S 2.409 Planning of partitioning and replication in the directory service

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Head of IT, Administrator

A scalable directory service offers you the ability to divide parts of the directory database into partitions and distribute them across different directory service servers. This reduces the average access time, since search queries will only span a special partition and not the entire directory tree under certain circumstances. In addition, partitioning increases the reliability, since only the partitions located on the server will be affected and not the entire directory database if one server fails. Furthermore, partitioning allows distribution of the data according to a previously performed classification scheme among correspondingly secure servers.

When planning the partitions, it is necessary to take the partition rules defined by the directory service into account. In turn, partitions can contain sub-partitions, which need to be created according to the rules specified.

In addition to the mechanism of partitioning the directory tree, directory services also offer you the ability to replicate parts of the directory tree on other directory service servers. In directory service terminology, the replicated areas are referred to as replicas or reproductions. When planning a replication mechanism, it is especially necessary to perform an analysis of the network traffic to be expected in order to determine the bandwidth requirements for the communication connections or to design the topology of the replicas based on prescribed network parameters.

When planning the partitions, the following aspects should be taken into consideration:

The following points must be taken into account when planning replication:

The exact contexts of the servers containing partitions or replications must be taken into account. If the structure is too flat, then it will be necessary to expend greater effort internally for replication. Furthermore, individual servers not available at a given time will result in corresponding status messages on all other directory service servers contained in this replication.

Review questions: