RE: [PHP-GENERAL] LDAP
| From: | Jeffrey Clowser | Date: | Wed, 21 Jun 2000 20:51:28 +0000 |
| Subject: | RE: [PHP-GENERAL] LDAP | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2532@lists.php.net to get a copy of this message | ||
Big question :-)
Try these URL's:
http://www.data.com/issue/990207/ldap.html
http://developer.netscape.com/viewsource/markey_ldap.html
http://developer.netscape.com/docs/manuals/ldap/ldap.html
http://idm.internet.com/foundation/ldap.shtml
http://linuxworld.com/linuxworld/lw-1999-07/lw-07-ldap_1.html
http://www.linuxworld.com/linuxworld/lw-1999-03/lw-03-uptime.html
and of course:
http://www.umich.edu/~dirsvcs/ldap/
Basically, almost every service you will deploy has a directory service.
This may be the address book in Notes, Exchange, an NT domain,
a Unix user/group database (/etc/passwd, NIS, etc), your web servers user
and groups database, sendmail (usually uses the unix user database for
it's "directory"), etc. All these things have some shared info -
usernames, passwords, email addresses, etc.
LDAP, amoung other things, is meant to be a standard directory service
where you can store common info (like users, groups, devices, etc) in
one place, one time and manage it there. Imagine if you could create
one user, define a list of services they have access to, and set a few
parameters, and the user now has email, dialup, unix logins, an NT
account, etc. The services they can use are dependent on the data you
put into their one entry, and common info is not duplicated in many
places. By pulling out these proprietary directory services out
of the application and having a shared, open directory service, it
makes it easier to manage resources, and creates consistency between
services (i.e. EVERY service has the same sense of what your email
address is, and if you change your email or password, it changes it
in ALL services). If you delete a user, you delete them everywhere
(well, everywhere that's LDAP enabled) instead of having to remember
to delete them from everything (and maybe forgeting some and leaving
them with access they should not have)...
Potentially, you can use a relational database (mysql, oracle, etc)
for this, but they are very heavyweight by comparison. They have
to balance taking lots of reads with lots of writes to handle high
volumes of transactions, etc. LDAP is geared toward reading far
more than writing (you may log into a system with your uid and password
hundreds or thousands of times between changing it), and it is
optimized for this. As a result, while relational databases tend to
have a lot more functionality towards transaction processing, roll
back, roll forward, etc, this is not required for LDAP. Technically,
you can use a relational database to backend an LDAP server, but
performance is typically much lower than if the backend database
is specifically geared toward a hierarchical database. It is also
optimized for replication and distributed databases, whereas making
replicas in Oracle is much more challenging.
-Jeff
> -----Original Message-----
> From: Chris Sano [mailto:sano@mail.rit.edu]
> Sent: Wednesday, June 21, 2000 2:26 PM
> To: PHP List
> Subject: [PHP-GENERAL] LDAP
>
>
> Can someone explain to me what the benefits of using LDAP
> are? I'm reading
> Professional PHP Programming and have reached the chapter on
> LDAP and don't
> understand how it is beneficial, or different than using alternate
> programming options.
>
> Thanks in advance,
>
> Chris
>
> ___________________________
> got sano? (new design!)
> http://www.rit.edu/~cms0670
>
>