Setting Up eDirectory

The Novell eDirectoryTM system requires a DirXML driver to be installed and configured on each tree for which you will synchronize data. In Installing the Novell DirXML Starter Pack, you should have installed the first DirXML driver for eDirectory. You will configure that driver later in this chapter.

This section explains how to install and configure the second DirXML driver for eDirectory.

To set up synchronization for the second eDirectory tree, complete each of the following sections:


Prerequisites


Collecting Configuration Information

You'll need to provide a number of system-specific details when you install and configure the DirXML driver for eDirectory. Some of these details can be collected before you complete the following procedures, and others will be defined during the process.

During the configuration process, you will need to provide the container names for placement of synchronized objects. For more information about eDirectory placement options, see Default Driver Settings for eDirectory.


Required Driver Configuration Information for eDirectory

IMPORTANT:  The data you supply during configuration is used to build DirXML rules. Often, case is significant to a rule. Mirror case when entering the requested data.

System Value

 

Remote Tree Address and Port
IP address and port for Tree 1

 

Remote Base Container
Base container for Tree 1

If this container does not exist, you must create it before starting the driver.

 

Base Container
Base Container for groups in Tree 2

(If you choose the Flat placement option, you need two base containers: one for users and one for groups. For more information about placement options, see Default Driver Settings for eDirectory.)

 

Figure 16
eDirectory Configuration Form


 eDirectory Configuration Form (continued)


Installing DirXML and the DirXML Driver for eDirectory on Tree 1

  1. At the server for your first tree, insert the DirXML CD into the CD drive. Run the installation program.

  2. Read the license agreement; if you agree to the terms, click I Accept.

  3. On the Components page, select the following items, then click Next.

  4. In the Schema Extension page, specify the following:

  5. Select the DirXML Driver for eDirectory, then click Next.

  6. Select the driver configuration (XML files) for eDirectory, then click Next.

  7. Read the Summary page, then click Finish.

    The file copy might take a few minutes.

  8. After the installation completes and displays the Installation Complete dialog box, click Close.

  9. Continue with the next section, Configuring the DirXML Driver for eDirectory.


Configuring the DirXML Driver for eDirectory

This section explains how to configure the eDirectory driver for the first tree. Configuring the eDirectory driver for the second tree, along with the drivers for Active Directory and NT, is explained in Configuring the DirXML Drivers.

  1. From your administrative workstation, launch iManager by going to http://serveripaddress/nps/iManager.html.

    IMPORTANT:  This URL is case sensitive.

  2. Authenticate to the first tree.

  3. Click DirXML Management > Create Driver.

  4. Mark In a New Driver Set, then click Next.

  5. Specify a driver set name, browse to the context where you want the driver set object to be created, then browse to the server object representing the server where you installed DirXML.

  6. Leave Create a New Partition checked, then click Next.

  7. Mark Import a Preconfigured Driver from the Server, select eDir-Driver.xml, then click Next.

  8. Using the configuration information you collected earlier, fill in the prompts for information required by the driver.

  9. Click Define Security Equivalence, add Admin, then click OK.

    Drivers need rights to read and update data in eDirectory. Assigning a security equivalent is a quick way to provide necessary rights assignments. This option does not provide access to data in the other eDirectory tree.

  10. Click Exclude Administrative Roles, add Admin, click OK, then click Next.

    These objects will not be replicated to the other eDirectory tree. We recommend that you add all objects that represent an administrative role (for example, the Admin object) to this list. These objects typically have no function outside of the directory tree that they were created in. Maintaining these objects in only one directory prevents potentially disruptive changes, such as access control or password changes, from causing problems.

  11. Click Finish with Overview.

  12. The eDirectory driver for Tree 1 is prepared to synchronize data. Complete preparation of other participating systems, then proceed to Configuring the DirXML Drivers.