Igor Belyi wrote:
Marlys Nelson wrote:
The PDC appears to request ALL groups from LDAP, using the search
(objectclass=sambaGroupMapping). In our case, this is nearly 14,000
entries and it can take almost 10 minutes to retrieve those from LDAP
when there are hundreds trying at once. Indexing do
> I have a suggestion. I think you can partition off the groups by
> putting them in sub OU's of your groups OU.
Yes, and you could partition those OUs across servers.
>
> Alternatively you could use some Balanceing Domain Controllers with
> disconnected authentication. This entails setting up
I have a suggestion. I think you can partition off the groups by
putting them in sub OU's of your groups OU.
Alternatively you could use some Balanceing Domain Controllers with
disconnected authentication. This entails setting up Balanceing Domain
Controllers, each with a local LDAP slave serv
Marlys Nelson wrote:
The PDC appears to request ALL groups from LDAP, using the search
(objectclass=sambaGroupMapping). In our case, this is nearly 14,000
entries and it can take almost 10 minutes to retrieve those from LDAP
when there are hundreds trying at once. Indexing doesn't help in this