22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

New for<br />

Domino 6<br />

458 Lotus Security Handbook<br />

Using a central directory architecture in a Domino domain<br />

Prior to Domino 6, companies always used a distributed directory architecture in<br />

which every server in a Domino domain had a full replica of the domain's primary<br />

Domino Directory. A primary directory contains all types of documents:<br />

documents used to provide directory services such as Person and Group<br />

documents, as well as documents used to configure Domino servers.<br />

In this release, companies can implement a central directory architecture, in<br />

which a few directory servers in a domain have a replica of the primary Domino<br />

Directory that contains the entire contents of the Domino Directory. The other<br />

servers in the domain have a Configuration Directory, which is a small, selective<br />

replica of the Domino Directory that contains only documents used for Domino<br />

configuration. A server with a Configuration Directory uses a primary Domino<br />

Directory on another server – referred to as a remote primary Domino Directory –<br />

to look up information in Person, Group, Mail-In Database, and Resource<br />

documents, and in any new types of custom documents a company has added to<br />

the directory.<br />

A central directory architecture allows for tighter administrative control over<br />

directory management because only a few directory replicas contain user and<br />

group information. In addition, application and mail servers can run on less<br />

powerful machines than the directory servers require, since the application and<br />

mail servers don't have to store a primary Domino Directory, which can be the<br />

largest database in a company. If the user and group information in a directory<br />

changes frequently, the servers with Configuration Directories have immediate<br />

access to the changes that critical business applications and processes require,<br />

because they don't have to wait for the changes to replicate locally.<br />

To use a central directory architecture, you must have adequate network<br />

bandwidth to support the remote primary directory lookups. For failover, it is also<br />

important that at least two servers in a domain are configured as remote primary<br />

Domino Directories.<br />

11.6.3 Directory assistance<br />

Directory assistance is a feature a server can use to look up information in a<br />

directory other than a local primary Domino Directory (NAMES.NSF). You can<br />

configure directory assistance to use a particular directory for any of these<br />

services:<br />

► Client authentication (including Web browser/HTTP clients)<br />

► Group lookups for database authorization<br />

► Notes mail addressing<br />

► LDAP service searches or referrals

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!