
Chapter 19. Synchronizing Red Hat Directory Server with Microsoft Active Directory
462
• On Windows 2000, Active Directory creates a new entry with a new unique ID; this new ID is
synched back to the Directory Server entry.
• On Windows 2003, Active Directory resurrects the old entry and preserves the original unique ID for
the entry.
For Active Directory entries on both on Windows 2000 and 2003, when the tombstone entry is
resurrected on Directory Server, all of the attributes of the original Directory Server are retained and
are still included in the resurrected Active Directory entry.
19.3.5. Manually Updating and Resynchronizing Entries
Synchronization occurs every five minutes. However, an incremental update can be done manually if
there are changes that need synchronized immediately.
To perform an incremental update manually:
1. Go to the
Configuration
tab in the Console.
2. Right-click on the synchronization agreement icon, and select
Send and Receive Updates
from
the drop down menu.
During normal operations, all the updates made to entries in the Directory Server that need to be sent
to Active Directory are collected the changelog and then replayed during an incremental update.
However, when the synchronization is initially configured, there have been major changes to data, or
synchronization attributes are added to pre-existing Directory Server entries, it is necessary to initiate
a
resynchronization
. Resynchronization is a total update; the entire contents of synchronized subtrees
are examined and, if necessary, updated. Resynchronization is done without using the changelog.
To send a total update:
1. Go to the
Configuration
tab in the Console.
2. Right-click on the synchronization agreement icon, and select
Initialize Re-synchronization
from
the drop down menu.
This will not delete data on the sync peer; it will send and receive all updates and add any new or
modified Directory Server entries; for example, it will add a pre-existing Directory Server user that
had the
ntUser
object class added.
19.3.6. Checking Synchronization Status
Check synchronization status in the
Replication
tab in the
Status
of the Console. Highlight the
synchronization agreement to monitor, and the relevant information should appear in the right-hand
pane. The
Status
area shows whether the last incremental and total updates were successful and
when they occurred.
19.3.7. Modifying the Sync Agreement
It is possible to modify parts of the synchronization agreement after it has been created.
In the
Configuration
>
Replication
tab of the Directory Server Console, select the sync agreement
icon from beneath the database. There are two tabs,
Summary
and
Connection
.
Summary of Contents for DIRECTORY SERVER 8.0
Page 18: ...xviii ...
Page 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Page 30: ...12 ...
Page 112: ...94 ...
Page 128: ...110 ...
Page 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Page 224: ...206 ...
Page 324: ...306 ...
Page 334: ...316 ...
Page 358: ...340 ...
Page 410: ...392 ...
Page 420: ...402 ...
Page 444: ...426 ...
Page 454: ...436 ...
Page 464: ...446 ...
Page 484: ...466 ...
Page 512: ...494 ...
Page 522: ...504 ...