Digital Equipment Corporation
|
Enterprise Messaging Services Fact Sheet
|
Digital LDAP Directory Synchronizer Utility (LDSU)
Release 1.0
Description
Digital LDAP Directory Synchronizer Utility (LDSU) is a software tool that
provides directory data exchange between a central LDAP directory and virtually
any other directory or database. LDSU can provide a necessary component to
incorporate an enterprise-wide Meta-Directory service by providing a method to
synchronize all directories. LDSU enables the automated and bi-directional
exchange of electronic directory information in a multi-vendor environment .
LDSU works with any directory that supports the LDAP protocol, or RFC 1777.
LDSU is a batch interface to the LDAP directory that supports both import and
export. It accepts formatted directory feeds from other directory databases.
LDSU views the LDAP directory as the central repository for directory
information. When new feeds are processed, LDSU uses intelligent algorithms to
synhronize the new data with what is already in the LDAP directory. LDSU can
generate formatted directory data files representing what is in the LDAP
directory as well.
LDSU can provide bi-directional directory synchronization between other email
directories such as: Microsoft Exchange, Lotus Notes, Digital's ALL-IN-1,
GroupWise and many others. LDSU can be customized to support virtually any
directory. With the expansive set of features, it can be used to generate
lists, such as White Pages and Yellow Pages.
Features
- LDSU provides bi-directional synchronization between any LDAP directory and
virtually ANY other directory to provide the data exchange and synchronization
necessary for an enterprise-wide Meta Directory.
- The Import feature loads the LDAP directory with information from virtually
any existing directory or other source of information, such as an electronic
mail address list or Human Resources system. Incoming information in various
formats is mapped into LDAP by using flexible configuration files. LDSU allows
for initial bulk-loading of directory information, as well as ongoing
synchronization maintenance. Import feeds can be either in the form of a full
feed or a delta feed.
- The Export feature uses highly-flexible configuration files that permit the
extracted directory information to be tailored into a form ready for use by the
receiving directory. It allows an extract of the full directory, a subset of
the directory (based on Directory Group ID or selected LDAP directory
attributes), or only the recent changes. Extracts can be formatted specifically
for the target directory database being updated.
- With LDSU, virtually any directory can be synchronized with the LDAP
directory through the use of site-specific Record Description Files (RDFs).
- During the import process, RDFs define the directory file format and map
this information appropriately into the LDAP directory attributes. The import
directory feed need only be a sequential file in fixed or variable length field
format. During the export process, RDFs allow the exported information to be put
into the exact format needed by the receiving directory system.
- LDSU tags all entries with a unique (and configurable) Directory Group ID
(Group ID.) Use of Group IDs simplifies identification, maintenance and
reporting functions. It is especially useful with the export feature because it
allows the directory administrator to specify which portions of the LDAP
directory to extract. A Group ID attribute is associated with each entry in the
LDAP directory being managed by LDSU. The actual attribute used to contain this
information is selected by the directory administrator.
In addition, LDSU includes several features that specifically support import and
export synchronization of electronic mail directory information. These features
are:
Import Synchronization
- Provides capability to initially bulk-load directory information into the
LDAP directory which simplifies and reduces what was previously a tedious,
manual maintenance effort.
- Provides capability to load deltas from external directories.
- Allows each entry in the LDAP directory to contain an unlimited number of
electronic mail address aliases per user (barring any limitation on the LDAP
directory.) Each address alias can optionally be checked for uniqueness within
the LDAP directory.
- Ensures the integrity of the enterprise-wide Meta-Directory by performing
configurable uniqueness checking on multiple fields or combination of fields.
This prevents address duplication.
- Includes the option to create a unique, system-wide nickname in
the LDAP Directory for each entry.
Export Synchronization
- Allows the directory administrator to select whether all, or only
specialized subsets of the directory information is exported. Options available
include:
- full directory export
- selective export (subset selectable via Group ID(s) or other LDAP attributes
from the specified search context)
- changes only (export only the entries changed during synchronization
session. This is useful when synchronizing with populations that may not be
capable of processing complete directory updates on a regular basis)
- Creates export directory files in a ready-to-use format.
Record Description Files (RDF)
- Permits the directory administrator to supply default values for any field
in the RDF. This is a useful feature when all users in a directory or Group ID
share the same information, (e.g., Department Name).
- Includes example import and export RDFs to use in synchronization operations
with Microsoft Exchange, Innosoft's PMDF tables, a UNIX Sendmail alias table,
etc.
- Allows complex conditional logic to be applied in import and export RDFs-an
important feature which permits the ability to check the value of data in
fiellds and allows for conditional processing based on the results of this
check. Conditional operators include "equal to", "not equal to", "exists", "does
not exist", "is a substring of", and "is not a substring of". Additionally,
conditional logic on multiple fields can be combined (using "or", "and", and
"not" operators) to determine the values to place into fields.
- Allows input and output file filtering, which provides the ability to ignore
certain records depending on a condition. This can be especially useful when
using IMPORT mode since the foreign directory input file contains a full dump of
a foreign directory which may contain records which are "local" and should not
be synchronized.
Management
- LDSU supports all attributes that are present in the LDAP directory.
- Synchronizes a virtually unlimited number of directory files simultaneously,
with no upper limit on the number of Group IDs that can be stored within the
LDAP Directory.
- Allows LDSU's file names and directory locations to be changed to suit to
your environment's unique requirements,
- Provides import transaction logging, including:
- Full logging (optional), when it is important to capture an exact account of
the transaction updates to the LDAP directory,
- Condensed logging, listing start- and end-processing times, and the entry's
transaction type (ADD, MODIFY, or DELETE), distinguished name, and status
(SUCCESS or FAILED)
- Transaction statistics summary reporting at processing completion, listing
start- and end-processing times for each Group ID, the total number of
transactions processed, and the number of successful ADDs, MODIFYs, DELETEs, and
FAILs
- Permits invocation of an external command procedure (script) that can be
used to execute notification, clean-up, and post-processing operations at
selected intervals and at the end of a LDSU run.
- Can notify the directory administrator, via electronic mail, of the status
of LDSU runs by providing a copy of the Transaction Statistics Summary Report.
Enterprise Messaging Services
Digital Software Integration services are available to assist you in
implementing LDSU. These consulting services are designed to help ensure a
smooth rollout of this technology within your enterprise. For more information
on Digital Software Integration services, contact your local Digital office.
Software Licensing
This software is furnished under the licensing provisions of Digital Equipment
Corporation's Standard Terms and Conditions. For more information about
Digital's licensing terms and policies, contact your local Digital office.
Warranty
The Digital LDAP Directory Synchronizer Utility software is warranted to conform
to this Digital LDAP Directory Synchronizer Enterprise Messaging Service Fact
Sheet. This means that Digital will remedy any nonconformance when it is
reported to Digital in writing by the Customer during the warranty period. The
Warranty period is ninety (90) days. It begins when the software is installed or
thirty days after delivery to the end user, whichever occurs first, and expires
90 days later.
Optional Extended Warranty, providing functionality enhancement updates during
the period of coverage, is also offered.
Telephone support is available.
Media and Documentation
Digital LDAP Directory Synchronizer Utility software and documentation
is supplied on floppy diskette.
Software Requirements
LDSU currently runs on the following operating systems. The sole requirement
of each system is TCP/IP Networking.
- Windows NT V4.0 or Later (Alpha or Intel)
- Digital UNIX V3.2 or Later (Alpha)
- OpenVMS V6.1 or Later (Alpha or Vax)
Optional Software
LDSU interacts with any directory product that supports the V2 LDAP protocol and
is accessible to the system where LDSU is installed through TCP/IP Networking.
Some examples of directory products are:
- Digital X.500 Directory Services for Digital UNIX
- Digital AltaVista Directory for Windows NT
- Microsoft Exchange Server V5.5
More Information
For more information about Digital LDAP Directory Synchronizer Utility, send
mail to DirSolutions@digital.com.
Copyright © Digital Equipment Corporation 1998. All rights reserved.