LDAP - password policy + prod/dev architecture

From: Beck, Joseph (jbeck@seic.com)
Date: Tue Feb 05 2008 - 11:15:17 EST


We recently introduced native LDAP as a naming service in our latest
batch of development server builds.

I'm looking for a good reference book, manual, site in terms of
operational tasks. For example, the default password policy has quickly
become an issue for a few users. I need to better understand if/how to
implement a password policy at the LDAP level or if this is strictly
done at the system level (via /etc/default/passwd or pam.conf or ?).

A few other areas I need to research are roles, profiles, jumpstart,
etc. & understand how much flexibility there is...for example, can I
manage home directory (+profile) based on hostname or do they all need
to be the same?

Also, one architectural question, do companies typically have separate
LDAP infrastructures? One for development environment & one for
production? I'm thinking there has to be a design that would allow for 1
centralized LDAP instance which would then replicate a subset of that
data to other LDAPs.

Thanks,

Joe Beck Ciber Inc. - a consultant to SEI One Freedom Valley Drive/ 100
Cider Mill Road| Oaks, PA 19456 | p: 610.676.2258 | jbeck@seic.com
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:42:45 EDT