Step 7: Begin Synchronization

Sync New Windows Users. When enabled, all user entries found in Windows that are subject to the agreement will automatically be created in the Directory Server.

Sync New Windows Groups. When enabled, all group entries found in Windows that are subject to the agreement will automatically be created in the Directory Server.

8.The Windows and Directory Server subtree information is automatically filled in; use the defaults to sync only users or change these as appropriate to sync groups or groups and users.

9.Check the Using encrypted SSL connection checkbox. The use of SSL is recommended for security reasons, and SSL is required for synchronizing passwords because Active Directory will refuse to modify passwords unless the connection is SSL-protected.

10.Fill in the authentication information in the Bind as... and Password fields with the sync ID information. This user must be on both the Active Directory server and will be one of the supplier DNs available in the database replication setup, as described in Section 2.5, “Step 5: Configure the Directory Server Database for Synchronization”.

11.The last screen is a summary of the synchronization agreement. It is possible to modify all of the configuration at this using the back buttons to get to the appropriate screen. If the agreement is correct, click Done.

When the agreement is complete, an icon representing the synchronization agreement is displayed under the suffix. This icon indicates that the synchronization agreement is set up.

2.7. Step 7: Begin Synchronization

After the sync agreement is created, begin the synchronization process. Select the sync agreement, right-click or open the Object menu, and select Begin resynchronization. This will begin the synchronization process.

If synchronization stops for any reason, begin another total update (resynchronization) by selecting this from the sync agreement menu. Beginning a total update (resynchronization) will not delete or overwrite the databases.

3. Using Windows Sync

After the sync agreement is setup, synchronize the user and group entries on the Directory Server and Active Directory server.

Section 3.1, “Synchronizing Users”

Section 3.2, “Synchronizing Groups”

Section 3.3, “Deleting Entries”

527

Page 547
Image 547
HP UX Red Hat Direry Server Software manual Using Windows Sync, Begin Synchronization