LDAP-UX Client Services B.04.00 with Microsoft Windows 2000/2003 Active Directory Administrator's Guide

Installing LDAP-UX Client Services
Planning Your Installation
Chapter 216
How will user and group data be migrated into your directory?
The migration scripts provided with LDAP-UX Client Services for
Active Directory migrate all user and group data to the “Users”
container.
If you merge your data into an existing directory, for example, to
share user names and passwords with other applications, the
migration scripts can create LDIF files of your user data, but you
must write your own scripts or use other tools to merge the data into
your directory. PosixAccount attributes can be added to your users
already in the directory to leverage your existing directory data.
For information about importing information into the directory, refer
to “Importing Name Service Data into Your Directory” on page 32.
For information on migration scripts, refer to “Command, Tool, and
Migration Script Reference” on page 153.
CAUTION If a root login is placed in the Active Directory, that user and
password will be able to log in as root to any client using LDAP-UX
Client Services. It is recommended that you keep the root user in
/etc/passwd on each client system so the root user can be managed
locally, and to allow local access to the system. It is not recommended
to put the same users both in /etc/passwd and in the directory, as
this could cause conflicts and unexpected behavior.
How many profiles do you need?
If you use ADS multiple domains, refer to Chapter 3, “Active
Directory Multiple Domains,” on page 59 for more information about
configuring remote domains.
If ADS multiple domains are not used, refer to the following
information.
A configuration profile is a directory entry that contains
configuration information shared by a group of clients. The profile
contains the information clients need to access user and group data
in the directory. For example, this information includes:
Your directory server hosts.
Where your supported name service data is in the directory.
Other configuration parameters such as search time limits.