LDAP design question for multiple sites

LDAP design question for multiple sites
I'm planning to implement the Sun Java System Directory Server 5.2 2005Q1 for replacing the NIS.
Currently we have 3 sites with different NIS domains.
Since the NFS over the WAN connection is very unreliable, I would like to implement as follows:
1. 3 LDAP servers + replica for each sites.
2. Single username and password for every end user cross those 3 sites.
3. Different auto_master, auto_home and auto_local maps for three sites. So when user login to different site, the password is the same but the home directory is different (local).
So the questions are
1. Should I need to have 3 domains for LDAP?
2. If yes for question 1, then how can I keep the username password sync for three domains? If no for question 1, then what is the DIT (Directory Infrastructure Tree) or directory structure I should use?
3. How to make auto map work on LDAP as well as mount local home directory?
I really appreciate that some LDAP experta can light me up on this project.

Thanks for your information.
My current environment has 3 sites with 3 different NIS domainname: SiteA: A.com, SiteB:B.A.com, SiteC:C.A.com (A.com is our company domainname).
So everytime I add a new user account and I need to create on three NIS domains separately. Also, the password is out of sync if user change the password on one site.
I would like to migrate NIS to LDAP.
I want to have single username and password for each user on 3 sites. However, the home directory is on local NFS filer.
Say for userA, his home directory is /user/userA in passwd file/map. On location X, his home directory will mount FilerX:/vol/user/userA,
On location Y, userA's home directory will mount FilerY:/vol/user/userA.
So the mount drive is determined by auto_user map in NIS.
In other words, there will be 3 different auto_user maps in 3 different LDAP servers.
So userA login hostX in location X will mount home directory on local FilerX, and login hostY in location Y will mount home directory on local FilerY.
But the username and password will be the same on three sites.
That'd my goal.
Some LDAP expert suggest me the MMR (Multiple-Master-Replication). But I still no quite sure how to do MMR.
It would be appreciated if some LDAP guru can give me some guideline at start point.
Best wishes

Similar Messages

  • Iweb 09_good for multiple site designs

    Hi!
    I am looking to upgrade to a better imac and iWeb 09 to create "microsites" for my current print design clients to help expand their marketing. Is this version of iWeb easy to use for that or does it to multiple sites at all? Basically I am asking is this version a good one for multiple site building? Ease of use for that purpose? Thanks!

    Welcome to the Apple Discussions. iWeb 09 can handle multiple sites quite easily. However, a lot depends on where you plan to host the sites and manage them. Will they each have a domain name for the site?
    On MobileMe you can have only one site with CNAME domain name forwarding to the same account. The others must use the standard html URL forwarding. AND they all must be created in the same Domain.sites2 file. That can be a problem.
    If you use the standard domain name forwarding with MMe for all the sites then you can have a separate domain file for each client and use Web Site Maestro to manage then them and select which one to open and work on.
    If each client will provide their own hosting server then it's possible that CNAME forwarding can be used for each client if they have a domain name and their server supports CNAME.
    I use iWebSites to manage over 75 individual sites. It lets me create multiple sites and multiple domain files.
    This lets me edit several sites and only republish the one I want.
    OT

  • How to send right CallingNumber when Cisco CER is down for multiple sites

    Hi,
    Cisco ER 7.x system with centerized CUCM 7.1(x) cluster for multiple sites over WAN, where each site has local voice gateway (MGCP) with T1/PRI connected. All the phones are DIDs.
    When considering 911 calls redundancy when CER is down, Cisco ER administration guide recommends using Local Route Group for 10911 or something else route-pattern on CUCM which is used:
    http://www.cisco.com/en/US/partner/docs/voice_ip_comm/cer/7_1_1/english/administration/guide/e911plan.html#wp1062106
    To configure LRG, follow these steps:
    1. On Cisco Unified Communications Manager Administration, configure the LRG route pattern and route point for 911 emergency call routing.
    2. On Cisco Unified Communications Manager Administration, configure any destination route point that is being forwarded in the emergency call route point with the LRG route pattern.
    3. On Cisco ER Administration, configure the LRG route pattern as the default ERL.
    My question is:
    On the 10911 route-pattern using LRG, how can configure the each site ELIN number as the calling number on the route-pattern which is normally assigned on E911 partition only? or do I need change MGCP to H.323 in order to achieve this purpose?
    Do I miss something?
    Thanks,
    JJ

    Hi,
    I am not sure with in obiee it is possible? But third party tool we can do it.
    Site scope monitor tool is there, what this tool will do it will send the alert mail to respective team whenever services are down.
    For more information google it? You can get better idea.
    Thanks,
    Satya

  • IPv6 deployment problem for multiple site

    Dear Expert,
    I have a question about the deployment of IPv6 on two different site and the requirement is that client may need to auto switchover to another site while one of the ASR1002 is failure. I have using two different prefix on two sites with IPv6 stateless autoconfig like above diagram. Different prefix used for each site due to each site should use there own IPv6 prefix for Firewall Stateful(Default gateway point to local site firewall only). Client will retrieved two IPv6 addresses at the same time and it seems workable on Vista PC and Mac(Mac haven't select the High DRP one but work fine) and I haven’t try for other mobile device (have WiFi device for vlan100). Is it a valid solution? Any other solution for multiple site deploy IPv6 with Firewall no NAT enabled?
    Thank you very much!
    Regards,
    Kawaii

    One option would be to tweak the OS prefix policy table to prefer v4 to v6.  On Linux this is in /etc/gai.conf; on windows you'd run "netsh interface ipv6 set prefixpolicies ...".  The side effect would be that you'd only do v6 with the v6-only sites, not with the dual-stack sites.

  • AP Payment for multiple sites

    Is there a way to pay more than one site for a supplier in the same payment?

    Hello All,
    Any solution for this situation ? We are on R12 and we would like to pay single payment for multiple sites for same supplier. Anyone has any idea how do we go about this ?
    Thanks in Advance
    Dinesh
    Edited by: Dinesh Chauhan on 11-May-2010 01:15

  • Submitting site maps for multiple sites to Google

    I sort of glommed on to the end of the thread "meta and google-ing...i give up," but I'll start a fresh post here with this:
    I have three sites in iWeb, all of which have their own registered Go Daddy domain names and are forwarded to .mac without masking. I followed James Tseng's instructions and successfully submitted to Google and verified my "www.mac.com/user/iWeb" url.
    I also successfully uploaded a site map for one of my sites (let's just call it Site 1), which is in my iWeb folder (not the Site 1 folder).
    My question: I assume I can create separate site maps for Sites 2 and 3. Do they also go in the same iWeb folder as the first one? Is that possible if they're all named "sitemap.xml" or do they have to be given different names?
    Also... if I want to submit these three sites to other engines like MSN and Yahoo, can I submit the forwarded domain names, or will these engines not follow the forwarding to my .mac url?
    If that's the case, is it best to submit the single "www.mac.com/user/iWeb url" as I did with Google, or should I submit each site's .mac url separately?
    Thanks in advance for your help!
    Mitch

    <As posted in the the other thread...>
    Hi Mitch....
    I hope you've been finding all this helpful so far! It's always fun to see just how much feedback you can get from Google. Sort of gives you a feeling that "you've arrived". haha.
    Regarding your question about sitemaps and multiple sites.... My strategy is this... I like to give Google sort of the broadest catch that I can. That's why I really suggest to people that they register the most general URL... http://web.mac.com/username/iWeb/ . You see how that really leaves the door open for the possibility of multiple sites, without having to register multiple sites. Google really doesn't care that you call them separate sites...to Google they appear as part of the same site...with the same base verified URL.
    So with that registered URL, there really is only one place where the verification file and sitemap.xml file can go. And that place is in the iDisk/Web/Sites/iWeb/ folder. And there is really only a need for a single verification file and a single sitemap.xml file, no matter how many sites you have. The point here isn't telling Google that you have more sites...it's just about telling Google that you have more LINKS in the site that it already knows about.
    So how do you do this? Just spider your new site or gather the links in your own way and then copy and paste the links (just the links section...not the first two lines or the last line of the code) into the sitemap.xml file that you have already submitted before. Then resubmit it to Google.
    Does this make sense? Let me know what you think.

  • Single-signon for multiple sites or sub sites

    Does anyone know of some good articles/publications or suggestions for
    implementing a single signon for multiple very secure internet sites in
    weblogic type environments.
    For example, bank1 has a internet site and bank 2 has an internet site.
    Bank 2 has some cool features they want to offer bank1's customers. They
    agree but, bank1 wants to present bank2 as a tab or part of bank1 site.
    IN order to do this there are lots of fun things, but the things Im
    interested in are how to authenticate between them and handle timeouts.
    timeouts seem particularly tricky in that if I dont hit a page on bank2
    for a while, it could time out its session for the guy on bank1. Also if
    im in the bank2 section of the site, then bank1 could time me out as
    well.
    any ideas let me know.
    thanks
    Joel

    I've been informed ;-) that a pure Java solution is also available from
    Entegrity. So here are a couple of URLs for you to research
    anagrammatically:
    http://www.netegrity.com
    http://www.entegrity.com
    Cameron Purdy
    Tangosol, Inc.
    http://www.tangosol.com
    Tangosol: How Weblogic applications are customized
    "Cameron Purdy" <[email protected]> wrote in message
    news:[email protected]...
    Netegrity?
    Cameron Purdy
    Tangosol, Inc.
    http://www.tangosol.com
    Tangosol: How Weblogic applications are customized
    "Tim Funk" <[email protected]> wrote in message
    news:[email protected]...
    This is long winded and I tried to have this make sense, if it doesn't
    just mark this as read ...
    I am running into the same issue. Out of need, different applications
    need to be hosted on different boxes/JVM's/web applications. I am
    experimenting with a customer single sign on process which is
    independent of Java but lends itself nicely to it. Here is my thoughts:
    1) All applications need to run under the same domain. For example:
    foo.redrose.net, www.redrose.net, bar.redrose.net, app1.redrose.net
    all reside under redose.net.
    2) You have a database table (secure) that contains the following:
    user id, password, session id, last access time.
    3) This database table contains all of the valid sessions across the
    domain (in this exmaple .redrose.net)
    4) There is a daemon running which runs every ?? seconds that deletes
    any records older than ?? seconds/(or minutes/hours) in the
    database.
    5) There exist a cookie which is set to the domain level that contains
    the session id.
    6) The session id provides a way to obtain the id and password for the
    user to authenticate to the container. For example in WL5.1SP8 there
    exists: weblogic.servlet.security.ServletAuthentication.weak(...) to
    authenticate to your container. By using this you will get the
    capability of setting up your roles and ACLS etc in you web.xml and
    weblogic.xml to handle authorization.
    7) All requests to any applications participating in this philosophy
    must do the following for EVERY request (or appropriate):
    Even if you are logged authenticated to the container and authorized,
    you may have timed out or logged out of another application. So the
    database table must be checked to see if the session id exists. At the
    same time, you must also update the last access time to prevent timeout.
    8) If the user tries to access a different application which he has not
    authenticated to yet - the user will be forwarded to a servlet whichwill:
    a) Look for the cookie at the domain level
    b) If the cookie is found - get the UID and PWD from database
    b2) Present login form if cookie is invalid/not exists
    c) Authenticate to container
    d) Forward back to original page and let the container handle
    authorization since you have already authenticated.
    I use have encapsulated the database activity into 3 stored functions:
    1) isValidSession(session_id) - Returns null or the user id and pwd
    concatentated which will need split apart if needed
    2) makeSession(user_id, password) - Returns a new unique session id and
    creates the appropriate record
    3) cleanUpSessions() - Arguements not yet determined. This will delete
    any records older than a certain time. I would like to have the proc
    know what to delete without being given a parameter but time to the
    second level can be tricky for some DBMS's.
    There is a concern of storing the user id and password in the database
    but this can be eliminated with a good design to restrict access to the
    database table and using encrypted connections.
    Hope this helps. Hopefully - a similar philosphy will be adopted by an
    application container so I may not have to worry about this and I can go
    back programming business functionality.
    -Tim
    Joel Nylund wrote:
    Does anyone know of some good articles/publications or suggestions for
    implementing a single signon for multiple very secure internet sites
    in
    weblogic type environments.
    For example, bank1 has a internet site and bank 2 has an internetsite.
    Bank 2 has some cool features they want to offer bank1's customers.They
    agree but, bank1 wants to present bank2 as a tab or part of bank1site.
    IN order to do this there are lots of fun things, but the things Im
    interested in are how to authenticate between them and handletimeouts.
    >>>
    timeouts seem particularly tricky in that if I dont hit a page onbank2
    for a while, it could time out its session for the guy on bank1. Alsoif
    im in the bank2 section of the site, then bank1 could time me out as
    well.
    any ideas let me know.
    thanks
    Joel

  • Design Suggestions for Multiple DaqMX Task Streaming App?

    I'm working on a LabVIEW application in which I'm streaming high-speed data to disk from multiple PXI devices simultaneously.  Each device has its own DaqMX task, and all tasks stream to the same file.  The PXI device configuration (which devices are in the chassis, which slots they're in, and which channels to read from each device) is determined at runtime.
    Does anyone have a suggestion for a design model for this?  To make matters worse, I'd like to be able to specify a channel to monitor its data during the streaming.  I'm thinking the Producer-Consumer model is the basic approach, and I'm at the point where I have an array of DaqMX tasks, one for each device.  I could probably extend that array to be an array of clusters containing:
       1) DAQ Command (e.g. Initialize, Start, Stop, Acquire, etc)
       1) Task ID
       2) Control reference to 2-D array (where each DaqMX read can be stored)
       3) Array of channel names (to allow selection of channel to be monitored
    This could be passed as notifier data, to a data collection subVI, but the part I'm struggling with is finding the best way to run X number of tasks in parallel, where X is not known until runtime.
    Any suggestions would be appreciated.

    Thanks for the input.  With regards to the file format, the decision has been made by my superiors not to use TDMS - unfortunate, but NI hasn't provided the information to write a MatLab file reader, which is a requirement.  So, I've created a custom file format tailored to the needs of my application, but generic enough to be used for other apps. With it, I've been able to stream 8 channels at 800KHz (4 channels each from 2 PXI-6120s) without breaking a sweat.  However, the performance varies greatly depending on which slots the cards are in (but that's a whole different discussion - see the PXI forum for that one).  Once NI solves that one, I'll feel a lot more comfortable.
    I have already made reentrant subVIs that can perform a specific DAQ task.  The problem with a for loop is that the VI sits and wait for a start trigger, then acquires the streaming data.  I can't start the next VI because I'm in the first one.  I thought about creating a data collection VI, and this VI would start up to 6 other VIs in parallel, based on how many and which cards were present.  It's a bit messy, because each slot can contain one of two devices, so I'd need to check which type it was before calling it.  I'm thinking I'll have to create the task list and the references to the data in the main GUI loop, and then pass this using a notifier or queue to the data collection loop. 

  • Using SPSiteDataQuery for multiple Site Collections

    Hi All,
    I would like to query five contact lists on multiple site collections. I can query the lists using SPSiteDataQuery if they are within the same site collection, but I can not query the lists over multiple site collections.
    Is there a method like SPSiteDataQuery that I can use to query lists over multiple Site Collections?
    Many Thanks,
    Colin

    Hi,
    As you have mentioned that: SPSiteDataQuery which can query multiple webs within the same site collection, but not across multiple site collections. You can't accomplish that easily.
    The solution evolves from first using the SPSiteDataQuery class to run a query upon each site collection and then aggregating the results.
    For detailed information, refer to the following article:
    https://oidatsmyleg.wordpress.com/2009/08/13/cross-site-collection-query-almost/
    Besides, here is a similar requirement post, you can take a look at:
    http://sharepoint.stackexchange.com/questions/114329/accessing-list-data-in-multiple-site-collections
    Best Regards,
    Lisa Chen
    TechNet Community Support
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

  • CQ5 Multiple custom 404 error pages for multiple sites

    HI,
    I have multiple sites, and I would like to set up a different 404 page for each of my sites
    Someone already faced this problem? How I can accomplish this?
    Or there is a way to do via the dispatcher and create a static 404 error HTML page each time I publish a site?
    Thank You
    Adolfo

    Currently the most effective way to do what you're asking is to set up your 404.jsp to include the content of a site specific 404.
    There was a conversation about this here;
    http://dev.day.com/discussion-groups/content/lists/cq-google/2010-02/2010-02-11__day_commu nique_Sling_error_pages_zambak.html
    -jason

  • Creating Iweb seperate domains for multiple sites DIDNT WORK

    Hi! Any help would be much appreicaited!
    I am creating mutiple websites in iWeb 09'. All 3 of my websites have been stored under 1 domain file on my mac. I have read numerous discussion boards stating the steps of how to seperate each of the created sites from the one domain file, into mutiple domain files. I followed the steps on this website :
    http://lmsdiweb.wikispaces.com/Saving+Locally
    I moved the Domain folder out of its original location into a new folder on my harddrive entitled "Sites". Then i made sub folders within that folder and duplicated the domain 3 times and placed each copy in those folders. then i double clicked on the domain for my 1st site, opened iWeb, and then deleted the other sites i did not want on this new "domain" file i created and hit saved. This is exactly what the website said to do to create the seperate domain files for each seperate site. It then said repeat for each site, deleting the sites that are not needed on that domain.
    All of that being said, it didnt seem to work when i tried to open the 2nd copy of the domain. When iWeb opened after double clicking the 2nd domain copy, it did not open and show me all 3 sites as it should have, it opened to show me the one site that i just "saved" after deleting the other sites for the previous domain i was trying to create.
    I'm afraid i posisbly lost my other 2 sites. I backed up my first initial "domain" file which had all 3 sites within it on my external hard drive, and when i double clicked on that to make sure my sites weren't lost forever, same thing happened and only my lastest site that i saved on the 1st attempt to seperate domain files is visable on my iWeb.
    Did i loose everything i created in my other 2 sites? How do i get them back? What did i do wrong? Any help is much appreiciated as i have a feeling i might have made a serious mistake and need some help figuring this all out!
    Thank you!
    Also, I published all of my sites "to a folder" on my hard drive before doing this as well. Is there any way to take the published folder contents and put my site back on iweb for editing again?

    With three sites in a domain file here's how I would do it.  Create 3 copies of your domain file and name them for the three website, i.e "website1.sites, website 2.sites, etc.
    With the application discussed in the text below open website1.sites and delete website 2 and website 3 from it and save.  Open website 2.sites and delete 1 and 3.  Do the same for website 3.sites. 
    Then use the application mentioned below to open iWeb and select the website you want. 
    In Lion and Mountain Lion the Home/Library folder is now invisible. To make it permanently visible enter the following in the Terminal application window: chflags nohidden ~/Library and hit the Enter button - 10.7: Un-hide the User Library folder.
    To open your domain file in Lion or Mountain Lion or to switch between multiple domain files Cyclosaurus has provided us with the following script that you can make into an Applescript application with Script Editor. Open Script Editor, copy and paste the script below into Script Editor's window and save as an application.
    do shell script "/usr/bin/defaults write com.apple.iWeb iWebDefaultsDocumentPath -boolean no"delay 1
    tell application "iWeb" to activate
    You can download an already compiled version with this link: iWeb Switch Domain.
    Just launch the application, find and select the domain file in your Home/Library/Application Support/iWeb folder that you want to open and it will open with iWeb. It modifies the iWeb preference file each time it's launched so one can switch between domain files.
    WARNING: iWeb Switch Domain will overwrite an existing Domain.sites2 file if you select to create a new domain in the same folder.  So rename your domain files once they've been created to something other than the default name.
    NOTE:  iWeb 2 is not compatible with Mt. Lion and has trouble saving to the hard drive.  It's suggested you obtain iWeb 3
    OT

  • URL prefix under IIS for multiple sites

    I'm trying to set up DW8. I webmaster a large number of sites
    for clients using a variety of hosting companies and web servers. I
    use IIS under Win2K Pro.
    Pre-DW, my setup has been to have a test area with folders:
    Inetpub\wwwroot\site1, Inetpub\wwwroot\site2, etc. To test I browse
    to localhost/site1, localhost/site2, etc. Then I copy the files to
    another part of the disk: websites\site1, websites\site2, editing
    them to change directions to the include files (sometimes I work in
    ASP, sometimes in PHP). Even with a utility we've made special for
    this task, this is a ROYAL PAIN. Then I upload site1 to server1,
    site2 to server2, etc.
    I have to do it this way because IIS will only recognize one
    website at a time, and I jump around from site to site so often
    it's a real pain to turn the sites on & off via the Control
    Panel.
    Now I'm trying to set up site definitions on DW8. For Site1 I
    say the URL is www.site1.com, the local testing spot is
    Inetpub\wwwroot\site1, and it gives me this "site URL prefix for
    the testing server does not match the site URL prefix specified in
    the HTTP address". What do I do? What have you-all found is the
    easist approach:
    1. fool DW about where files are kept?
    2. Do the PITA switch between which site IIS thinks is
    "live"?
    3. host a local multi-site server?

    > I have to do it this way because IIS will only recognize
    one website at a
    > time
    Fix:
    http://mnteractive.com/archive/running-multiple-sites-on-win2k-and-xp/
    -Darrel

  • Can I use SRST for multiple sites wit separate 911 lines

    Is it possible to use an SRST (like a 2911 CME/SRST) to support multiple sites. 
    We have two sites next door to each other. They are connected by fiber with Cisco switches (vlans) at box sites.
    Can I use a single SRST and have two separate 911 POTS lines setup so that each site has it's own unique 911 associated with it?
    I can create two separate Voice vlans for the two sites and I could have both 29xx interfaces in use (one for each VLAN), but can I separate the dialing out function so that each vlan uses a unique POTS line this way?
    Any other solutions other than two SRSTs?

    We have to keep the 911 dialing the same at all sites since I already had an idea like that ...but we use 911, 9911 and 8911 for everyone to reach 911 so that they are not confused during an outage.
    We will just have to bite the bullet and order 2901 SRSTs for all our small remote sites. 

  • Site Search for Multiple Sites in 1 Account

    Is it possible to have multiple sites in 1 account with search results from selected pages?
    Eg, Site 1 only show Site 1 pages and Site 2 only show Site 2 pages in the results. When searching in Site 1, the results pull from all pages.
    Is there a way to selected certain pages for certain searches (without securing an entire site)?

    Hi Trina,
    That's not possible at this stage.
    -mario

  • Design question for database connection in multithreaded socket-server

    Dear community,
    I am programming a multithreaded socket server. The server creates a new thread for each connection.
    The threads and several objects witch are instanced by each thread have to access database-connectivity. Therefore I implemented factory class which administer database connection in a pool. At this point I have a design question.
    How should I access the connections from the threads? There are two options:
    a) Should I implement in my server class a new method like "getDatabaseConnection" which calls the factory class and returns a pooled connection to the database? In this case each object has to know the server-object and have to call this method in order to get a database connection. That could become very complex as I have to safe a instance of the server object in each object ...
    b) Should I develop a static method in my factory class so that each thread could get a database connection by calling the static method of the factory?
    Thank you very much for your answer!
    Kind regards,
    Dak
    Message was edited by:
    dakger

    So your suggestion is to use a static method from a
    central class. But those static-methods are not realy
    object oriented, are they?There's only one static method, and that's getInstance
    If I use singleton pattern, I only create one
    instance of the database pooling class in order to
    cionfigure it (driver, access data to database and so
    on). The threads use than a static method of this
    class to get database connection?They use a static method to get the pool instance, getConnection is not static.
    Kaj

Maybe you are looking for

  • If else logic in select statement

    Hi, Can someone kindly explain me how can i use if-else logic in the place of case statement in the below query. SELECT deptno, empno, ename, sal,              CASE                 WHEN deptno = 10                    THEN sal * 0.05                 W

  • My macbook air is generating a strong electrical current! HEALTH concerns!

    Hi everyone, I am using an American macbook air in Hong Kong, China. I have been living in Hong Kong for a while now, but only recently noticed this NEW problem (I have had at least 3-4 other problems that my computer had to be "hospitalized" for in

  • How do I get rid of 'Do you want to allow the following program..."?

    I have recently installed Windows 7 on a new computer and have also installed Dreamweaver MX. Whenever I open Dreamweaver, it comes up with an annoying message "Do you want to allow the following program to make changes to this computer?" My question

  • How are *Credit Card*--Cash Advances handled?

    How are *Credit Card*--Cash Advances handled? Can employees add that to their Expense report? Example: If the employee takes a $100 cash advance and reconciles the transaction in SAP Expense, we are expected to pay Credit Card Provider $100. However,

  • I chose not to renew my .Mac account

    I decided not to renew my .Mac account this year. There were two main reasons for this. Firstly I was very disappointed with the service; I was unable to receive my mail or to access my home computer during the time I was traveling last year in N and