Chapter 19. Synchronizing Red Hat Directory Server with Microsoft Active Directory
458
begins). When a new Windows user account is created, a corresponding entry will automatically be
created on the peer Directory Server. If an existing sync agreement is modified to begin synchronizing
users, the Windows users will be added to the Directory Server after the next total update.
A new Directory Server user account is synchronized to a Windows server if the new Directory Server
entry uses the
ntUser
object class and the
ntUserCreateNewAccount
attribute. New users that
are created on the Directory Server with the
ntUser
object class are synced to the Windows machine
at the next regular update; existing users that have the
ntUser
object class added are synchronized
at the next total update.
Special schema are applied to synchronized user entries in the Directory Server. This schema are
similar, but not identical, to that used by Netscape Directory Server 4.x NT Synchronization.
All synchronized entries in the Directory Server, whether they originated in the Directory Server or in
Active Directory, have special synchronization attributes.
•
ntUniqueId.
This contains the value of the
objectGUID
attribute for the corresponding Windows
entry. This attribute is set by the synchronization process and should not be set or modified
manually.
•
ntUserDomainId.
This corresponds to the
sAMAccountName
attribute for Active Directory entries.
•
ntUserDeleteAccount.
This attribute is set automatically when a Windows entry is synced over but
must be set manually for Directory Server entries. If
ntUserDeleteAccount
has the value
true
,
the corresponding Windows entry be deleted when the Directory Server entry is deleted.
Setting
ntUserCreateNewAccount
and
ntUserDeleteNewAccount
on Directory Server entries
allows the Directory Manager fine-grained control over which users within the synchronized subtree
will be synched on Active Directory, similar to selecting in the sync agreement whether to synchronize
new Windows users.
When creating a Directory Server user in the Console (see
Section 2.1.2, “Creating Directory Entries”
),
there is an
NT User
tab in the
New User
dialog. Fill in this information to supply Windows attributes
automatically.
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...