Project

General

Profile

action #81292

[sle][migration][SLE15SP3] multi machine check setup for ldap migration

Added by coolgw 11 months ago. Updated 11 months ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
Spike/Research
Target version:
-
Start date:
2020-12-23
Due date:
% Done:

100%

Estimated time:
35.00 h
Difficulty:

Description

base following PR we need also prepare multi machine setup for migration
https://github.com/os-autoinst/os-autoinst-distri-opensuse/pull/10947

History

#1 Updated by coolgw 11 months ago

  • Priority changed from Normal to High

#2 Updated by coolgw 11 months ago

Also we need consider following multimachine scenairo, means three machine setup: one for 12sp5, one for 15sp3, one for ldap server.
on 12sp5 we do ldap configration and test, export configuration to 15sp3 machine do upgrade tools and do test with ldap server
detail info can refer following link(NOTE: this ticket focus on build multi setup, not for the whole ldap test):
https://jira.suse.com/browse/SLE-11501

Configure a base system with 12sp5 OR 15sp2
Configure OpenLDAP with HA/TLS/Schema, do LDAP functional test
Create the slapd.d conf and database.ldif exports on the machine.
Configure a seperate machine with 15sp3
On the 15sp3 machine, install 389-ds
Import the slapd.d conf and database.ldif from the openldap machine to the 15sp3 machine
Run openldap_to_ds
Do functional tests

#3 Updated by coolgw 11 months ago

  • Estimated time changed from 25.00 h to 35.00 h

coolgw wrote:

base following PR we need also prepare multi machine setup for migration
https://github.com/os-autoinst/os-autoinst-distri-opensuse/pull/10947

Output of this ticket:
Run a test case with sambe_adcli check before/after migration.(With above multi machine setup)

#4 Updated by tinawang123 11 months ago

  • Assignee set to tinawang123

#5 Updated by tinawang123 11 months ago

Checked some information:
LDAP 是一种协议,标准
Active Directory 是一种实现了LDAP标准的产品
同类的产品还有如OpenLdap等ldap产品
Active Directory
Active Directory是指Windows 2000网络中的目录服务。它有两个作用:1.目录服务功能。 Active Directory提供了一系列集中组织 管理和访问网络资源的目录服务功能。Active Directory使网络拓扑和协议对用户变得透明,从而使网络上的用户可以访问任何资源(例如打印机),而无需知道该资源的位置以及它是如何连接到网络的。
Active Directory被划分成区域进行管理,这使其可以存储大量的对象。基于这种结构,Active Directory可以随着企业的成长而进行扩展。从仅拥有一台存储几百个对象的服务器的小型企业,扩展为拥有上千台存储数百万个对象的服务器的大型企业。
2.集中式管理。
Active Directory还可以集中管理对网络资源的访问,并允许用户只登陆一次就能访问在Active Directory上的所有资源。
Active Directory是一个基于 Windows 环境中提供身份验证,目录,策略和其他服务的数据库系统
LDAP是目录数据的协议规范。
Active Directory是基于LDAP的目录服务器的微软实现。
Active Directory不仅仅是微软的一个实现,它只是广告的一小部分。 Active Directory是( 以一种过于简化的方式) 提供基于Kerberos授权的基于LDAP的身份验证的服务。
Active directory是一个目录服务提供程序,可以将新用户添加到目录中,删除或者修改,指定 privilages,指定策略 等等,就像每个人都有唯一的联系人号码一样。 AD(Active Directory) 中的每一个东西都被视为对象,每个对象都有一个惟一的标识。( 类似于电话簿中的唯一联系人号) 。
Ldap是专门为目录服务提供商设计的协议。 Windows Server 操作系统使用AD作为目录服务器,AIX是一个UNIX版本,它使用了 Tivoli directory server 。 它们都使用LDAP协议与目录交互。
除了协议之外,还有LDAP服务器,LDAP浏览器。

#6 Updated by tinawang123 11 months ago

  • Status changed from New to In Progress
  • % Done changed from 0 to 20

#7 Updated by tinawang123 11 months ago

  • % Done changed from 20 to 30

#8 Updated by tinawang123 11 months ago

before and after migration for samba:
https://openqa.suse.de/tests/5270856

#9 Updated by tinawang123 11 months ago

  • Status changed from In Progress to Resolved
  • % Done changed from 30 to 100

As samba can check AD information before and after migration
Refer: https://openqa.suse.de/tests/5270856#step/samba_adcli_check/12
Close this ticket

Also available in: Atom PDF