|
M-Vault Connector is a directory server that supports both LDAPv3 and X.500, and can be used to connect an LDAP-only directory server as part of an X.500 Directory Service and build an integrated directory service, linking together other directory servers (LDAP or X.500) into a coherent single directory service. M-Vault Connector is a specialized version of the full M-Vault directory server, not a simple cut-down protocol engine. This gives a number of advantages:
Connecting an LDAP Server to X.500
Governments and organizations often choose to deploy X.500 because it enables departments to operate independent directories, and connect using the standard X.500 directory system protocol (DSP) and replication (DISP). This will typically be achieved by deployment of a central X.500 service, with departments independently selecting their directory server products. M-Vault Connector is useful in situations where a department wishes to deploy an LDAP only directory, which cannot connect to the central X.500 system. M-Vault Connector enables the departmental directory to be integrated with the central directory. Queries are resolved in two basic scenarios:
The performance of this system can be optimized by replication of data.
Integrating Directory Servers
There are many advantages in building a distributed directory. In particular it enables data to be managed locally and in a server that is appropriate to local (and usually most frequent) use. Provided that care is taken with consistent naming of directories and structure of the DIT (Directory Information Tree), multiple directory servers can work together to provide a coherent directory service. In principle, a set of directory servers could all work together as peers. In practice, it works better to have a central M-Vault Connector directory, as shown above. This central directory does not hold any data, but facilitates all of the directories working together. The key value the M-Vault Connector provides in this scenario is that it knows about the location of all of the other directory servers, and can dispatch queries to the server that can resolve them. There are a number of reasons why this is desirable.
Protocols and AuthenticationX.500 DSP distinguishes between the directory servers that are connecting and the initiator of the query. Thus DSP authentication is straightforward, as M-Vault can use DSP peer authentication to an X.500 server. LDAP (and X.500 Directory Access Protocol (DAP)) do not make this distinction. When M-Vault Connector performs LDAP chaining, it must bind to the LDAP directory as a user. M-Vault Connector can be configured to bind anonymously or as a specific user.
|
|
| Copyright © 2009 Isode | sitemap privacy feedback
|