The
Password Synchronization Agent (PWsynch) synchronizes password values
bi-directionally between any LDAP-V3 compliant directory server and
Windows directories, namely Windows 2000 Active Directory (AD) and NT
SAM (NT) Registry. Users accessing applications that use Sun Directory
Server, AD or NT for login authentication need only remember a single
password, and when applying periodic password updates, the user needs
to make the password update only once.
Password
Synchronization Agent (PWsynch) is made out of a set of components,
primarily individual Connectors that allow for the synchronization of
password updates between LDAP-V3 compliant directory servers and
Windows directories.
A
Password Synchronization Agent (PWsynch) Connector interfaces directly
with one or more directories/domains and is responsible for propagating
password PWsynch between directory/domain instances.
Password
Synchronization Agent (pwSynch) Connectors communicate with each other
over a secure and persistent transport protocol.
NOTE
: Password Synchronization Agent (PWsynch) is a Password
Synchronization Agent that provides bi-directional synchronization
between Microsoft Active Directory and any LDAP server.
How
Password Synchronization Agent (PWsynch) Works ?
Password Synchronization Agent (PWsynch) is a utility that synchronises
Microsoft Active Directory / NT (SAM) UserID's and passwords with any
LDAP-V3 compliant directory server. Password Synchronization Agent
(PWsynch) has 2 core components.
(WPsynch) Microsoft
active directory / NT-SAM to LDAP-V3 compliant directory server
synchronization library (DLL)
This
is a uni-directional synchronization library that would synchronize any
LDAP-V3 compliant directory server with microsoft active directory or
NT-SAM elements and attributes including the passwords.
Features
All
components support Secure Socket Layers (SSL)
Does
not depend on any meta directory product
Never
stores any passwords on the file system. All passwords are stored in
the memory as part of the synchronization process
Passwords
are encrypted in config files
Encrypted
Bind DN password store
Retry
intervals and maximum life can be set
System
Requirements
Windows
NT 4.0 SP6a (for Microsoft NT-SAM password synchronization)
Windows
2000 Advanced Server SP2 (for Mictosoft Active Directory password
synchronization)
(PWsynch) LDAP-V3
compliant directory server to microsoft active directory
synchronization plugin
This
is a uni-directional synchronization plugin that would synchronize
microsoft active directory with any LDAP-V3 compliant directory server
elements including the passwords.
This plugin is specific to
the verison of the LDAP server being used. We currently support the
following LDAP-V3 complitant directory servers
OpenLDAP
Sun
Java Enterprise Systems Directory Server (formerly known as SunONE / iPlanet )
Novell
eDirectory
Netscape
Directory Server (from AOL Enterprise
Systems)
For complete bi-directional synchronization; one
would need to implement both elements of this productbase.