RE: [PHP-GENERAL] LDAP

From: Date: Wed, 21 Jun 2000 20:51:28 +0000
Subject: RE: [PHP-GENERAL] LDAP
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-2532@lists.php.net to get a copy of this message
Big question :-) Try these URL's: http://www.data.com/issue/990207/ldap.html http://developer.netscape.com/viewsource/markey_ldap.html http://developer.netscape.com/docs/manuals/ldap/ldap.html http://idm.internet.com/foundation/ldap.shtml http://linuxworld.com/linuxworld/lw-1999-07/lw-07-ldap_1.html http://www.linuxworld.com/linuxworld/lw-1999-03/lw-03-uptime.html and of course: http://www.umich.edu/~dirsvcs/ldap/ Basically, almost every service you will deploy has a directory service. This may be the address book in Notes, Exchange, an NT domain, a Unix user/group database (/etc/passwd, NIS, etc), your web servers user and groups database, sendmail (usually uses the unix user database for it's "directory"), etc. All these things have some shared info - usernames, passwords, email addresses, etc. LDAP, amoung other things, is meant to be a standard directory service where you can store common info (like users, groups, devices, etc) in one place, one time and manage it there. Imagine if you could create one user, define a list of services they have access to, and set a few parameters, and the user now has email, dialup, unix logins, an NT account, etc. The services they can use are dependent on the data you put into their one entry, and common info is not duplicated in many places. By pulling out these proprietary directory services out of the application and having a shared, open directory service, it makes it easier to manage resources, and creates consistency between services (i.e. EVERY service has the same sense of what your email address is, and if you change your email or password, it changes it in ALL services). If you delete a user, you delete them everywhere (well, everywhere that's LDAP enabled) instead of having to remember to delete them from everything (and maybe forgeting some and leaving them with access they should not have)... Potentially, you can use a relational database (mysql, oracle, etc) for this, but they are very heavyweight by comparison. They have to balance taking lots of reads with lots of writes to handle high volumes of transactions, etc. LDAP is geared toward reading far more than writing (you may log into a system with your uid and password hundreds or thousands of times between changing it), and it is optimized for this. As a result, while relational databases tend to have a lot more functionality towards transaction processing, roll back, roll forward, etc, this is not required for LDAP. Technically, you can use a relational database to backend an LDAP server, but performance is typically much lower than if the backend database is specifically geared toward a hierarchical database. It is also optimized for replication and distributed databases, whereas making replicas in Oracle is much more challenging. -Jeff > -----Original Message----- > From: Chris Sano [mailto:sano@mail.rit.edu] > Sent: Wednesday, June 21, 2000 2:26 PM > To: PHP List > Subject: [PHP-GENERAL] LDAP > > > Can someone explain to me what the benefits of using LDAP > are? I'm reading > Professional PHP Programming and have reached the chapter on > LDAP and don't > understand how it is beneficial, or different than using alternate > programming options. > > Thanks in advance, > > Chris > > ___________________________ > got sano? (new design!) > http://www.rit.edu/~cms0670 > >

« previous php.general (#2532) next »