posted 22 years ago
Hi Sandep,
Yes. Meta-directory can help in this regard. You would use the meta-directory product to synchronize information between the two directories as appropriate. One thing to consider, however, is that some meta-directory products have weak password propagation capabilities. meaning that if you change a password in LDAP you might not be able to easily move the password to Active Directory and vice-versa. In an environment where the idea is to provide a consolidated identity information (including login information), this is obviously an important field to get integrated.
To get around this with those meta-directory products, you can use special password synchronization products, most of which are agent-based and specialize in password capture. Psynch, Passgo, and Courion all make good password synchronization products that work with Active Directory and other LDAP directories.
As an alternative to meta-directory, you might go with a provisioning product. Rather than have you use your management interfaces in Exchange and Sun and then synchronize with a metadirectory on the backend, you might use the provisioning tool's interface to make changes and have it fan out those changes to Active Directory, Sun One, and any other identity repository that might need the information.
Clayton
[ March 17, 2003: Message edited by: Clayton Donley ]