
Active Directory Schema Compatibility
Chapter 18
Windows Sync
567
The total update time shows when the last resynchronization operation completed.
Modifying the Synchronization Agreement
It is possible to modify parts of the synchronization agreement after it has been
created.
In the Configuration>Replication tab of the Directory Server Console, select the
sync agreement icon from beneath the database. There are two tabs: Summary, and
Connection.
• The Summary tab allows you to change the description of the agreement. This
tab also shows the sync peer host and port information and synchronized
subtrees.
• The Connection tab will let you change the bind DN and bind credentials for
the sync manager. It will also show whether this is over an SSL connection.
Finally, it shows whether new user and group entries will be created in the
Directory Server.
Active Directory Schema Compatibility
Although Active Directory supports the same basic X.500 object classes as
Directory Server, there are a few subtle incompatibilities of which administrators
should be aware:
• Both Active Directory and Directory Server can enforce
password policy
that can
enforce certain requirements upon passwords: minimum length, maximum
age and so forth. Windows Sync does not synchronize the policies, nor does it
ensure that the policies are consistent. This is something that the
administrators of both systems must ensure is done. If password policy is not
consistent, then password changes made on one system may fail when
replayed on the other system.
• Nested groups (where a group contains another group as a member) are
supported and will be synchronized. However, Active Directory imposes
certain constraints for the composition of nested groups. For example, a global
group may not be a member of a local group. Directory Server has no concept
of local and global groups, and therefore, it is possible to create entries on the
Directory Server side that will violate Active Directory’s constraints when
synchronized. Again, it is the responsibility of the administrators to ensure that
this does not happen.
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...