What should we use instead of openldap-servers in Red Hat Enterprise Linux 8?

https://access.redhat.com/solutions/3816971

 SOLUTION 已验证 - 已更新 2019年四月1日16:39 - 

English 

环境

  • Red Hat Enterprise Linux 8

问题

  • The openldap-servers package was removed in RHEL8.
  • What should I use instead, Red Hat Directory Server or Identity Management?
  • How should I migrate my LDAP servers from RHEL7 to RHEL8 ?

决议

Overview

The openldap-servers package was removed in Red Hat Enterprise Linux 8. The openldap-clients package is still shipped though.

If you use openldap-servers in Red Hat Enterprise Linux 7 (RHEL7), you need to consider to change your LDAP server from OpenLDAP to Red Hat Directory Server (RHDS) in Red Hat Enterprise Linux 8 (RHEL8).

RHDS is provided as an add-on subscription in RHEL8, so you need buy the subscriptions in addition to RHEL subscription.

However, if you use your LDAP server as a Back-End DB of Identity Management like user management , you might be able to use Identity Management (IdM) which is included in Red Hat Enterprise Linux without buying RHDS.

What is Red Hat Directory Server?

Product Outline
◼LDAPv3 Compliant directory server
◼ Red Hat distributed and supported version of 389 DS project 
     Identity Management uses 389 DS as it’s foundation
◼ Flexible and extensible
    Schema and DIT can be extended at customer discretion
◼High performance
     Scales to globally distributed deployments
◼ Reliable and Robust
◼ Offered as a stand alone product
Solving Problems
◼General purpose replicated identity storage
◼A reliable storage for user accounts and other related data as a back end of a business application
◼High volume of read and authentication operations
◼Custom design of objects and data
◼Distributed and complex topologies with replication
    Allows read only replicas and replication policy
◼Drop-in replacement for existing costly 3rd party LDAP solutions
Use Cases
◼Best fit
    Back end for externally facing applications (usually large volume of data)
    Cases where a lot of customisation is required
◼Can be used:
    To manage identities inside the enterprise (but not recommended)
◼Not a good fit:
     Systems, policies, certificate, key management inside enterprise
Why is it not recommended outside best fit cases?
◼It will be too much effort to adapt RHDS to manage internal identities and related policies, customer would have to do a lot of integration work that is already done in IdM
◼Directory Server does not provide any systems, policies, certificate, and key management capabilities for inside the enterprise use case
◼Active Directory integration is very basic

What is Identity Management ?

Product Outline
◼IdM – Identity Management in Red Hat Enterprise Linux
◼Based on FreeIPA open source technology
◼IPA stands for Identity, Policy, Audit
     Focused on identities and related policies
    A separate project is ongoing in the audit space
◼Built into operating system - comes with RHEL subscription
Solving Problems
◼Central management of authentication and identities for Linux clients
    Improvement over standalone LDAP/Kerberos/NIS based solutions
    Simplify management of infrastructure
◼Gateway between the Red Hat Enterprise Linux and Active Directory.
    Supports Active Directory forest trusts (recommended)
    User and Password synchronization (not recommended)
Use Cases
◼Best fit
    Manage user population inside the enterprise
    Manage Linux/UNIX systems, policies and access
    Integrate with Active Directory
    As a replacement for existing LDAP solutions used for internal identities
◼Can be used
    As a back end for external facing applications (but not generally recommended)
    As a replacement for existing LDAP solutions used for external identities
◼Not a good fit (yet):Highly customizable back end is required
    Huge amount of data (hundreds of thousands of entries)
Why is it not recommended outside best fit cases?
◼It is better to have different policies for internal and external users thus it is better to store them in different places and federate using IdP like Red Hat SSO
◼IdM is focused on the specific set of attributes and objects tilted towards inside the enterprise use case; application might require completely new objects and attributes - high levels of customisation are not supported with IdM
◼IdM can scale to tens of thousands of users it is yet not good in handling hundreds of thousands or millions
◼IdM does not support read only replicas

Comparison

AreaRed Hat Directory ServerIdentity Management
UseGeneral purpose LDAP serverDomain controller for Linux/UNIX
ExtensibilityHighly customizablePreconfigured data and object model
InterfacesLDAP, command line tools, admin consoleRich CLI, JSON RPC API, Web UI
Schema & treeLDAPv3 compliant, tree design up to deploymentOptimized for domain controller use case
AuthenticationLDAPLDAP, Kerberos with SSO, Certificate based
AD integrationUser synchronizationAdvanced integration via cross forest trusts
ReplicationUp to 20 masters + unlimited read only replicas and hubsUp to 60 active masters
ScalabilityScales well beyond 100K objectsHas limitations beyond 100K objects

How to migrate from an LDAP Directory to IdM

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/linux_domain_identity_authentication_and_policy_guide/migrating_from_a_directory_server_to_ipa

Additional References

https://access.redhat.com/products/identity-management

https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/index.html

https://www.redhat.com/en/blog/preparing-identity-management-red-hat-enterprise-linux-8?source=author&term=27711

https://rhelblog.redhat.com/2015/06/01/identity-management-or-red-hat-directory-server-which-one-should-i-use/

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.4_release_notes/chap-red_hat_enterprise_linux-7.4_release_notes-deprecated_functionality

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8-beta/html/8.0_beta_release_notes/changes_to_packages#removed_packages

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值