchronize changes made on Active Directory to the corresponding Directory Server
entry; without that attribute, Directory Server will not recognize the deletion.
To delete the entry on Active Directory and then synchronize the deletion over to Directory
Server, wait five minutes so that the
ntUniqueId
attribute is synchronized, and then
delete the entry.
19.3.4. Resurrecting Entries
It is possible to add deleted entries back in Directory Server; the deleted entries are called
tombstone
entries. When a deleted entry which was synched between Directory Server and Active Directory
is re-added to Directory Server, the resurrected Directory Server has all of its original attributes and
values. This is called
tombstone reanimation
. The resurrected entry includes the original
ntUniqueId
attribute which was used to synchronize the entries, which signals to the Active Directory server that
this new entry is a tombstone entry. The way that tombstone entries are handled is different between
Windows Server 2000 and Windows Server 2003:
Summary of Contents for DIRECTORY SERVER 8.0
Page 18: ...xviii ...
Page 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Page 30: ...12 ...
Page 112: ...94 ...
Page 128: ...110 ...
Page 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Page 224: ...206 ...
Page 324: ...306 ...
Page 334: ...316 ...
Page 358: ...340 ...
Page 410: ...392 ...
Page 420: ...402 ...
Page 444: ...426 ...
Page 454: ...436 ...
Page 464: ...446 ...
Page 484: ...466 ...
Page 512: ...494 ...
Page 522: ...504 ...