Figure 4-14 Using the l attribute to represent different countries

4.5.2 Directory tree for an ISP

Internet service providers (ISPs) may support multiple enterprises with their directories. ISP should consider each of the customers as a unique enterprise and design their directory trees accordingly. For security reasons, each account should be provided a unique directory tree with a unique suffix and an independent security policy.

An ISP should consider assigning each customer a separate database and storing these databases on separate servers. Placing each directory tree in its own database allows data to be backed up and restored for each directory tree without affecting the other customers.

In addition, partitioning helps reduce performance problems caused by disk contention and reduces the number of accounts potentially affected by a disk outage.

Figure 4-15 Directory tree for example ISP

4.6 Other directory tree resources

See the following for more information about designing the directory tree:

RFC 2247: Using Domains in LDAP/X.500 Distinguished Names

RFC 2253: LDAPv3, UTF-8 String Representation of Distinguished Names

4.6 Other directory tree resources

57