Operating System - HP-UX
1834148 Members
1980 Online
110064 Solutions
New Discussion

Re: UNIX to AD - LDAP migration experiences?

 
Don Mallory
Trusted Contributor

UNIX to AD - LDAP migration experiences?

Hi everyone,

I'm looking to find what other people's experiences migrating to LDAP and Kerberos authentication in a Windows Active Directory from NIS or a similar tool.

We have a number of HP-UX and Linux servers that are managed using an account management system that works much like NIS, but is not.

What I'm wondering is:

What sort of experiences have people had?
What sort of timeline for migration was required?
Were there any show-stoppers or large challenges that required special solutions?
What sort of performance and latency issues did you come across?
Were there any big surprises along the way?
Which version of HP-UX or Linux were you running?
Active Directory 2000 or 2003?
Automouter or AutoFS?
Do you use centralized NFS file servers and automount or local home directories?
How did you manage the auto.* files that AD cannot provide (but NIS does)?
Access control for specific nodes?
Amount of additional network traffic?
Did you use SSL?

I've worked with LDAP-UX 3.30 and I'm starting to play around with 4.0. I have an idea what sort of trouble I'm up against, but I'd like to hear what challenges other people may have come up against. I haven't started working with the OpenLDAP clients at all yet.

I also wanted to add, that I have had excellent support from the Internet & Security Solutions support team at HP. They have been phenomenal.

Thanks in advance,
Don
2 REPLIES 2
support_5
Super Advisor

Re: UNIX to AD - LDAP migration experiences?

Hi,

Isn't anyone going to answer these questions? Surely this has been done heaps of times? What are peoples experiences with LDAP integration?

Thanks

- Andy
Don Mallory
Trusted Contributor

Re: UNIX to AD - LDAP migration experiences?

I am still interested in this.

I will be deploying this live into our environment within the next 4 weeks, so any feedback would be greatly appreciated.

Thanks,
Don