S 2.237 Planning of partitioning and replication in Novell eDirectory

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator, Head of IT

As a scalable directory service, eDirectory offers the ability to divide parts of the directory database into partitions and to distribute them across different eDirectory servers. This reduces the average access times, since the search will only span a special partition and not the entire directory tree under some circumstances. In addition, partitioning increases the reliability, since only the partitions located on the server will be affected and not the entire directory database if one server fails. Furthermore, partitioning allows distribution of the data according to a previously performed classification scheme among correspondingly secure servers.

When planning the partitions, it is necessary to take into consideration the partition rules defined by the eDirectory.

Planning eDirectory partitioning
Figure: Planning eDirectory partitioning

In turn, partitions may contain sub-partitions, which were created according to the rules specified. Partitions can be used to either perform different operations, e.g. generating, merging, moving, or cancelling one of the mentioned operations.

In addition to the mechanism of partitioning the directory tree, eDirectory also offers the ability to replicate parts of the directory tree on other eDirectory servers. In the terminology of eDirectory this is referred to as replicas. Each partition contains a so-called master replica. These form the centre of the respective partition. The creation of new sub-partitions or new replicas of the current partition depends on the availability of the master replica server. There are different options for replicating the directory data to other servers:

The types of replicas described above are set up and configured manually. The replication itself is automatic. Another type of replication includes the subordinate reference replicas. However, these are created and administrated by the eDirectory system itself. They only contain branch addresses, so as to be able to efficiently resolve object names across partition borders (so-called tree walking).

When planning the partitions, the following aspects should be taken into consideration:

The following items must be taken into consideration when planning the replicas:

Review questions: