Author :Lakshmi Shankar Source: IBM DW China
Overview of AIX 5L? Operating System V5.3 TL5 Update Lightweight Directory Access Protocol (Lightweight Directory Access Protocol, LDAP) related enhancements. These enhancements include support for Active Directory, multiple base distinguished name (DN) support,, and an extended base DN format.
Introduction For the AIX 5L? operating system , based on Lightweight Directory Access Protocol (LDAP) user management is getting more and more attention. Typically & # xff0c; clients can use LDAP or LDAP with Kerberos for their authentication and user management needs. LDAP provides a centralized mechanism for maintaining system configuration and policy information. This enables clients to configure and manage multiple systems using only one set of user-identified configuration information, and simplifies system administration. The AIX 5L LDAP client supports centralized administration of administrative databases of user, group, and network information for various systems. Terminology In this article,we will use the following terms and definitions:
Table 1. Terms
Term description
Active Directory service Microsoft?
AIX 5L V5.3 TL 05 AIX 5L Service Release Technology Level 05
LDAP Lightweight Directory Access Protocol , an open standard for user security repository and authentication mechanism
/>SFU Microsoft’s Services For UNIX? software module , which provides Active Directory configuration in a manner close to an RFC 2307-compliant LDAP server. Overview of AIX 5L LDAP User Management This section describes the AIX 5L operating system V5. 3 LDAP user management features prior to TL5 update. All features are described in detail in the following documents : AIX? document “Configuring an AIX Client System for User Authentication and Management through LDAP” white paper, and Integrating AIX 5L into Heterogeneous LDAP Environments IBM Redbook ( ;See the Resources section). The AIX operating system was one of the first operating systems to introduce LDAP-based user management in the 1990s. After Request for Comment (RFC) 2307 became the standard way to maintain user or group information & # xff0c; various operating systems needed to provide a more standardized way for directory support. AIX 5L LDAP-based user management adapted for RFC 2307 compliance & # xff0c; Allows clients to manage AIX 5L systems as well as RFC 2307 compliant systems for other platform types. Some important parts of AIX 5L’s LDAP-based user management include : support for the full set of AIX 5L user and group attributes
When selecting the AIX 5L operating system platform as the LDAP server( and the AIX 5L media included LDAP software )time,AIX 5L operating system supports more attributes than RFC 2307, and provides additional control functions for user login. The AIX 5L operating system provides complete password and login controls. (Some attributes are specific to AIX 5L,It is described in the AIX 5L Version 5.3 Security Guide. See the Resources section. )
The AIX 5L operating system supports the following databases in its LDAP implementation : information specified by RFC 2307 and other user or group information
Advanced Statistical Configuration Tables
With AIX 5L Seamless Integration of User Management Commands and Tools
The same set of commands and System Management Tool (SMIT) interface that customers are familiar with can be used to complete LDAP-related management tasks. The AIX 5L operating system provides corresponding interfaces to include LDAP, to provide simple configuration for LDAP clients and servers.
AIX 5L operating system also provides some tools,for migrating configuration information from local files to LDAP database. Support autoload
AIX 5L operating system provides users with autoload function, so that users can use the network file system (NFS) to create their own home directory. Multiple Server Configuration and Failover Capabilities
The AIX 5L operating system can be configured to use multiple LDAP servers to retrieve configuration information,and these servers can be prioritized,so that,& xff0c; provides redundant protection for LDAP server information. If the primary LDAP server fails,then the AIX 5L operating system will automatically fail over to another server.
Supported LDAP servers AIX 5L LDAP user management can be implemented by configuring the AIX 5L server as a client of the LDAP server,. AIX 5L LDAP-based user and group management supports the following types of directory servers:
Transfer: https://blog.51cto.com/508239/153695