Bring on the replication The year of Replication in Samba4 Sysadmin Miniconf – Linux.conf.au 2010 Andrew Bartlett Samba Team Cisco Systems.

Slides:



Advertisements
Similar presentations
What’s New in Windows Server 2008 AD?
Advertisements

Security and Policy Enforcement Mark Gibson Dave Northey
Who I am Computing and Communications NDC Systems Management Stanford University Addison-Wesley Windows Enterprise Admin Nebula Admin Windows Enterprise.
Colorado State University’s Active Directory Environment Presented by the ACNS Windows Group Windows Administrators Advisory Group Meeting Feb
Module 1: Installing Active Directory Domain Services
31/10/2000NT Domain - AD Migration - JLab 2000 NT DOMAIN - ACTIVE DIRECTORY MIGRATION Michel Jouvin LAL Orsay
Overview of Active Directory Domain Services Lesson 1.
Chapter 11: Directory Services. Directory Services A directory service is a database that contains information about all objects on the network. Directory.
Exploring Directory Services. Need for DS Multiple servers, multiple services in single network –Multiple servers for reliability, security, optimizing.
Using Skype For Business
Part I.  NOS  Directory Data Store(directory service, database)  Located on Domain Controllers (DCs), globally distributed, replicated (no longer PDCs/BDCs)
Module 9: Active Directory Domain Services. Overview Describe new features in AD DS List manageability and reliability enhancements in AD DS.
Deploying Chromebooks RICK NICHOLAS A.
Julien “Superman” Stroheker and Nicolas “Batman” Georgeault Negotium
Windows 2000 Operating System -- Active Directory Service COSC 516 Yuan YAO 08/29/2000.
Totally Automated Security (TAS) Mark Nichols Louisiana Department of Education (LDOE) March 6, 2007.
Active Directory Operations Masters. Overview  Active Directory updates generally multimaster Changes can be made on any DC  Some exceptions — single.
Module 11: Read-Only Domain Controllers. Overview Describe the Read-Only Domain Controllers role Use Read-Only Domain Controllers.
NETWORK OPERATING SYSTEM INTEROPERABILITY Jason Looney EKU, Department of Technology, CEN.
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Samba – Good Just Keeps Getting Better The new and not so new features available in Samba, and how they benefit your organization. Copyright 2002 © Dustin.
Terminal Services Technical Overview Olav Tvedt TVEDT.info Microsoft Speaker Community
Module 1: Implementing Active Directory ® Domain Services.
SkyDrive Pro Personal Timeline Editable and automatically color coded by project Important tasks Tasks you’ve marked as top of mind.
11 UPGRADING AND MIGRATING TO WINDOWS SERVER 2003 Chapter 12.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
Microsoft ® Lync™ Server 2010 Setup and Deployment Module 04 Microsoft Corporation.
Log Shipping, Mirroring, Replication and Clustering Which should I use? That depends on a few questions we must ask the user. We will go over these questions.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
 What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Demo.
Redmond Protocols Plugfest 2016 Randy Dong AD Family and BYOD Protocol Test Suite Updates Software Engineer.
Microsoft Exam
Samba4 towards a release An update on Samba as a AD DC.
-Active Directory is the brain of the Microsoft windows Server Network. -It’s a database that keeps track of huge amount of stuffs and gives us a centralized.
Samba4. What is Samba4? ● A replacement for Active Directory ● The centre of a windows domain: – Windows domain logon server – Windows-compatible LDAP.
Creative Commons Share Alike Attribution 3.0 Active Directory on ARM Running an Embedded Active Directory Domain Controller on the BeagleBoard.
Planning for Application Recovery
Stress Free Deployments with Octopus Deploy
Managing Windows Server 2012
Samba and the road to 100,000 users
Constructing Deploying and Maintaining Enterprise Systems
Shared Services with Spotfire
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
O365 & AZURE ADDS Mladen Baranek, Miadria
AAD Connect, AD-FS and you
Microsoft - Managing Office 365 Identities and Requirements
Upgrade, upgrade, upgrade! Say goodbye to clean installs of Windows 10
Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro.
Overview of Active Directory Domain Services
Active Directory and Group Policy
Active Directory Replication (Part 2) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
4th Forum How to easily offer your application as a self-service template by using OpenShift and GitLab-CI 4th Forum Alberto.
MCSA VCE
Essentials of UrbanCode Deploy v6.1
Unit 3 NT1330 Client-Server Networking II Date: 1/6/2016
Dev-Staging-Prod Environment Guidelines
CIS 409 Competitive Success/snaptutorial.com
CIS 409 Education for Service-- snaptutorial.com.
CIS 409 RANK Lessons in Excellence-- cis409rank.com.
CIS 409 Teaching Effectively-- snaptutorial.com
X in [Integration, Delivery, Deployment]
Local AD, Azure AD, & Google Suite User Management
Network Administration
What’s changed in the Shibboleth 1.2 Origin
SharePoint Online Hybrid – Configure Outbound Search
M7: New Features for Office 365 Identity Management
Introduction to VSTS Database Professional
Office 365 – How NOT to do it UKNOF43.
Microsoft 365 Business Technical Fundamentals Series
Presentation transcript:

Bring on the replication The year of Replication in Samba4 Sysadmin Miniconf – Linux.conf.au 2010 Andrew Bartlett Samba Team Cisco Systems

abartlet ● A Samba developer for 9 years now ● One of the lead developers on Samba4 ● I work for Cisco Systems – Full time on Samba4 – But these are my views, not theirs ● Please ask questions during the talk

Samba4 ● Provides AD-compatible Domain Controller ● Now also a replication Partner!

Replication ● Replication of user and group data – Data in the Directory – Not Group Policy data – Between Domain Controllers ● Replication of Passwords

Why Replication? ● Making Samba safe(er) to deploy ● Who wants a single point of failure?

Before ● Samba4 was suitable for: – Greenfield sites – Sites with only one domain controller – Sites willing to cut and run

The risks of cut and run ● Process: – Vampire AD domain – Shut down AD domain – Start up Samba4 – Hope everything still works ● There was no way back – As soon as Samba starts, the DB may change – No way to replicate changes back

Now ● As of alpha11 ● Benefits: – Samba4 is (more) suitable for sites with existing domains – Samba4 can be disabled, without loss of data ● Risks – Incorrect data written will be propagated across the enterprise

But didn't we already have replication? ● LDAP replication isn't really good enough ● We really need replication with Windows – And not just by using LDAP or DirSync ● The LDAP protocol does not have transactions – Nor do our current backend servers – We want both replication and transactions

DRS Replication ● The native replication with Windows ● Supported in both directions ● Supported from both initiators – Samba's provision – Windows 'dcpromo from scratch' ● NOT supported with the LDAP backend

Read Only Domain Controller ● Our next priority ● Allows safe incremental deployment ● Suitable for insecure branch offices – So a buggy Samba can't be any more malicious :-) ● This reduces the 'pollution' risk – No need to validate updates if there are none

Remaining risks ● Access Control – We have not fully locked down our LDB stack – Certain controls allow bypass of ACLs ● Samba4 may mislead it's clients – Group policy files not sync'ed yet ● Disasters in the Samba4 code ● AD servers don't validate inbound replications

Remaining tasks ● Admin tools ● Multi-domain forests ● Role management ● DNS ● And the DRS TODO list.

Interoperable DC versions ● Tested with – Windows 2008 R2 – Windows 2008 – Windows 2003

Production sites ● Secret Russian production site ● And a few others – Less intense use – Little feedback

Testing sites ● Little interest out of last year's Sysadmin Miniconf ● Have you eliminated all your windows clients? ● What are we not doing right?

Can I have version 1.0? ● No ● We will not 'release' Samba4 just to get the testing we need – Samba4 is unlikely to suit you if you can't pull from GIT to fix the problems you report

Demo Time!