[1885] in Moira
AD Container Management snap-in: major issues to iron out!
daemon@ATHENA.MIT.EDU (Joseph Calzaretta)
Mon Oct 29 17:05:18 2001
Message-Id: <200110292200.RAA13764@melbourne-city-street.mit.edu>
Date: Mon, 29 Oct 2001 17:00:14 -0500
To: pismere-team@MIT.EDU, moiradev@MIT.EDU
From: Joseph Calzaretta <joe@MIT.EDU>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
I'd like to have this meeting tomorrow sometime (I haven't followed up on this since Garry's suggestion that we meet tomorrow, but I think at least Danilo's on board.) Does 1pm sound reasonable?
--Joe
------------------------------------
Dear folks:
I'm currently working on an AD Container Management snap-in (adcontmgr.msc) which basically presents a view similar to the Active Directory Users & Computers snap-in (dsa.msc) , but is mostly doing things in moira behind the scenes. Unfortunately, I've just hit a snag. Well, a set of snags. Here are the issues:
---------------------------
We need to put computers in groups in AD, especially for Group Policy. Do we
a) create computer-only groups in AD? What ACLs do we use?
b) allow computers to join groups in AD and have them not reflected in moira? What ACLs do we use and how does incremental work?
c) allow computers to join groups in moira? How do we make sure that all machines have a primary group, etc, as required by AD?
We need to decide where the ACLs in Active Directory come from for:
container objects
computer objects
user objects
group policy objects
There are properties of computers and containers in Active Directory which are not propagated from moira. For instance, computers have a "Description" field which is not stored in moira. And there is a "Location" field in both moira and AD which is not synchronized in any way. And we should revisit properties of users and groups while we're at it.
----------------------
Basically it comes down to this:
For each object and each property of every object that anyone cares about in Active Directory, either:
It is stored in Moira, and propagated to Active Directory from Moira incrementally, OR
It is not stored in Moira, and its ACL is propagated to Active Directory from Moira incrementally.
In the first case, all Moira clients will allow the appropriate users to do what they need to do, and adcontmgr.msc will just query moira.
In the second case, dsa.msc will allow the appropriate users to do what they need to do, and adcontmgr.msc will just query AD.
Any object or property which is neither stored in Moira nor has an ACL propagated from Moira will be a problem. How will the appropriate users be able to modify these properties? Does a domain admin need to manually assign ACLs for each of these? That seems inappropriate and unscalable.
We need to sit down and discuss what things come from where. Before these decisions are made, not only can't I go forward with my snap-in, but the growing number of container admin-type people (dusp, bio-micro, podium, bldg 37 cluster) who would like to do something useful with their containers will frown, snarl, etc.
---------------------------
It would be cool if such a meeting could star the following celebrities:
Garry, Paul Hill, Danilo, Qing, Dave, and yours truly As Himself.
This coming week might actually be bad for Pismere, as Paul is out of town and we have this IT Partners thingy on Thursday. But I could probably meet on Tuesday afternoon at, oh, 4pm. If this doesn't work out, can we meet, say, a week from Monday?
--Joe