ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    DC Demotion Question

    IT Discussion
    11
    108
    8.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tiagom @BRRABill
      last edited by

      @BRRABill Yup same boat. Solo it guy.

      1 Reply Last reply Reply Quote 0
      • T
        tiagom @scottalanmiller
        last edited by

        @scottalanmiller I agree that is a superior but i would still have issues with the other services.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @tiagom
          last edited by

          @tiagom said in DC Demotion Question:

          @scottalanmiller I agree that is a superior but i would still have issues with the other services.

          How crippling are those other services? Do they affect everyone, just a few people?

          1 Reply Last reply Reply Quote 0
          • T
            tiagom
            last edited by

            Varies on the service. But some of them can have engineers or our manufacturing floor at a stand still.

            BRRABillB 1 Reply Last reply Reply Quote 0
            • BRRABillB
              BRRABill @tiagom
              last edited by

              @tiagom said in DC Demotion Question:

              Varies on the service. But some of them can have engineers or our manufacturing floor at a stand still.

              Can't you replicate those services on other servers and leave AD singular?

              1 Reply Last reply Reply Quote 0
              • BRRABillB
                BRRABill
                last edited by

                @scottalanmiller

                Why isn't there an open source product that can replicate AD? That would solve all our problems!

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • T
                  tiagom
                  last edited by

                  The services authenticate against AD using LDAP.

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @BRRABill
                    last edited by

                    @BRRABill said in DC Demotion Question:

                    @scottalanmiller

                    Why isn't there an open source product that can replicate AD? That would solve all our problems!

                    There is. Samba4 functions as AD completely. LDAP will replicate it, like FreeIPA.

                    BRRABillB 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @tiagom
                      last edited by

                      @tiagom said in DC Demotion Question:

                      The services authenticate against AD using LDAP.

                      So you have double dependencies, if either AD or LDAP fails everything goes down?

                      1 Reply Last reply Reply Quote 0
                      • T
                        tiagom
                        last edited by

                        I happened to have spare licenses already in house, so it was the "simplest" solution.

                        1 Reply Last reply Reply Quote 0
                        • T
                          tiagom
                          last edited by

                          It is single dependency as i understand it. If AD goes down i cant use a LDAP query again it.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @tiagom
                            last edited by

                            @tiagom said in DC Demotion Question:

                            It is single dependency as i understand it. If AD goes down i cant use a LDAP query again it.

                            That's one dependency. But you depend on LDAP as well. What if LDAP goes down?

                            AD needs LDAP, LDAP needs AD. It's an "and" not an "or".

                            T 1 Reply Last reply Reply Quote 0
                            • BRRABillB
                              BRRABill @scottalanmiller
                              last edited by

                              @scottalanmiller said in DC Demotion Question:

                              @BRRABill said in DC Demotion Question:

                              @scottalanmiller

                              Why isn't there an open source product that can replicate AD? That would solve all our problems!

                              There is. Samba4 functions as AD completely. LDAP will replicate it, like FreeIPA.

                              Could one of those provide redundancy for AD in a 1 server scenario?

                              Save some licensing costs?

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • T
                                tiagom @scottalanmiller
                                last edited by

                                @scottalanmiller said in DC Demotion Question:

                                @tiagom said in DC Demotion Question:

                                It is single dependency as i understand it. If AD goes down i cant use a LDAP query again it.

                                That's one dependency. But you depend on LDAP as well. What if LDAP goes down?

                                AD needs LDAP, LDAP needs AD. It's an "and" not an "or".

                                Maybe im missing something but..

                                I have the service and AD(/DC). The service uses a ldap query's against AD.

                                If the service goes down well then we never get to authenticate. If AD goes down the service will still try to authenticate but fail.

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @BRRABill
                                  last edited by

                                  @BRRABill said in DC Demotion Question:

                                  @scottalanmiller said in DC Demotion Question:

                                  @BRRABill said in DC Demotion Question:

                                  @scottalanmiller

                                  Why isn't there an open source product that can replicate AD? That would solve all our problems!

                                  There is. Samba4 functions as AD completely. LDAP will replicate it, like FreeIPA.

                                  Could one of those provide redundancy for AD in a 1 server scenario?

                                  Save some licensing costs?

                                  Samba4 can, but doesn't do the LDAP portion that he needs.

                                  BRRABillB 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @tiagom
                                    last edited by

                                    @tiagom said in DC Demotion Question:

                                    @scottalanmiller said in DC Demotion Question:

                                    @tiagom said in DC Demotion Question:

                                    It is single dependency as i understand it. If AD goes down i cant use a LDAP query again it.

                                    That's one dependency. But you depend on LDAP as well. What if LDAP goes down?

                                    AD needs LDAP, LDAP needs AD. It's an "and" not an "or".

                                    Maybe im missing something but..

                                    I have the service and AD(/DC). The service uses a ldap query's against AD.

                                    If the service goes down well then we never get to authenticate. If AD goes down the service will still try to authenticate but fail.

                                    Oh, you are hitting AD directly, not talking to an LDAP server? Commonly for non-AD enabled services people use federation for AD to sync to LDAP and then they hit LDAP directly. Like with FreeIPA.

                                    T 1 Reply Last reply Reply Quote 0
                                    • T
                                      tiagom @scottalanmiller
                                      last edited by

                                      @scottalanmiller There's the disconnect.

                                      Yup hitting AD directly.

                                      I see interesting, i haven't been in that scenario. Is that the only way to do it, or just the most common?

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @tiagom
                                        last edited by

                                        @tiagom said in DC Demotion Question:

                                        @scottalanmiller There's the disconnect.

                                        Yup hitting AD directly.

                                        I see interesting, i haven't been in that scenario. Is that the only way to do it, or just the most common?

                                        Definitely not the only way, but I think it is more common. Many systems, like Linux boxes, talk to LDAP natively and it works really smoothly.

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          tiagom
                                          last edited by

                                          Cool, the services that i deal with all (luckily) talk to LDAP natively.

                                          1 Reply Last reply Reply Quote 0
                                          • BRRABillB
                                            BRRABill @scottalanmiller
                                            last edited by

                                            @scottalanmiller said in DC Demotion Question:

                                            @BRRABill said in DC Demotion Question:

                                            @scottalanmiller said in DC Demotion Question:

                                            @BRRABill said in DC Demotion Question:

                                            @scottalanmiller

                                            Why isn't there an open source product that can replicate AD? That would solve all our problems!

                                            There is. Samba4 functions as AD completely. LDAP will replicate it, like FreeIPA.

                                            Could one of those provide redundancy for AD in a 1 server scenario?

                                            Save some licensing costs?

                                            Samba4 can, but doesn't do the LDAP portion that he needs.

                                            In my scenario, thinking about going down to one AD ... could Samba work here for redundancy if the AD server goes down while I am away?

                                            scottalanmillerS 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 2 / 6
                                            • First post
                                              Last post