10 OES 11 SP2: Novell Domain Services for Windows Security Guide
2.2.1 eDirectory Partitions
ApartitionineDirectoryisalogicalgroupofobjectsinaneDirectorytree.Partitioningallowsyouto
managethetreebytakingpartofthedirectoryfromoneserverandputtingitonanotherserver.If
youhavesloworunreliableWANlinksorifyourdirectoryhassomany
objectsthattheserveris
overwhelmedandaccessisslow,youshouldconsiderpartitioningthedirectory.
Eachdirectorypartitionconsistsofasetofcontainerobjects,alltheobjectscontainedinthem,and
dataaboutthoseobjects.eDirectorypartitionsdon’tincludeanyinformationaboutthefilesystemor
itsdirectories
andfiles.Partitionsarenamedbytheirtopmostcontainer.
Foracompletediscussionofpartitions,seeManagingPartitionsandReplicas(http://www.netiq.com/
documentation/edir88/edir88/data/a2iiiik.html).
2.2.2 DSfW Domains
AdomaininDSfWisasecurityboundarythatissimilartoapartitionineDirectory.Thedomainalso
formstheadministrativeandsecurityboundaryforalogicalgroupofnetworkresourcessuchas
usersorcomputers.Typically,adomainresidesinalocalizedgeographiclocation;however,this
mightnotalways
bethecase.Domainsarecommonlyusedtodivideglobalareasofanorganization
anditsfunctionalunits.
2.3 Understanding DSfW in Relation to Active Directory
eDirectory:eDirectoryorganizesobjectsinatreestructure,beginningwiththetopTreeobject,which
bearsthetreeʹsname.WhetheryoureDirectoryserversarerunningLinux,UNIX,orWindowsall
resourcescanbekeptinthesametree.Youdon’tneedtoaccessaspecificserverordomaintocreate
objects,grantrights,changepasswords,ormanageapplications.Thehierarchicalstructure ofthetree
givesyougreatmanagementflexibilityandpower.Formoreinformationontrees,referto
“UnderstandingeDirectory“(https://www.netiq.com/documentation/edir88/edir88/?page=/
documentation/edir88/edir88/data/fbadjaeh.html)inthe.NetIQeDirectory8.8AdministrationGuide
(https://www.netiq.com/documentation/edir88/edir88/data/front.html)
IneDirectory,themasterreplicaisawritablereplica
typeusedtoinitiatechangestoanobjector
partitionThemasterreplicaisresponsibleformaintainingallreplicaandschemaepochs.Ifa
replicationorschemaproblemneedstobecorrected,theoperationisperformedfromthemaster
replica.Ifthedirectoryhasbeenpartitionedintoanumberofreplicas,
amasterreplicaisrequiredon
eachserver.
ActiveDirectory:ActiveDirectoryisahierarchicalmultilevelframeworkofobjects.Itprovides
informationontheobjects,organizesthem,controlsaccesstothemandsetssecurity.Thelogical
divisionsofanActiveDirectorynetworkconsistofforests,trees,anddomains.
Domain:In
ActiveDirectory,adomainisasecurityboundarythatissimilartoapartitionin
eDirectory.EachActiveDirectorydomainthatisconfiguredtoactasaGlobalCatalogstoresa
fullcopyofallActiveDirectoryobjectsinthehostdomainandapartialcopyofallobjectsfor
all
otherdomainsintheforest.
Forest:AforestisacollectionofActiveDirectorydomainsand iscomparabletoatreein
eDirectory
TrustRelationships:Youcan setuptrustrelationshipstoshareresourcesbetweendomains.
Federationcanbeaccomplishedthroughestablishingcross‐domainandcross‐foresttrusts.