Cyril's Identity Management Blog

Aller au contenu | Aller au menu | Aller à la recherche

lundi 29 mars 2010

LDAP Tools v1.0

For those who are looking for a web interface, either simple or sophisticated, to their LDAP directory, I suggest you to check this site out. It may also be worth browsing if you're interested in LDAP monitoring or provisioning.

I also plan to update this site each time a new tool or tool version will be available.

Some thoughts about replication between heterogeneous LDAP directories

I recently did some searches on what was going in the LDAP replication world, and especially the efforts to adopt a common replication protocol between directory vendors, that would allow them to replicate between each others. In the world of legacy directory servers, no standard's been adopted, since there was little commercial interest at least. The LDUP series of draft is a good example of aborted works in that direction. But since we now have at least 4 open source LDAP directories out there (OpenLDAP, Fedora, Apache DS and OpenDS), new developments and open source LDAP replication protocols 've been proposed and try to emerge.

For example, the LDAP Content Synchronization Operation protocol (RFC 4533), also known as "syncrepl", while experimental, published since 2006, and implemented at first in OpenLDAP, 's finally been recently chosen by the Apache DS team, although it's not clear wether it's fully or partially supported. Moreover, syncrepl's not optimized as this protocol transfers all visible values of entries belonging to the content upon change instead of change deltas. Delta-syncrepl improves syncrepl on that point, but it's not yet been published.

On the other side, neither Fedora DS nor OpenDS have plans to implement this RFC, but Fedora DS can already synchronize with older SUN DS versions and Netscape directory server: see this.

So, it seems like things are going better but some work has yet to be done. Provisioning engines, meta-directories, LDAP proxies, virtual directories, dedicated synchronization plugins or custom synchronization procedures should continue to exist for a while ...