[Date Prev][Date Next] [Chronological] [Thread] [Top]

RE: OpenLDAP <-> Advanced Directory Syncs



> -----Original Message-----
> From: owner-openldap-software@OpenLDAP.org
> [mailto:owner-openldap-software@OpenLDAP.org]On Behalf Of Lon Tierney

> > Just as a data point: Sun One 5.2 (Beta) now has the ability to do
> > this.  We're not sure to what extent. I need to show that ability
> > within  OpenLDAP if I'm to sell this solution to management.

> > Thus, my original question stands: Is there a way, within
> > OpenLDAP to extract info from an ADS?

back-ldap and back-meta will fetch data in realtime. They can also be used to
perform some manipulation/rewriting of some of the data. You should try
reading the FAQ. http://www.openldap.org/faq/data/cache/756.html

> Unknown, but if you look at recent messages on this list
> regarding AD you
> will see that there are some limitations to what you can get from AD -
> independent of the client (you can find more information on
> AD from other
> sources). As long as you don't need restricted bits of info, any "Meta
> Directory" type of product should work for you.
>
> You may be able to use an OpenLDAP backend to read data from AD on a
> request-by-request basis, or use a referral to you AD server.
> Does anyone
> know if there is any OpenLDAP-based "pull-type"
> synchronization component?

There's some of this in CVS. However, the OpenLDAP "pull-model" sync code is
based on two competing Internet Drafts, and it's unclear what spec will make
it to Standard. As the drafts require cooperation from the server, and I
doubt AD supports either method, the question is moot.

  -- Howard Chu
  Chief Architect, Symas Corp.       Director, Highland Sun
  http://www.symas.com               http://highlandsun.com/hyc
  Symas: Premier OpenSource Development and Support