Re: Red Hat Directory Server

Tarjei Huse <[email protected]> Tue, 14 Jun 2005 18:31:39 +0200
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
On Wed, 2005-06-08 at 02:50 -0500, Manuel Amador wrote:
> El mar, 07-06-2005 a las 06:10 +0200, Dieter Kluenter escribió:
> 
> 
> > 
> > I do not agree with your statement. Defined standards are required for
> > interoperability reason and if there are stringend standards, one
> > should follow these standards when developing software.
> 
> But you get problems when there are several differing interpretations of
> the standard, which is exactly what happened here.  Had the standard
> said anything different, DA would have been developed using a different
> architecture, based on the assumption that a single entity in the
> directory cannot be of several structural object classes.  We use that
> "feature" or "bug" (depending on the flavor/interpretation of the day)
> to make maintaining an address book, and mail routing instructions, and
> several other things, as a single entity, thus lowering development
> efforts and (in addition) reducing the chance of bugs and "leftover
> crap" when deleting old users.
> 
> I agree with your statement, I do!  But I'm not so sure I agree with
> whatever the thought was that prompted you to cite your statement in
> this context.
> 
> > 
> > > 2. NDS always has had very mature administration tools, whereas with
> > > OpenLDAP you're practically stuck with the ldap command-line tools.
> > > That is simply unacceptable in a corporate environment.
> > 
> > Your are argueing based on outdated information. You can write to the
> > config and schema backends of OpenLDAP by means of ldif, thus any ldap
> > editor can be used to change configuration and add schemas at runtime.
> 
> ...which proves, again, my point.  An "LDAP editor" is definitely not
> the right choice for directory management in the enterprise level.  It
> may be a debugging utility, and an inspection helper, but definitely not
> an enterprise directory management tool.
I agree that what has been lacking is a more complete admin solution.
OpenLDAP has been and is a very good LDAPserver - but it is not a
complete enterprise management solution.

This isn't as much about the admintool as about the OSS community never
managing to get together a complete concept of how you should build your
network. The lack of this means that everyone finds their own solutions.
For example there are 10 - 30 different php solutions for administering
a samba-ldap configuration and very few does things the same way.

IMHO the best candidate to change this is gosa
(https://gosa.gonicus.de/) as it is backed by ideas and concepts for how
the network should be sett up, suggested configuration files and a
featureset that goes beyond the normal Samba/LDAP to handle kerberos,
Cyrus IMAPD and (soon ) CA management, DNS and DHCP management.

For those with money we'll always have Novel and RH. For us others Gosa
and projects like it provides an nice refuge :).

PS: If someone can point me to other projects simmilar to Gosa and in
active development I'll be happy to look at them. ISPMan springs to
mind.

Kind regards
Tarjei


> 
> When entering the business space, the technology no longer matters as
> much as what the client (in this case a directory manager, or a CTO, or
> whoever is in charge of authorizing a check for you) sees.  DA has
> fulfilled an important role in this space.
> 
> > 
> > -Dieter
> > 
-- 
Tarjei Huse <[email protected]>