Step 3: Select or Create the Sync Identity
451
iv. Accept the certificate request. For example:
certreq -accept cernew.cer
v. Make sure that the server certificate is present on the Active Directory server. In the
File
menu, click
Add/Remove
, then click
Certificates
and
Personal>Certificates
.
vi. Import the CA certificate from Directory Server into Active Directory. Click
Trusted Root
CA
, then
Import
, and browse for the Directory Server CA certificate.
For more information, see
http://support.microsoft.com/default.aspx?scid=kb;en-us;321051
.
19.2.3. Step 3: Select or Create the Sync Identity
There are two users used to configure Windows Sync: an Active Directory user, specified in the sync
agreement, and a Directory Server user, specified in the
Password Sync
service.
The user specified in the sync agreement is the entity as whom the Directory Server binds to Active
Directory to send and receive updates. The Active Directory user should be a member of the Domain
Admins group, or have equivalent rights, and must have rights to replicate directory changes. This
limits the extent of the Windows directory that can be affected by the sync ID to only the synchronized
subtree. For information on adding users and setting privileges in Active Directory, see the Microsoft
documentation.
The user references in the
Password Sync
service must have read and write permissions to every
entry within the synchronized subtree and absolutely must have write access to password attributes in
Directory Server so that
Password Sync
can update password changes.
For security reasons, the
Password Sync
user should not be Directory Manager and should not
be part of the synchronized subtree. For information on adding users, see
Chapter 2, Creating
Directory Entries
; for information on setting permissions, see
Chapter 6, Managing Access Control
.
For information on creating a special sync ID, see
Section 8.3, “Creating the Supplier Bind DN Entry”
NOTE
The user cited in the sync agreement (the supplier DN) exists on the Active Directory
server. The user cited in the
Password Sync
configuration exists on Directory Server.
19.2.4. Step 4: Install and Configure the Password Sync Service
Password Sync
can be installed on any Windows machine to synchronize Windows passwords.
Passwords can only be synchronized if both the Directory Server and Windows server are running
in SSL, the sync agreement is configured over an SSL connection, and certificate databases are
configured for
Password Sync
to access.
1. Copy the
PassSync.msi
file that contains the
Password Sync
utility to the Active Directory
machine.
2. Double-click on the
PassSync.msi
file to install it.
3. The
Password Sync
Setup window will appear. Hit
Next
to begin installing.
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...