建立目錄同步配置文檔

建立啟用目錄同步的目錄服務文件後,請在Domino ®目錄中建立目錄同步設定文件。您可以使用本文檔選擇目錄同步配置選項,然後啟用目錄同步。

程序

  1. 開啟Domino ®目錄。
  2. Select Configuration > Directory > Directory Sync.
  3. 點選新增目錄同步
  4. 填寫「基本資訊」標籤中的以下欄位:
    Table 1. Fields in the Basics tab of a Directory Sync Configuration document
    場地 描述
    目錄服務域 選擇在啟用目錄同步的目錄服務文件的 LDAP 標籤的網域名稱中指定的網域。例如,裝修 AD
    注意:為了能夠選擇網域,必須有一個為指定該網域的目錄同步啟用的目錄輔助文件。
    目錄同步狀態 完成本文檔中的其他設定選項後,選擇「啟用」以啟用目錄同步。您將看到以下提示:
    立即開始同步還是在測試模式下運作?
    選擇以下選項之一:
    • 同步數據
    • 以測試模式運作(登入控制台,不更新資料)

    選擇「在測試模式下運行」以模擬目錄同步將執行的操作,但不更改任何Domino ®資料。對目錄同步配置進行所需的任何調整。當您準備好真正啟用同步時,請選擇同步資料

    同步所有 Active Directory 用戶
    • 選擇「是」以同步 Active Directory 用戶,無論他們是否在 Domino 中註冊。
    • 選擇(預設)僅同步在 Domino 中註冊的 Active Directory 使用者。如果先前設定為Yes ,則先前同步的任何未註冊的 Active Directory 使用者都會從 Domino 目錄中刪除。

    更改此欄位的值會導致完全重新同步。

    對於要與 Domino 同步的 Active Directory 記錄,Active Directory mail 字段必須匹配Internet address Domino 目錄 Person 文檔中的欄位。

    Domino®目錄檔名 The file name for the Domino® directory, typically names.nsf.
    Direction The direction of synchronization. Currently only Active Directory to Domino® is available.
    Rename Domino® users upon Active Directory rename
    • Select Yes to change the common name of a registered Domino® user in Domino® when the users' common name changes in Active Directory. For more information, see Renaming Domino users when their names change in Active Directory.
    • Select No (default) to prevent users' common names from changing in Domino® when they change in Active Directory.
    Note: If the name of an Active Directory user who is not registered in Domino® changes, the name is automatically updated in the Domino® directory Person document during sync, regardless of this option.
    Sync frequency How frequently the Dirsync task checks for Active Directory changes to synchronize. Default is once a minute.
    Resync frequency

    How often to resync all data from Active Directory, in minutes. Default is 10,000 minutes or approximately once a week. If you don't want to regularly resync all data, specify 0.

    Resync causes the following changes to synchronize which are not otherwise synced:
    • Deleted users and groups.
    • Name changes within groups.

    Consider increasing the default value if many users and groups are regularly deleted in Active Directory. Also if there are frequent name changes and you synchronize Active Directory groups.

    Resync runs in the background on the Domino administration and does not have a big impact on performance.

    Table 2. Fields in Synchronization tab of a Directory Sync Configuration document
    場地 描述
    Fields to sync to Domino®

    Use this field to specify which Active Directory person fields to sync to Domino®. A standard list of fields from Active Directory is shown by default. You can add or remove fields from the list. When Active Directory and Domino® use different names for a field, the Domino® field name is shown in parentheses after the Active Directory field name. For example: mail (Email address).

    Modifying this field causes a full resync.

    Note:
    • When syncing multi-valued attributes, only the first value is synced.
    • Removing an attribute that was previously synced does not remove it from Person documents.
    LDAP Filter

    When you don't specify a filter, the following default search filter is used: (|(objectClass=Group)(objectClass=Person)). This filter syncs all users and groups in Active Directory.

    Optionally, use a standard LDAP search filter to sync a subset of users and groups based on attribute. Be sure to include the default filter in your custom search filter; that way, only user and group records are synced and not other types of records that are not relevant for the Directory Sync feature.

    For example, to sync only user and group records that contain the department hr AND the state MN, use the following filter: (&(|(objectClass=Group)(objectClass=Person))(&(department=hr)(st=MN)))
    Tip:
    To verify a custom search filter, you can use an open source LDAP browser such as Apache Directory Studio.

    Modifying this field causes a full resync.

    LDAP Groups
    • If you want to synchronize groups, select the types of groups to synchronize. If you don't want to synchronize groups, do not select either option.
      • Security groups, to be able to use Active Directory security groups in Notes® access lists.
      • Distribution groups, to be able to use Active Directory distribution groups in Notes® mail addressing.
    • Select No to synchronize person information only.

    Modifying this field causes a full resync.

  5. Click Save & Close.
  6. Restart the Domino server:
    Restart server
  7. The Dirsync task begins to run when it detects the configuration document.