The LDAP Directory Life After Sun
Alban MEUNIER
IdM Senior consultant ameunier@smartwavesa.com www.smartwavesa.com
The LDAP Directory Life After Sun A story of migration Alban - - PowerPoint PPT Presentation
The LDAP Directory Life After Sun A story of migration Alban MEUNIER IdM Senior consultant ameunier@smartwavesa.com www.smartwavesa.com Agenda Introduction Common layer Migrate a standalone instance Migrate a replicated infra
Alban MEUNIER
IdM Senior consultant ameunier@smartwavesa.com www.smartwavesa.com
The LDAP Directory Life After Sun 2
3 The LDAP Directory Life After Sun
The LDAP Directory Life After Sun 4
5 The LDAP Directory Life After Sun
The LDAP Directory Life After Sun 6
The LDAP Directory Life After Sun 7
The LDAP Directory Life After Sun 8
http://pen.iana.org/pen/PenApplication.page
The LDAP Directory Life After Sun 9
avoid redundancy and conflicting rules limit personal ACLs and privilege group/sub tree
Change log, audit log, persistent search External tool for delta evaluation Identity management, provisioning
Server-Side Sort Control, Virtual List View Control, ... Persistent Search Control, Proxy Authorisation Control, Get
Effective Rights Control, ….
The LDAP Directory Life After Sun 10
ldapsearch –s base –b "" (objectclass=*) supportedControl
complexity entries concerned inheritance
Pointers to the password policy Failed login count Locked status
The LDAP Directory Life After Sun 11
The LDAP Directory Life After Sun 12
The LDAP Directory Life After Sun 13
find a workaround in the client applications develop a custom extension of the directory if possible change the version/vendor of the new directory
The LDAP Directory Life After Sun 14
tools with http://myvd.sourceforge.net/bridge.html)
The LDAP Directory Life After Sun 15
The LDAP Directory Life After Sun 16
Environment Engine Instance Configuration
The LDAP Directory Life After Sun 17
The LDAP Directory Life After Sun 18
19 The LDAP Directory Life After Sun
Sun –> Redhat DS, CentOS DS, 389 OpenDS –> OpenDJ, Oracle Unified Directory
Old to new 2 ways are rarely supported
The LDAP Directory Life After Sun 20
Normalise DN (‘, ’ –> ‘,’ case) Add: objectClasse, default values Remove: system attributes, incompatible attributes/objectclass Change: attribute name, trim spaces, date format, DIT, referals ….
The LDAP Directory Life After Sun 21
++++ script +++++
Normalize DN (‘, ’ –> ‘,’ case) Add: objectClasse, default values Remove: system attributes, incompatible attributes/objectclass Change: attribute name, trim spaces, date format, DIT, referals ….
The LDAP Directory Life After Sun 22
23 The LDAP Directory Life After Sun
If nb of existing replica is already at it’s max supported,
unconfigure one replica
Old to new 2 ways are rarely supported
Adapt the procedure with referal, multiple dbs, …
The LDAP Directory Life After Sun 24
consolidated export timestamp sorted)
The LDAP Directory Life After Sun 25
26 The LDAP Directory Life After Sun
What about the LDAP directory life after Sun 27
If nb of existing replica is already at it’s max, unconfigure one
replica
Old to new 2 ways are rarely supported
REPLICATION over LDAP and not using binary feeding
What about the LDAP directory life after Sun 28
to separate write and read requests to migrate step by step
The LDAP Directory Life After Sun 29
30 The LDAP Directory Life After Sun
The LDAP Directory Life After Sun 31
32 The LDAP Directory Life After Sun