Active Directory Considerations

The driver can run in several security modes. The major factors to consider are authentication, encryption, and use of the DirXML Remote Loader. If you are using the Remote Loader you must consider security settings on the Remote Loader channel between DirXML and the driver plus the settings between the driver and Active Directory. If you have Windows 2000 SP3 or later, you'll want to consider a security option called signing.

A simple prescription for managing security is not possible because the security profile available from Windows 2000 varies with service pack, DNS server infrastructure, domain policy, and local policy settings on the Windows 2000 servers. Security choices for the DirXML driver for Active Directory are covered in the following sections. Various combinations of these choices are discussed in Recommended Security Configurations in the Implementation Guide for the Active Directory driver.


Security Parameters

You can set the following parameters during installation or later, in the Driver Parameters page. Understanding how the parameters work together and work with the operating system will help you define your approach to security for DirXML data synchronization.


Authentication Options

The three authentication methods used by the driver are listed below. If you have installed a different security package into the Microsoft Security Service Provider Interface (SSPI) infrastructure, you will have additional options.



  Previous Page: NetWare Considerations  Next Page: Installing the Novell DirXML Starter Pack