HP UX LDAP-UX Integration Software manual Security Comparison Between LDAP-UX and NIS+

Page 12

Overview of NIS+ to LDAP Migration

Comparing Features and Security Between LDAP-UX and NIS+

access the database. The LDAP server provides global account and password policies to LDAP-enabled clients and applications. There are some feature differences between LDAP and NIS+.

Table 1-1 compares features between LDAP and NIS+:

Table 1-1

Features Comparison between LDAP and NIS+

 

 

 

 

 

 

 

Feature

NIS+

 

LDAP

 

 

 

 

 

 

hierarchical data

yes

 

yes

 

 

 

 

 

 

dynamic updates

yes

 

yes

 

 

 

 

 

 

dynamic replication

yes

 

yes

 

 

 

 

 

 

access control list

yes

 

yes

 

 

 

 

 

 

complex data

no

 

yes

 

 

 

 

 

 

multiple master replication

no

 

yes

 

 

 

 

 

 

trusted system mode on

yes

 

a

 

HP-UX

 

 

 

 

 

 

 

 

 

account/password policies

yes

 

yes

 

 

 

 

 

a.LDAP-UX Client Services version B.03.30 or later supports coexistence with Trusted Mode.

Security Comparison Between LDAP-UX and NIS+

This section describes the security comparison between NIS+ and LDAP as follows:

NIS+ uses SecureRPC with Diffie-Hellman authentication. This mechanism uses public/private key pairs which are 192-bits long. It is an old mechanism which has been shown to be compromised easily.

With the LDAP-UX product, the HP-UX operating system can use an LDAP directory for centralized security policy enforcement, authentication and authorization. LDAP-UX supports simple and SASL Digest-MD5 for user and proxy authentication. SSL is also supported for secured communication between an LDAP client and the directory server. With SSL support, the LDAP-UX Client provides a more secure way to protect the password over the network. SSL is a more robust scheme than SecureRPC.

6

Chapter 1

Image 12
Contents Editon Manufacturing Part Number J4269-90054 E0606Legal Notices Contents Glossary Index Intended Audience Publishing HistoryCommand and Tool Reference Use this chapter to What’s in This documentHP Encourages Your Comments Overview of NIS+ to Ldap Migration Overview Documentation References Ldap Directory Server and LDAP-UX Client Services Overview of the LDAP-UX Integration ProductComparing Features and Security Between LDAP-UX and NIS+ Feature Comparison Between Ldap and NIS+Features Comparison between Ldap and NIS+ Security Comparison Between LDAP-UX and NIS+Security Coexisting with Trusted Mode Security Comparison between LDAP-UX and NIS+ NIS+ withTrusted Mode Comparing Ldap and NIS+ Information SharingSimplified NIS+ Environment How LDAP-UX Client Services Work Simplified LDAP-UX Client Services EnvironmentComparing Ldap and NIS+ Information Sharing LDAP-UX Client Administrator’s Tools Migration Scripts Ldap Administrator ‘s Tools DescriptionNIS+ to Ldap Migration Tools Description NIS+ to Ldap Migration Tools Tool DescriptionOverview of NIS+ to Ldap Migration Migrating NIS+ to Ldap Before You BeginBefore You Begin Migrating NIS+ Service Data to the Ldap Server Summary of Migration StepsStep Migrating NIS+ Clients to LDAP-UX Client Services Installing and Configuring Your Ldap Directory Server Installing Netscape Directory ServerConfiguring Netscape Directory Server Installing the LDAP-UX Integration Product Installing ONC EP/NCF Software and AutoFS 2.3 Patch ONC EP/NCF Software RequirementSeptember AutoFS Patch Requirement Chapter Publickey and Automount Schemas Publickey SchemaAutomount Schema Following shows the new automount schema in the Ldif formatImporting Your NIS+ Data to Your Ldap Directory Server Steps to Import Your NIS+ Data into Your Directory Server and placed into a Ldif formatted file Importing Your NIS+ Data to Your Ldap Directory Server Migrateallnisplusonline.sh Enter the manager DN Configuring LDAP-UX Client Services Automount files ldap Configure the LDAP-UX Client Services, see the Configure Configuring LDAP-UX Client Services Verify LDAP-UX Client Services Ll /tmp Ls -l Verify LDAP-UX Client Services Chapter Ldappasswd Command SyntaxLdap Directory Tools ExamplesLdapentry Ldapscope SyntaxExamples NIS+ to Ldap Migration Scripts Ldapsearch Ldapmodify LdapdeleteMigrates groups Migrates all user Environment Variables General Syntax For Migration ScriptsDefault Naming Context Naming ContextNIS+ Map Name Location in the Directory Tree Migrating The Credential Table NisMapName=mapname Non-standard mapaMigrating Most of Service Data Using One Script Migrating Individual Service Data Migrating User-Defined Maps NIS+ to Ldap Migration Scripts NIS+ to Ldap Migration Scripts Following shows the nispautomap.ldif file NIS+ to Ldap Migration Scripts Chapter Glossary Ldap Data Interchange Format LdifNetwork Information Service Plus NIS+ Glossary Symbols Index
Related manuals
Manual 214 pages 54.35 Kb Manual 26 pages 60.39 Kb