IBM Redbook - Using LDAP for Directory Integration (2004).pdf

(2289 KB) Pobierz
SG246163.book
Front cover
Directory Integration
or
Integration guidelines for systems
administrators
Examples to help you integrate
directories
Includes IBM Tivoli
Directory Integrator
Steven Tuttle
Kedar Godbole
Grant McCarthy
Using LDAP for
29887635.001.png
International Technical Support Organization
Using LDAP for Directory Integration
February 2004
SG24-6163-01
29887635.002.png
Note: Before using this information and the product it supports, read the information in
“Notices” on page vii.
Second Edition (February 2004)
This edition applies to IBM Tivoli Directory Server V5 release 2, IBM Tivoli Directory Integrator V5
release 2, IBM Lotus Domino Server V6 release 5, and Microsoft Windows 2000 Advanced
Server Active Directory.
© Copyright International Business Machines Corporation 2003, 2004. All rights reserved.
Note to U.S. Government Users Restricted Rights -- Use, duplication or disclosure restricted by GSA ADP
 
Contents
Notices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vii
Trademarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . viii
Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ix
The team that wrote this redbook. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ix
Become a published author . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x
Comments welcome . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xi
Summary of changes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xiii
February 2004, Second Edition . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xiii
Chapter 1. Introduction to Directory Integration . . . . . . . . . . . . . . . . . . . . . 1
1.1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
1.2 Directories . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
1.3 Advantages of using a directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
1.4 Directory Components. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
1.5 IBM Tivoli Directory Integrator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
1.5.1 Directory Integrator software components . . . . . . . . . . . . . . . . . . . . 13
1.5.2 Solution building approach . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
1.6 IBM Tivoli Directory Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
1.7 IBM Lotus Domino 6.5 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
1.8 Microsoft Active Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
1.8.1 Naming contexts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
1.8.2 Logical elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
1.8.3 Physical elements: sites and domain controllers . . . . . . . . . . . . . . . 19
1.8.4 Architecture . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
1.8.5 The role of DNS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
1.8.6 Special roles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Chapter 2. Scenario 1: Domino and Active Directory . . . . . . . . . . . . . . . . 23
2.1 Scenario 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
2.2 Synchronizing Active Directory and Domino Directory using ADSync . . . 25
2.3 Installing the ADSync tool . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
2.4 Enabling Domino Directory synchronization . . . . . . . . . . . . . . . . . . . . . . . 27
2.5 Registering users of Active Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
2.5.1 Registering existing Active Directory users in Domino . . . . . . . . . . . 32
2.5.2 Registering new users in both Active Directory and Domino . . . . . . 37
2.6 Registering users using the Domino Administrator client . . . . . . . . . . . . . 41
2.7 Deleting users . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45
© Copyright IBM Corp. 2003, 2004. All rights reserved.
iii
Zgłoś jeśli naruszono regulamin