2.3 Understanding DSfW in Relation to Active Directory

eDirectory: Novell eDirectory organizes objects in a tree structure, beginning with the top Tree object, which bears the tree's name. Whether your eDirectory servers are running Linux, UNIX, or Windows all resources can be kept in the same tree. You don’t need to access a specific server or domain to create objects, grant rights, change passwords, or manage applications. The hierarchical structure of the tree gives you great management flexibility and power. For more information on trees, refer to “Understanding Novell eDirectory“ in the Novell eDirectory Administration Guide.

In eDirectory, the master replica is a writable replica type used to initiate changes to an object or partition The master replica is responsible for maintaining all replica and schema epochs. If a replication or schema problem needs to be corrected, the operation is performed from the master replica. If the directory has been partitioned into a number of replicas, a master replica is required on each server .

Active Directory: Active Directory is a hierarchical multilevel framework of objects. It provides information on the objects, organizes them, controls access to them and sets security. The logical divisions of an Active Directory network consist of forests, trees, and domains.

The Active Directory security model is based on shared secrets. The domain controller contains all users’ keys. The authentication mechanism is based on Kerberos, NTLM, smart cards, Digest, etc.

For more information on Active Directory forests, refer to the Active Directory Tutorial

2.3.1 Additional Features of Active Directory

  • Within an Active Directory topology, distinct roles are defined, but these roles are not fixed. Any role can be moved to another server at any time. For more information about these roles, see Flexible Single Master Operation (FSMO) Roles in the OES 2 SP3: Domain Services for Windows Administration Guide.

  • In Active Directory, Flexible Single Master Operation (FSMO) roles ensure directory integrity by policing specific operations that belong only on a single-server directory service. For example, FSMO roles enable Active Directory to avoid the simultaneous creation of new domains with identical names or the creation of concurrent schema extensions using the same attribute with a different underlying syntax.

  • In Active Directory, the Primary Domain Controller Emulator FSMO role has two primary functions. It provides backward compatibility for Windows NT4 domains and for servers, and it acts as an accelerator for certain account management functions. For example, password changes and account lockouts are passed to the PDC Emulator FSMO role and then quickly replicated throughout a domain infrastructure.

  • In a Microsoft environment, time synchronization is important primarily for maintaining Kerberos authentication. Time synchronization is not vital to the functioning of the primary domain controller.