目录缓存技术用于有效的用户管理

F. B. Manolache, W. McDowell, O. Rusu
{"title":"目录缓存技术用于有效的用户管理","authors":"F. B. Manolache, W. McDowell, O. Rusu","doi":"10.1109/ROEDUNET.2011.5993696","DOIUrl":null,"url":null,"abstract":"User management is one of the most time consuming tasks for administrators of large networks. This paper presents some techniques developed at Carnegie Mellon University to improve handling of accounts and access rights in a corporate environment. Directory information is typically handled by a hierarchy of LDAP servers maintained by different support groups on different administrative levels, from corporate to department. Optimization of information flow between these levels can be achieved by minimizing the need for communication between different support groups, and by reusing the data provided by the higher levels for automatic configuration of the lower levels. The method described here for achieving this goal is to trickle down user information from the higher to the lower administrative levels using successive cache mechanisms. This technique can be applied between different levels of LDAP servers (corporate, departmental, group), as well as for end-user computers. To preserve the flexibility of the configuration and the autonomy of the lower levels, the information stored by the LDAP server that's the closest to the end-user computer should have the highest precedence. By implementing the techniques described here, user management became more efficient, especially for automatically creating new accounts on end-user computers, expanding the number of local authenticated services, and granting local access rights for users.","PeriodicalId":277269,"journal":{"name":"2011 RoEduNet International Conference 10th Edition: Networking in Education and Research","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-06-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Directory cache techniques for efficient user management\",\"authors\":\"F. B. Manolache, W. McDowell, O. Rusu\",\"doi\":\"10.1109/ROEDUNET.2011.5993696\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"User management is one of the most time consuming tasks for administrators of large networks. This paper presents some techniques developed at Carnegie Mellon University to improve handling of accounts and access rights in a corporate environment. Directory information is typically handled by a hierarchy of LDAP servers maintained by different support groups on different administrative levels, from corporate to department. Optimization of information flow between these levels can be achieved by minimizing the need for communication between different support groups, and by reusing the data provided by the higher levels for automatic configuration of the lower levels. The method described here for achieving this goal is to trickle down user information from the higher to the lower administrative levels using successive cache mechanisms. This technique can be applied between different levels of LDAP servers (corporate, departmental, group), as well as for end-user computers. To preserve the flexibility of the configuration and the autonomy of the lower levels, the information stored by the LDAP server that's the closest to the end-user computer should have the highest precedence. By implementing the techniques described here, user management became more efficient, especially for automatically creating new accounts on end-user computers, expanding the number of local authenticated services, and granting local access rights for users.\",\"PeriodicalId\":277269,\"journal\":{\"name\":\"2011 RoEduNet International Conference 10th Edition: Networking in Education and Research\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-06-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2011 RoEduNet International Conference 10th Edition: Networking in Education and Research\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ROEDUNET.2011.5993696\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 RoEduNet International Conference 10th Edition: Networking in Education and Research","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ROEDUNET.2011.5993696","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

用户管理是大型网络管理员最耗时的任务之一。本文介绍了卡内基梅隆大学开发的一些技术,用于改进企业环境中的帐户处理和访问权限。目录信息通常由LDAP服务器的层次结构处理,这些服务器由不同管理级别(从公司到部门)的不同支持小组维护。这些级别之间的信息流优化可以通过最小化不同支持组之间的通信需求,以及重用较高级别提供的数据来实现较低级别的自动配置。这里描述的实现这一目标的方法是使用连续缓存机制将用户信息从较高的管理级别逐步传递到较低的管理级别。这种技术可以应用于不同级别的LDAP服务器(公司、部门、组)之间,也可以应用于终端用户计算机。为了保持配置的灵活性和低层的自主性,最接近最终用户计算机的LDAP服务器存储的信息应该具有最高的优先级。通过实现这里描述的技术,用户管理变得更加高效,特别是在最终用户计算机上自动创建新帐户、扩展本地身份验证服务的数量以及为用户授予本地访问权限方面。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Directory cache techniques for efficient user management
User management is one of the most time consuming tasks for administrators of large networks. This paper presents some techniques developed at Carnegie Mellon University to improve handling of accounts and access rights in a corporate environment. Directory information is typically handled by a hierarchy of LDAP servers maintained by different support groups on different administrative levels, from corporate to department. Optimization of information flow between these levels can be achieved by minimizing the need for communication between different support groups, and by reusing the data provided by the higher levels for automatic configuration of the lower levels. The method described here for achieving this goal is to trickle down user information from the higher to the lower administrative levels using successive cache mechanisms. This technique can be applied between different levels of LDAP servers (corporate, departmental, group), as well as for end-user computers. To preserve the flexibility of the configuration and the autonomy of the lower levels, the information stored by the LDAP server that's the closest to the end-user computer should have the highest precedence. By implementing the techniques described here, user management became more efficient, especially for automatically creating new accounts on end-user computers, expanding the number of local authenticated services, and granting local access rights for users.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信