Presentation is loading. Please wait.

Presentation is loading. Please wait.

Virtual Directory Services and Directory Synchronization May 13 th, 2008 Bill Claycomb Computer Systems Analyst Infrastructure Computing Systems Department.

Similar presentations


Presentation on theme: "Virtual Directory Services and Directory Synchronization May 13 th, 2008 Bill Claycomb Computer Systems Analyst Infrastructure Computing Systems Department."— Presentation transcript:

1 Virtual Directory Services and Directory Synchronization May 13 th, 2008 Bill Claycomb Computer Systems Analyst Infrastructure Computing Systems Department Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL85000.

2 Introduction Challenges and Solutions Future work Questions Agenda

3 Introduction What are directory information services? –What data do they contain? –Who wants that data? –Why must it be protected? –How do we protect it? What are virtual directories? What is directory synchronization?

4 Directory Information Services Provide user data to applications –Web portals –Instant Messaging –Single-sign-on –Email May contain personally identifiable information Come in several different flavors –LDAP Active Directory SunOne –Databases SQL

5 Virtual Directories “Virtual” – the directory doesn’t actually exist Tailor data to specific needs Collect data from different data sources

6 Virtual Directory Server

7 Virtual Directories

8 Directory Synchronization Reflect data from one source to another Used for various purposes –Account provisioning –Application specific needs –Performance Improvement

9 Synchronization

10 Challenges Limiting the amount of data provided Limiting who has access to the data Providing data from one data source as another type of data source Provisioning accounts Combining data from disparate data sources Collecting data from remote data sources Keeping data up-to-date

11 Challenge: Limit the data provided Example: –An application which only requires name and email address Solution: –Configure a virtual directory to supply a subset of the total attributes available

12 Challenge: Limit who has access to the data Examples: –An external facing employee directory server –Data access restricted to U.S. Citizens i.e. Export Controlled Software Solution: –Use a virtual directory to reflect data from one environment to another –Use virtual directory authorization to specify access control

13 Challenge: Provide data from one source to another Example: –Technical Library needed information from an LDAP server –Information is only contained in a SQL database Solution: –Use a virtual directory to provide SQL information as LDAP information

14 Challenge: Account Provisioning Example: –Authorized account information is contained in multiple SQL databases –Accounts are stored in an LDAP directory Solution: –Use a virtual directory to create a complete view of account information –Use directory synchronization to provision new accounts according to that data

15 Challenge: Collect data from disparate data sources Example: –User information comes from both directories and databases Solution: –Use virtual directories to correlate and present data from multiple data sources

16 Challenge: Collect data from remote data sources Example: –Directory information from remote sites is needed for a local address book Solution: –Use directory synchronization to pull data from remote LDAP servers and populate it in a local LDAP store

17 Challenge: Keeping Data up-to-date Example: –External contact information, stored in a database, is needed in an LDAP directory Solution –Use directory synchronization to reflect database changes in the destination directory

18 Solution: Details Virtual Directory Services and Synchronization available on internal networks Can be ported to externally available sources Implemented by RadiantOne, from Radiant Logic, Inc.

19 Future Work Exploring additional security features Bringing additional data sources together

20 Questions


Download ppt "Virtual Directory Services and Directory Synchronization May 13 th, 2008 Bill Claycomb Computer Systems Analyst Infrastructure Computing Systems Department."

Similar presentations


Ads by Google