Museum

Home

Lab Overview

Retrotechnology Articles

Online Manuals

⇒

Media Vault

Software Library

Restoration Projects

Artifacts Sought

Installing and Configuring the Synchronization Service

When you install a directory server under NT, you are given the option of installing an NT synchronization service. The NT Directory Synchronization service allows you to synchronize the entries in your Windows NT directory with your directory server entries. NT users, NT groups, and passwords can be synchronized. As entries are created, modified, or deleted in one directory, the synchronization service makes the corresponding change to the other directory.

You can use the synchronization service with a Netscape Directory Server for Unix. To do this, you must install the synchronization service on an NT machine that is either a Primary Domain Controller (PDC) or a Backup Domain Controller (BDC). The synchronization service can only be run on an NT Primary Domain Controller. You can, however, (but not run) the service on an NT Backup Domain Controller. This allows you to have the service ready to use in the event that your Primary Domain Controller fails.

This chapter contains information about:

  • "Installing the Synchronization Service"

  • "Configuring the Synchronization Service"

  • "Configuring the Directory Server for NT Synchronization"

  • "Starting and Stopping the NT Synchronization Service"

 

Installing the Synchronization Service

To install the synchronization service, do the following:

  1. While not required, you are strongly recommended to use SSL with the synchronization service. Therefore, your first step should be to create a certificate database for use by the synchronization service. The easiest way to do this is to simply use the certificate database that you created when you set up SSL for your directory server. If your directory server is running on the same machine as your synchronization service, then you can just point the synchronization service at that same database. Otherwise, copy the directory server's certificate database to the same machine as the synchronization service is running.
  2. For information on setting up SSL and certificate databases for the directory server, see the Directory Server Administrator's Guide.

  3. Log in to an NT account with administrator privileges.
  4. Run the D30EIU2.EXE installation program. This launches the directory server installation program. You can find this file in the ntx86 directory on the directory server product CD.
  5. When you are asked to select the installation option, make sure the synchronization service is selected (checked). If you also select the directory server, the synchronization service is installed first.
  6. When prompted, you must accept the license agreement (the text of which is in license.txt) in order to proceed.

If you currently have any Netscape Server SuiteSpot 3.x products installed, the installation program places the synchronization service in the Netscape Server root directory. If you do not have any Netscape 3.x Server products currently installed, the installation program prompts you for a location where you wish to install the service.

Once the synchronization service is installed, the Synchronization Service Configuration Tool is launched. To successful synchronize your NT entries with the Netscape Directory Server, you must:

  • use the configuration tool to configure your synchronization service

  • go to your directory server manager and turn on the synchronization service plug-ins

The following sections describe the activities in detail. To learn more about the Netscape NT Synchronization Service, see the Netscape Directory Server Administrator's Guide.

 

Configuring the Synchronization Service

You use the synchronization service configuration tool to configure your synchronization service. This tool is described in the Netscape Directory Server Administrator's Guide, and in the help system available through the configuration tool. You must configure the following information in order to successfully start synchronization:

  1. In the Service Settings tab, enter:
  • The port number on your local NT system that the configuration tool uses to communicate with the synchronization service. Enter a unique port number in this field. The default port number is 5007. The port number can be any number between 1 and 65535 that is not in use by other TCP/IP applications.

  • The location of the synchronization service event log file. This logfile is used by the synchronization service to record significant events and problems. Each time a user or group is added, deleted, modified, or renamed in the NT domain, the synchronization servicerecords the event to this file.

  • Whether you want to use SSL for synchronization. You are strongly recommended to use SSL for synchronization because the synchronization service is transmitting user passwords to the directory server.

  • The location of the certificate database file. This field is required if you are using SSL. If you have a certificate database that you created for your Netscape Directory Server, then it is sufficient to reference that database in this field (the database must be on a local disk, so you may have to physically copy the directory server's certificate database to this primary domain controller). For information on how to create certificate database files for use with directory server clients, see the Netscape Directory Server Administrator's Guide.

  • In the Directory Server Settings tab, identify:
    • The directory server with which you will be synchronizing NT users and groups.

    • The port that the directory server is using for LDAP communications. If the synchronization service is using SSL (recommended) then the default is 636. Otherwise, it is 389.

    • The distinguished name and password that the synchronization service should use to bind to the directory server. This DN can either be the Root DN (cn=Directory Manager), or it can be a distinguished name that has full read, write, search, and compare privileges to the directory server subtree containing the NTUser entries (for example, uid=admin, o=airius.com). You are strongly recommended to avoid using the Root DN for normal bind operations such as this.

    • The directory base. This is the directory subtree where the synchronization service will create, modify, and delete entries. For example, ou=NTPeople, o=airius.com.

    • The directory tree in which you want to enforce uniqueness in the UID. SuiteSpot requires that all person entries in the directory have a unique UID attribute. Most SuiteSpot servers are configured to enforce this uniqueness in the entire directory tree (that is, from the directory suffix down). If SuiteSpot servers are managing users in other areas of the directory tree than the area in which the synchronization service is managing, then you should enter your directory suffix here. Otherwise, simply enter the same DN as you entered for directory base.

    • The TCP/IP port number which the Directory Server is using for non-SSL communications. Default is 5009.

  • If you are supporting NT-to-directory synchronization go to the Synchronization Schedule tab and examine the schedule configured there. Directory-to-NT synchronization is not affected by this schedule; that form of synchronization occurs over the non-LDAP port immediately upon a relevant change being made to the directory.
  • If you are supporting NT-to-directory synchronization, optionally go the Account Details tab and configure:
    • whether the synchronization service will create UID or CN-based distinguished names (UID is recommended and the default)

    • whether the synchronization service will create Netscape Messaging Server mail accounts, and if so how the email addresses will be generated by the synchronization service.

     

    Configuring the Directory Server for NT Synchronization

    Before you can use the Netscape NT Synchronization Service, you must configure your directory server for use with the synchronization service. To do this, you must:

    1. Configure your directory server to use SSL communications. See "Managing SSL" in the Netscape Directory Server Administrator's Guide.
    2. Configure the directory server to use the synchronization service plug-ins and synchronization service port number. You do this from the Server Preferences|Network form. For more information, see "Managing Network Settings" in the Netscape Directory Server Administrator's Guide.

     

    Starting and Stopping the NT Synchronization Service

    To start the synchronization service, go to the Status tab in the configuration tool and click Start.

    If you have installed the service on a Backup Domain Controller, you cannot start the service. In this case, you must change the service's startup state from Automatic to Disabled. Otherwise the service will attempt to start whenever you reboot your NT system. You change your service's startup state using the NT Services control panel.


    Copyright 1997 Netscape Communications Corporation. All rights reserved.

    Typewritten Software • bear@typewritten.org • Edmonds, WA 98026