20080605 ldap replication with oid - plembo/onemoretech GitHub Wiki

title: LDAP Replication with OID link: https://onemoretech.wordpress.com/2008/06/05/ldap-replication-with-oid/ author: lembobro description: post_id: 513 created: 2008/06/05 20:46:04 created_gmt: 2008/06/05 20:46:04 comment_status: open post_name: ldap-replication-with-oid status: publish post_type: post

LDAP Replication with OID

Some more liveblogging from Oracle University.

As I mentioned in my last post, I’m 4/5 of the way through Oracle’s “Directory Services: Administration” class. Right now I’m just completing the lab on setting up LDAP replication.

My initial impression is that the procedure involved was designed by a DBA rather than an LDAP systems person. That makes sense, because only database layer replication was originally available for OID. It’s only with the latest release that replication using the LDAP protocol became fully available.

Still, when compared to the more admin-friendly process used in the Netscape-family directories (iPlanet, Sun, Red Hat), it’s amazing that this passed user acceptance testing. To be fair, configuring OpenLDAP for replication isn’t much easier, although at least there all the system info is in slapd.conf so you don’t have to worry about bootstraping it into the directory database — for now (OpenLDAP also doesn’t offer multimaster replication as an option, which is its main shortcoming from an enterprise administrator’s point of view).

Of course, if the testers had no experience with the Netscape directory way of doing things, they wouldn’t know any better …

UPDATE: Since coming back from Oracle U., I’ve gone through the LDAP replication exercises again and then tried installing replication from scratch as part of a fresh install using by selecting the “High Availability” option during setup. While the process wasn’t quick, it was was much cleaner and reliable than the convoluted procedure required to manually set up LDAP replication. The bottom line is, if you’re thinking about building a multi-master or master-slave OID environment the best way to go is by first installing a standalone instance as your primary master and then selecting the H.A. option when building your secondary.

Copyright 2004-2019 Phil Lembo