
Integrated Installer Overview 9
Figure 1-1 Identity Vault Structure
Figure 1-1 depicts the Identity Vault structure for the Identity Manager. This structure is primarily
useful for a single-environment installation. This is the default structure for small and medium
Identity Manager deployments. Multi-tenant environments might have a slightly different structure.
Also, you cannot organize large and distributed trees in this way. This type of tree structure is created
when you create a new tree through the integrated installer.
Identity Manager 4.0.1 uses mostly organization containers, so that users, groups, and service admins
are placed in the same container. You should use organizations if possible and use organizational
units where it makes sense. The Identity Manager 4.0.1 structure is set up for scalability by having
three main components:
Section 1.2.1, “Security,” on page 9
Section 1.2.2, “Data,” on page 10
Section 1.2.3, “System,” on page 10
1.2.1 Security
The security container is a special container created during the installation of the Identity Vault. It is
designated as
cn=security
instead of
dc, o,
or
ou
. This container holds all security objects for the
Identity Vault. For example, it contains the certificate authority and password policies.
t=idv
o=system
cn=securityo=data
ou=users ou=groups ou=sa
ou=
...
ou=sa
cn=admin
cn=driver1
cn=driver2
ou=servers
cn=driverset1
cn=Role
Based
Service 2
...
Tree root
Split between the system and the data
objects. Only users should have
access to the data subtree.
Split between the system and the data
objects. Only admin users should
have access to the system subtree.
Security
container
Default
container
for users
Default
container
for groups
Default container
for the role admin
user, super user,
and service
accounts.
Other data
containers,
including
the devices
System users,
including the
admin, driver
admins, and
others
Separation of
the server
objects from
other system
objects, all
server and
related objects
Driver sets are
placed directly
under the
system, vault
container
For iManager
Other containers
hosting other
services
Tree admin Driver 1 Driver 2
Comentários a estes Manuais