您好,欢迎访问三七文档
ActiveDirectoryLecture3ActiveDirectoryDefinitionsADisMicrosoft’sconsolidationofthemajorenterprise-widedirectoryserviceswithinasingle,replicabledatastoreandadministrativeinterfaceADisanetwork-basedobjectstoreandservicethatlocatesandmanagesresources,andmakestheseresourcesavailabletoauthorizedusersandgroups.The2componentsofADaretheDataStoreandtheADServicesthatactonthatdataADAdvantagesProvidescentralizedlogonandauthenticationpointforuserstoaccessresourcesAfocalpointforcentralizedadministrationandmanagementAsearchablestoreforinfoabouteverynetworkobjectanditsattributesStandard-basedstructuresandinterfacesallowforproductinteroperabilityandcompatibilitywith3rdpartyproductsScalable(virtuallynolimitonnumberofobjects)NewFeaturesRestartcapabilityRead-onlyDomainControllerAuditingimprovementsMultiplePassword/AccountLockoutPoliciesinaDomainADLightweightDirectoryServicesRoleDNSDNSisanInternetstandardservicethattranslateseasilyreadablehostnames,suchasmycomputer.microsoft.com,tonumericIPaddresses.DomainnamesforDNSarebasedonthehierarchicalnamingstructure(invertedtreestructure):asinglerootdomain,underneathwhichcanbeparentandchilddomains(branchesandleaves).EachcomputerinaDNSdomainisuniquelyidentifiedbyitsDNSfullyqualifieddomainname(FQDN),e.g.server1.ifsm.umbc.eduDynamicDNS–newerstandard,requiredforADADandDNSintegration•ActiveDirectoryandDNShavethesamehierarchicalstructure.•AllADnamesfollowDNSconventions•DNSrecords(zones)canbestoredinActiveDirectory.•ActiveDirectoryclientsuseDNStolocatedomaincontrollers.ADOrganizationAnunderlyingprincipleoftheADisthateverythingisconsideredandobject–people,servers,workstations,printers,etc.EachobjectalsohascertainattributesObjectclassesaredefinitionsoftheobjecttypesthatcanbecreatedintheAD.ControllingObjectAccessEveryobjecthasanACLthatcontainsinformationaboutwhohasaccesstoitandwhattheycandowithit.ControllingaccesstotheobjectinADisnotthesameasaccesstotheobjectitself.ADpermissionsonlyspecifywhetherauser,grouporcomputercanviewormodifyanobject’spropertiesinAD.AccesscanbesetupforindividualobjectpropertiesSchemaAsetofobjectdefinitions(objectclasses)andtheirassociatedattributesProvidesinfoonwhatobjectsandattributesareavailabletotheDirectoryAllowsadministratorstomodifyandaddnewobjectclasses,objectsandattributesasneeded,makingtheschemaextensibleBecauseofthisflexibility,ADiscapableofbeingthesinglepointofadministrationforallpublishedresources(files,peripheraldevices,hostconnections,databases,Webaccess,users)ADOrganizationADobjectsareorganizedaroundahierarchicaldomainmodelthatallowsscalabilityandexpandabilityDomainmodelbuildingblocksare:-domains-domaintrees-forests-organizationunitsNameSpaceADisbasedontheconceptofanamespace,thatisanameisusedtoresolvethelocationofanobjectADdomainnamescorrespondtoDNSdomainnamesEachobjecthasdifferentwaystorefertoit,andeachnamepinpointsthelocationofobjectinADDomainLogicalpartitioncomprisedofusers,computersandnetworkresourcesthatshareacommonlogicalsecurityboundaryandutilizeacommonnamespace(e.g.ifsm.umbc.edu)Domainscanbearrangedintoahierarchicalparent-childstructureAlldomainsmaintaintheirownsecuritypoliciesandsecurityrelationshipswithotherdomainsRequiresatleast1DomainController(whereADdatabaseisstored)Ifmorethan1DC(recommended)–theyusemulti-masterreplicationTrustsLogicalconnectionsbetweendomainstoallowusersfromonedomaintoaccessresourcesinanotherdomainCanbeone-ortwo-wayCanbetransitive,intransitiveorexplicitTrustterminology:TrustingtrustsTrustedDomainTrustedDomain(Users)TrustingDomain(Resources)TransitiveTrustsAtransitivetrustisatrustbetweentwodomainsinthesamedomaintree/forestthatcanextendbeyondthesetwodomainstoothertrusteddomainswithinthesamedomaintree/forest.Atransitivetrustisalwaysa2-waytrust-bothof.thedomainstrusteachother.Bydefault,allWindowsServer2008trustswithinadomaintree/forestaretransitivetrusts.DomainADomainBDomainCDomainTreeConsistsofhierarchyofdomainssharingacommonschema,securitytrustrelationship,andaGlobalCatalogFormedthroughtheexpansionofchilddomains,andthere’sonerootdomain(thefirstcreateddomain)DefinedbyacommonandcontiguousnamespaceDomainTreeExampleMarketing.toysrus.comToysrus.comSales.toysrus.comny.marketing.toysrus.comDomainForestsDomaintreeswithdifferentnamespacesconnectedbytrustrelationshipsAlltreeswithintheforestshareaGlobalCatalog,configurationandschema.Simplyareferencepointbetweentreesanddoesn’thaveitsownname.DomainForestExampleMarketing.toysrus.comtoysrus.comSales.toysrus.comNy.marketing.toysrus.comHR.Babiesrus.comBabiesrus.comSales.babiesrus.comNy.sales.babiesrus.comOrganizationalUnitAdministrativesubstructureofdomains,arrangedhierarchically,canbenestedSpecialtypeofobjectcalledcontainer;includesusers,computersystems,printers,etc.AlogicalsubsetdefinedbysecurityoradministrativeparameterswherespecificsystemadminfunctionscanbeeasilysegmentanddelegatedOUExampleMarketing.toysrus.comToysrus.comny.marketing.toysrus.comTeams.sales.toysrus.comOnline.teams…Retail.teams…Sales.toysrus.comGlobalCatalogADusesaglobalcatalogi
三七文档所有资源均是用户自行上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作他用。
本文标题:Active Directory and DNS - UMBC An Honors Universi
链接地址:https://www.777doc.com/doc-3435328 .html