Active Directory and DNS - UMBC An Honors Universi

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

ActiveDirectoryLecture3ActiveDirectoryDefinitionsADisMicrosoft’sconsolidationofthemajorenterprise-widedirectoryserviceswithinasingle,replicabledatastoreandadministrativeinterfaceADisanetwork-basedobjectstoreandservicethatlocatesandmanagesresources,andmakestheseresourcesavailabletoauthorizedusersandgroups.The2componentsofADaretheDataStoreandtheADServicesthatactonthatdataADAdvantagesProvidescentralizedlogonandauthenticationpointforuserstoaccessresourcesAfocalpointforcentralizedadministrationandmanagementAsearchablestoreforinfoabouteverynetworkobjectanditsattributesStandard-basedstructuresandinterfacesallowforproductinteroperabilityandcompatibilitywith3rdpartyproductsScalable(virtuallynolimitonnumberofobjects)NewFeaturesRestartcapabilityRead-onlyDomainControllerAuditingimprovementsMultiplePassword/AccountLockoutPoliciesinaDomainADLightweightDirectoryServicesRoleDNSDNSisanInternetstandardservicethattranslateseasilyreadablehostnames,suchasmycomputer.microsoft.com,tonumericIPaddresses.DomainnamesforDNSarebasedonthehierarchicalnamingstructure(invertedtreestructure):asinglerootdomain,underneathwhichcanbeparentandchilddomains(branchesandleaves).EachcomputerinaDNSdomainisuniquelyidentifiedbyitsDNSfullyqualifieddomainname(FQDN),e.g.server1.ifsm.umbc.eduDynamicDNS–newerstandard,requiredforADADandDNSintegration•ActiveDirectoryandDNShavethesamehierarchicalstructure.•AllADnamesfollowDNSconventions•DNSrecords(zones)canbestoredinActiveDirectory.•ActiveDirectoryclientsuseDNStolocatedomaincontrollers.ADOrganizationAnunderlyingprincipleoftheADisthateverythingisconsideredandobject–people,servers,workstations,printers,etc.EachobjectalsohascertainattributesObjectclassesaredefinitionsoftheobjecttypesthatcanbecreatedintheAD.ControllingObjectAccessEveryobjecthasanACLthatcontainsinformationaboutwhohasaccesstoitandwhattheycandowithit.ControllingaccesstotheobjectinADisnotthesameasaccesstotheobjectitself.ADpermissionsonlyspecifywhetherauser,grouporcomputercanviewormodifyanobject’spropertiesinAD.AccesscanbesetupforindividualobjectpropertiesSchemaAsetofobjectdefinitions(objectclasses)andtheirassociatedattributesProvidesinfoonwhatobjectsandattributesareavailabletotheDirectoryAllowsadministratorstomodifyandaddnewobjectclasses,objectsandattributesasneeded,makingtheschemaextensibleBecauseofthisflexibility,ADiscapableofbeingthesinglepointofadministrationforallpublishedresources(files,peripheraldevices,hostconnections,databases,Webaccess,users)ADOrganizationADobjectsareorganizedaroundahierarchicaldomainmodelthatallowsscalabilityandexpandabilityDomainmodelbuildingblocksare:-domains-domaintrees-forests-organizationunitsNameSpaceADisbasedontheconceptofanamespace,thatisanameisusedtoresolvethelocationofanobjectADdomainnamescorrespondtoDNSdomainnamesEachobjecthasdifferentwaystorefertoit,andeachnamepinpointsthelocationofobjectinADDomainLogicalpartitioncomprisedofusers,computersandnetworkresourcesthatshareacommonlogicalsecurityboundaryandutilizeacommonnamespace(e.g.ifsm.umbc.edu)Domainscanbearrangedintoahierarchicalparent-childstructureAlldomainsmaintaintheirownsecuritypoliciesandsecurityrelationshipswithotherdomainsRequiresatleast1DomainController(whereADdatabaseisstored)Ifmorethan1DC(recommended)–theyusemulti-masterreplicationTrustsLogicalconnectionsbetweendomainstoallowusersfromonedomaintoaccessresourcesinanotherdomainCanbeone-ortwo-wayCanbetransitive,intransitiveorexplicitTrustterminology:TrustingtrustsTrustedDomainTrustedDomain(Users)TrustingDomain(Resources)TransitiveTrustsAtransitivetrustisatrustbetweentwodomainsinthesamedomaintree/forestthatcanextendbeyondthesetwodomainstoothertrusteddomainswithinthesamedomaintree/forest.Atransitivetrustisalwaysa2-waytrust-bothof.thedomainstrusteachother.Bydefault,allWindowsServer2008trustswithinadomaintree/forestaretransitivetrusts.DomainADomainBDomainCDomainTreeConsistsofhierarchyofdomainssharingacommonschema,securitytrustrelationship,andaGlobalCatalogFormedthroughtheexpansionofchilddomains,andthere’sonerootdomain(thefirstcreateddomain)DefinedbyacommonandcontiguousnamespaceDomainTreeExampleMarketing.toysrus.comToysrus.comSales.toysrus.comny.marketing.toysrus.comDomainForestsDomaintreeswithdifferentnamespacesconnectedbytrustrelationshipsAlltreeswithintheforestshareaGlobalCatalog,configurationandschema.Simplyareferencepointbetweentreesanddoesn’thaveitsownname.DomainForestExampleMarketing.toysrus.comtoysrus.comSales.toysrus.comNy.marketing.toysrus.comHR.Babiesrus.comBabiesrus.comSales.babiesrus.comNy.sales.babiesrus.comOrganizationalUnitAdministrativesubstructureofdomains,arrangedhierarchically,canbenestedSpecialtypeofobjectcalledcontainer;includesusers,computersystems,printers,etc.AlogicalsubsetdefinedbysecurityoradministrativeparameterswherespecificsystemadminfunctionscanbeeasilysegmentanddelegatedOUExampleMarketing.toysrus.comToysrus.comny.marketing.toysrus.comTeams.sales.toysrus.comOnline.teams…Retail.teams…Sales.toysrus.comGlobalCatalogADusesaglobalcatalogi

1 / 24
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功