22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CN=David Hinkle<br />

EmpID=1234<br />

Dept=ISSL<br />

CN=David Hinkle<br />

EmpID=1234<br />

UID=DH9876<br />

database 1<br />

database 2<br />

Figure 8-13 Central master directory<br />

342 Lotus Security Handbook<br />

central master<br />

CN=David Hinkle<br />

EmpID=1234<br />

Dept=ISSL<br />

Mail=dave@ibm.com<br />

UID=DH9876<br />

database 3<br />

As illustrated in Figure 8-13, the central master performs the function of<br />

aggregating all attributes and storing them in a “master record.” The arrows<br />

depicted show the data flow going from the source directories (databases 1, 2,<br />

and 3) to the central master. Note that the CN and EmpID attributes are being<br />

used as the correlation keys for data provided from databases 1 and 2. This is a<br />

typical scenario where the master directory aggregates feeds from all other<br />

subordinate/spoke directories. Although the diagram does not depict this, note<br />

that it is also possible for attributes stored in the central master that came from<br />

one subordinate to be pushed from the master to a different subordinate<br />

directory. Typically, a limited number of attributes are shared between the<br />

subordinate directories in this architecture. When updating attributes in the<br />

subordinate directories, it is extremely important to keep track of the authoritative<br />

source of each attribute. A central directory generally does not strictly enforce<br />

authoritative sources. As a result, care must be taken when allowing the same<br />

attribute (other than correlation keys) to be accepted from the subordinates.<br />

Metadirectories have the advantage of real-time merging of data in addition to<br />

directory synchronization, but with this capability comes risks associated with the<br />

performance of the service. Because the various source directories are accessed<br />

over network connections, the data retrieval via the connectors is only as fast<br />

and reliable as the underlying infrastructure.<br />

Central directories have the advantage of being able to provide the merged data<br />

immediately. However, the frequency of the synchronization with the spoke

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!