Richard Megginson wrote:
Howard Wilkinson wrote:This may be terminology, AD is a collection of services running on the Domain Controllers. One of these services is replication which processes the transfer of strictly LDAP based information. By the time replication gets the data therefore the password has been hashed (I am relatively sure about this). The password change hook is called on the domain controller that accepted the password change prior to the hash is applied - YES??? Again I think I have this right! Therefore whichever DC gets to take part in the password change is going to need the passsync service. I am looking for someone to definitively confirm or deny this premise as I need to push this service out to multiple controllers and include it in new builds. Got that, hence my concern with placement of the passsync serviceand propagated to other DC's so it is then useless to the Passsync code. The hook therefore needs to be on the DC that receives the password change, which can be any DC in the environment....FDS must get the clear text password in order to perform its own hashing which is different from the way AD does hashing. But if I have 2 FDS servers running in multi-master and they both have synchronisation agreements with a single DC will they fight each other, and can they fight the DC's - deletes are the obvious problem. The ideal topology would have each of a multi-master set of FDS talking to more than one DC each allowing any system to fail and the services carrying providing up to date functionality.This gets a little tricky. In general, AD <-> FDS sync is a simple synchronization protocol, not a full blown multi-master replication protocol as FDS to FDS or AD to AD. FDS cannot be a full replication peer with AD. However, samba4 is getting closer and closer . . . Samba4 is something I would love to have but it looks a long way off as far as a replacement for what we have today... :-( Another thing about multi-master FDS's is which FDS should a DC talk to for its passsync updates? Ideally each DC would pick a different FDS or more than one if the first failed. .... Fault tolerance is fun... -- --
|
-- Fedora-directory-users mailing list Fedora-directory-users@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-directory-users