Author Topic: PDC, BDC. login users questions.  (Read 2606 times)

txsastre

  • Zen Monk
  • **
  • Posts: 75
  • Karma: +4/-0
    • View Profile
PDC, BDC. login users questions.
« on: September 28, 2011, 11:59:12 am »
hi all

I'm doing some tests and I've installed 2 Zentyal servers, one of them is LDAP domain primary controller and the other one is an slave of it.


I've tested the slave and I can see the users and grups, so I guess its working properly.


The question is. When I stop the PDC, users can not be validated through the slave ... Is this normal?



Thank you.

christian

  • Guest
Re: PDC, BDC. login users questions.
« Reply #1 on: September 28, 2011, 12:21:09 pm »
1 - LDAP is not the PCD (neither BDC  ;) ) but authentication back-end. What may be seen as PDC or BDC is Samba if configured this way. Trust me it's not nitpicking but just to be sure we discuss same concept.

2 - for what I understand from current LDAP implementation, although multiple LDAP servers are running, the main one (master) is always required because others are "only" adding specific schema and attributes on top of the master. This is not, as you may think, a full replica with failover capability. At least this is my understanding. Let's Zentyal team react on this  and explain in case I'm wrong ;)

txsastre

  • Zen Monk
  • **
  • Posts: 75
  • Karma: +4/-0
    • View Profile
Re: PDC, BDC. login users questions.
« Reply #2 on: September 28, 2011, 01:22:47 pm »
Thanks for your answer.

I wanted that to work because my idea is to have a slave in our remote departments. It's a way to have the user unificated, and if the connection is broken, a way to them to still can login in the system and use (for exemple) the files stored in the slave server.


christian

  • Guest
Re: PDC, BDC. login users questions.
« Reply #3 on: September 28, 2011, 01:38:59 pm »
I do share your goal but it looks like it doesn't work like this with Zentyal  ::)

txsastre

  • Zen Monk
  • **
  • Posts: 75
  • Karma: +4/-0
    • View Profile
Re: PDC, BDC. login users questions.
« Reply #4 on: September 28, 2011, 02:09:42 pm »
so i've found this manual about samba
https://help.ubuntu.com/10.04/serverguide/C/samba-dc.html

and as I can see in BDC, it should be possible :/

"Backup Domain Controller
With a Primary Domain Controller (PDC) on the network it is best to have a Backup Domain Controller (BDC) as well. This will allow clients to authenticate in case the PDC becomes unavailable."


christian

  • Guest
Re: PDC, BDC. login users questions.
« Reply #5 on: September 28, 2011, 02:19:37 pm »
hum... what you don't understand is that issue is not because of Samba but because of LDAP design choice.
Again you mix-up LDAP and Samba acting has domain controller or relying on fail-over back-end for authentication, unless I'm the one misunderstanding your point.