Google Apps Directory Sync Administration Guide Bedienungsanleitung Seite 1

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Software Google Apps Directory Sync Administration Guide herunter. Google Apps Directory Sync Administration Guide User Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 146
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - Google Apps Directory Sync

Google Apps Directory Sync Administration GuideRelease 4.0.2

Seite 2 - Part number: GADS_4.0.2

10 Release 4.0.2How to Send Comments About This GuideGoogle values your feedback. Please send comments about this guide to:enterprise-apps-doc-feedbac

Seite 3

100 Release 4.0.2 Sample Substring Match: Defunct Mailing ListsSeveral mailing lists are no longer in use because two nearby offices combined togethe

Seite 4 - 4 Release 4.0.2

Configuration 101Add Group Exclusion RuleClick Add Exclusion Rule to prevent an address from being treated as a mailing list, and specify the follow

Seite 5 - Contents

102 Release 4.0.2 User Profile AttributesSpecify what attributes Google Apps Directory Sync will use when generating the LDAP user profiles.

Seite 6 - 6 Release 4.0.2

Configuration 103The fields are as follows.LDAP Profile User Attribute DescriptionPrimary email LDAP attribute that contains a user’s primary mail a

Seite 7 - Escalating Problems 145

104 Release 4.0.2 User Profile Search RulesThis shows a list of rules used when determining which user profiles to import.Note: If you store your use

Seite 8 - 8 Release 4.0.2

Configuration 105This page shows the list of search rules. In a new configuration, this will be an empty list. To add a search rule, click the Add S

Seite 9 - About This Guide

106 Release 4.0.2 Rule The search rule for user profile sync to match. This rule is a standard LDAP query, and allows sophisticated logic and complex

Seite 10 - Document Description

Configuration 107User Profile Exclusion RulesIf you have any existing user profile information in Google Apps that you do not want to synchronize, s

Seite 11 - How Directory Sync Works

108 Release 4.0.2 Sample Exact Match: Opt-Out UsersTwo users have opted out of Google Apps and should not be synchronized.Add a separate rule for eac

Seite 12 - Data Flow

Configuration 109Specify the following:Shared ContactsSet up synchronization for Google Apps shared contacts in the LDAP Shared Contacts page. Share

Seite 13 - What Is Synchronized

Chapter 2 Overview of Google Apps Directory Sync 11Overview of Google Apps Directory SyncChapter 2What Is Google Apps Directory Sync?Google Apps Dire

Seite 14 - 14 Release 4.0.2

110 Release 4.0.2 You can see Shared Contacts in Google Apps by going to your Inbox and clicking the Contacts link.The Shared Contacts section config

Seite 15 - Directory Sync and Deployment

Configuration 111Below are some of the most common reasons to import Shared Contacts:• Add groups and outside addresses to autocomplete. User addres

Seite 16 - 16 Release 4.0.2

112 Release 4.0.2 The fields are as follows.LDAP Shared Contact Attribute DescriptionSync key An LDAP attribute that contains a unique identifier for

Seite 17 - Early Adopter

Configuration 113Shared Contact Search RulesThis shows a list of rules used when determining which shared contacts to import.Mobile phone numbers LD

Seite 18 - Maintenance

114 Release 4.0.2 By default, shared contacts are synchronized for all contacts that match these search rules will be added to the Google Apps user l

Seite 19 - System Requirements

Configuration 115LDAP Shared Contacts Search Rule FieldDescriptionScope This determines where in the LDAP directory this rule applies.Choose which o

Seite 20 - Level of Effort and Expertise

116 Release 4.0.2 Shared Contact Exclusion RulesIf you have any contacts on your LDAP directory server that match your search rules but should not be

Seite 21

Configuration 117This page shows the list of exclusion filters. In a new configuration, this will be an empty list. To add exclusion filters, click

Seite 22 - 22 Release 4.0.2

118 Release 4.0.2 Add Exclusion RuleClick Add Exclusion Rule to exclude a shared contact in your LDAP server from synchronization.Specify the followi

Seite 23 - Getting Started

Configuration 119LDAP Calendar ResourcesThis section configures how Google Apps Directory Sync generates your LDAP calendar resources list for compa

Seite 24 - Softerra LDAP Administrator

12 Release 4.0.2 Technical OverviewGADS includes two connected tools: Configuration Manager and the sync-cmd synchronization command line utility. Co

Seite 25 - Identify LDAP Resources

120 Release 4.0.2 Calendar Resource AttributesSpecify the attributes you want Google Apps Directory Sync to use when generating the LDAP calendar res

Seite 26 - Clean Up LDAP Data

Configuration 121Note: Calendar resource attributes use a different syntax than other Directory Sync attributes.All attributes in the LDAP Calendar

Seite 27 - Getting Started 27

122 Release 4.0.2 By default, all calendar resources that match these search rules will be added to the Google Apps calendar resources, and all calen

Seite 28 - ActiveGoogleAppsUsers

Configuration 123Calendar Resource Exclusion RulesIf you have any entities on your LDAP directory server that match your calendar resource search ru

Seite 29 - User Data

124 Release 4.0.2 Exclusion rules are based on string values and regular expressions, not LDAP settings. Note: To exclude individual calendar resourc

Seite 30 - Groups and Mailing Lists

Configuration 125Sample Substring Match: PrintersIn this example, printers are listed as LDAP resources and would match the LDAP query given. Howeve

Seite 31 - Getting Started 31

126 Release 4.0.2 Add Exclusion RuleClick the Add Exclusion Rule at the bottom of the page to exclude a user or organization in your LDAP server from

Seite 32 - Passwords

Configuration 127NotificationsYou can set Configuration Manager so that every time synchronization occurs, Google Apps Directory Sync will send out

Seite 33 - Roadmap for Deployment

128 Release 4.0.2 Consider adding a notification to send mail to your own address, and possibly the addresses of any concerned parties in your compan

Seite 34 - 34 Release 4.0.2

Configuration 129Test NotificationClick this button to test notifications. Configuration Manager will connect to the SMTP server you specified and s

Seite 35 - Getting Started 35

Overview of Google Apps Directory Sync 13SecurityGADS has the following security features:• It runs inside your network, on a machine you control.•

Seite 36 - 36 Release 4.0.2

130 Release 4.0.2 Logging SettingsYou can specify the file name and level of detail of logging for Google Apps Directory Sync.Specify the following:L

Seite 37 - Sample Scenario

Configuration 131SyncAfter you enter configuration information, use this section to verify and test your GADS settings. Configuration Manager does n

Seite 38 - Enable APIs

132 Release 4.0.2 Validation ResultsWhen you first go to this page, you will see Validation Results. This page will show a checklist of all the Confi

Seite 39 - Further Steps

Configuration 133During simulation, Configuration Manager will:• Connect to Google Apps and generate a list of users, groups, and shared contacts.•

Seite 41 - LDAP Queries

Chapter 7 Synchronization 135SynchronizationChapter 7About SynchronizationRun the synchronization command to push your LDAP directory server user inf

Seite 42 - Common LDAP Queries

136 Release 4.0.2 sync-cmdRun without any arguments, this command gives an error and directs you to run sync-cmd -h for help.To synchronize, use the

Seite 43 - LDAP Queries 43

Synchronization 137Scheduling SynchronizationOnce you have successfully run a manual synchronization, you can set up automatic synchronization. Use

Seite 44 - 44 Release 4.0.2

138 Release 4.0.2 To schedule a task1. In Control Panel, open Scheduled Tasks. 2. Double-click Add Scheduled Task.3. Complete the Scheduled Task wiza

Seite 45 - Installation

Synchronization 139MonitoringAfter you have set up scheduled synchronization, make a policy of regularly checking the status of your synchronization

Seite 46 - 46 Release 4.0.2

14 Release 4.0.2 User AliasesNicknames Other email addresses also used by a given primary address. Each user can have multiple nicknames in Google Ap

Seite 48 - 48 Release 4.0.2

Chapter 8 Release 4.0.2 Troubleshooting 141Release 4.0.2 TroubleshootingChapter 8About TroubleshootingThis chapter covers information about how to tro

Seite 49 - Configuration

142 Release 4.0.2 What port numbers should be used in GADS when connecting to Global Catalog server?By default, GADS connects to an LDAP server with t

Seite 50 - Configuration Files

Release 4.0.2 Troubleshooting 143A group rule or exclusion rule doesn’t seem to be doing anything.Check the scope of the rule. You may need to set th

Seite 51 - Configuration Best Practices

144 Release 4.0.2 The proxy environment requires a password challenge for external web access.GADS can use a proxy server but cannot respond to passwo

Seite 52 - General Settings

Release 4.0.2 Troubleshooting 145System TestsIf you encounter problems, use the tests in Configuration Manager to find the problem:1. In Configuratio

Seite 54 - 54 Release 4.0.2

Overview of Google Apps Directory Sync 15Directory Sync and DeploymentGADS can be used during different stages of the Google Apps deployment cycle.

Seite 55 - Configuration 55

16 Release 4.0.2 If you have already added users through another method, and begin using GADS afterwards, you may move directly to Global Go Live and

Seite 56 - Authorizing using OAuth

Overview of Google Apps Directory Sync 17Users: A small number of manually added users.In the Core IT phase, a small number of IT users activate in

Seite 57 - Google Apps Proxy Settings

18 Release 4.0.2 Global Go LiveUsers: All users active in Google Apps.In the Global Go Live phase, all users become active and begin using Google App

Seite 58 - Google Apps Exclusion Rules

Overview of Google Apps Directory Sync 19If you remove any users from your company, update Google Apps to reflect these changes. Many companies remo

Seite 59 - Configuration 59

2 Release 4.0.2 Google, Inc.1600 Amphitheatre ParkwayMountain View, CA 94043www.google.comPart number: GADS_4.0.2November 5, 2014© Copyright 2014 Goo

Seite 60 - Pattern of users

20 Release 4.0.2 Server Requirements• A server to run GADS. The server should run one of the following operating systems:• Microsoft Windows (support

Seite 61

Overview of Google Apps Directory Sync 21Depending on your configuration, you may need the following levels of expertise for implementing GADS:• Goo

Seite 63 - Configuration 63

Chapter 3 Getting Started 23Getting StartedChapter 3OverviewThis chapter discusses the steps you’ll take when you get started with Google Apps Directo

Seite 64 - LDAP Configuration

24 Release 4.0.2 5. Prepare your server environment for synchronization. Confirm that you have a notification mail server ready. For more information,

Seite 65 - LDAP Connection Settings

Getting Started 25JXplorerTo download the JXplorer Java Ldap Browser, go to:http://www.jxplorer.orgStep Two: Collect LDAP InventoryYou can deploy GAD

Seite 66 - LDAP Org Units

26 Release 4.0.2 Research LDAP StructureUse an LDAP browser to collect information about your LDAP server and structure.You may find, while preparing

Seite 67 - Org Unit Mappings

Getting Started 27When conducting LDAP cleanup, consider the following actions.• Identify users. Identify which users you want to synchronize with Go

Seite 68 - Examples of Mapping

28 Release 4.0.2 There are three ways to mark your Google Apps users in LDAP:• OU: Set up an organizational unit (OU) and move Google Apps users into

Seite 69 - Add Mapping

Getting Started 29Note: GADS does not create a domain for you, so you will need to add the domain before you use Directory Sync.Collect the exact dom

Seite 70 - Org Unit Search Rules

3This product includes software developed byThe Apache Software Foundation (http://www.apache.org/).Portions of Derby were originally developed by I

Seite 71 - Add Org Unit Search Rule

30 Release 4.0.2 queries, see “About LDAP Queries” on page 41.WARNING: Check to be sure that you are importing the correct number of users. If you imp

Seite 72 - Org Unit Exclusion Rules

Getting Started 31• Mailing Lists: Decide which mailing lists you want to synchronize from your LDAP directory server into Google Apps. Mailing lists

Seite 73 - Configuration 73

32 Release 4.0.2 Autocomplete addresses.Important: Shared Contacts do not show up immediately. After you synchronize Shared Contacts, it may take up t

Seite 74 - 74 Release 4.0.2

Getting Started 33passwords.Because this password may be guessed by other users, this is not generally recommended as a secure option.Important: Be c

Seite 75 - Add Rule

34 Release 4.0.2 For more information about deployment phases and the 3-phase deployment model, see “Directory Sync and Deployment” on page 15.Core IT

Seite 76 - User Accounts

Getting Started 35UsersSet up exceptions for manually-added Core IT users, temporary administrators, or other users that are not part of your LDAP se

Seite 77 - User Attributes

36 Release 4.0.2 Suspended UsersYou can synchronize Google Apps users as suspended users for testing Google Apps functionality.Suspended users can be

Seite 78 - Setting Description

Getting Started 37Sample ScenarioThe Google Apps administrator for MobiStep decides that the existing organization hierarchy on the LDAP server shoul

Seite 79 - Additional User Attributes

38 Release 4.0.2 The administrator decides that MobiStep needs to synchronize:•OUs•Users• Aliases• Groups (mailing lists)• Shared contacts• Calendar r

Seite 80 - 80 Release 4.0.2

Getting Started 39Step Five: Prepare Your Servers for SynchronizationBe sure that your servers and network are prepared for GADS.Notifications Mail S

Seite 82

40 Release 4.0.2

Seite 83

Chapter 4 LDAP Queries 41LDAP QueriesChapter 4About LDAP QueriesGADS uses the LDAP query language to collect data from your directory server. Before

Seite 84 - User Search Rules

42 Release 4.0.2 For examples of how these operators are used, see the common LDAP queries below.Common LDAP QueriesThe examples below show the most

Seite 85

LDAP Queries 43All user objects except for ones with primary email addresses that contain the word “test”(&(&(objectclass=user)(objectcatego

Seite 87 - User Exclusion Rules

Chapter 5 Installation 45InstallationChapter 5About InstallationGoogle Apps Directory Sync (GADS) is designed to run on Windows or Linux servers.The

Seite 88 - 88 Release 4.0.2

46 Release 4.0.2 3. Download and run the installer.4. Complete all the steps of the installer.The installer contains all needed components and can be

Seite 89 - Configuration 89

Installation 47If you upgrade GADS and then open a configuration file that you created in a previous version, you need to save that configuration fi

Seite 90

48 Release 4.0.2

Seite 91 - Configuration 91

Chapter 6 Configuration 49ConfigurationChapter 6About ConfigurationConfiguration Manager is a step-by-step graphical user interface that walks you th

Seite 92 - Group Search Rules

Contents 5ContentsAbout This Guide 9What This Guide Contains 9Related Documentation 9How to Send Comments About This Guide 10Chapter 2: Overview of

Seite 93 - Add Group Search Rule (LDAP)

50 Release 4.0.2 GADS includes several ways to customize search rules and filters. When collecting information from your LDAP server, you can define

Seite 94 - 94 Release 4.0.2

Configuration 51An LDAP query that would return too many results may time out. If this happens, do not create multiple configuration files to reduce

Seite 95 - Configuration 95

52 Release 4.0.2 General SettingsYou specify which categories of object to synchronize from your LDAP server on the General Settings page.Specify the

Seite 96 - 96 Release 4.0.2

Configuration 53Google Apps ConfigurationBefore you begin setup in Google Apps Configuration, collect information about your Google Apps domain and

Seite 97 - Configuration 97

54 Release 4.0.2 Google Apps Connection SettingsEnter your Google Apps connection information in this section.Specify the following:Google Apps Setti

Seite 98 - Group Exclusion Rules

Configuration 55Replace domain names in LDAP email addresses (of users and groups) with this domain name.If checked, all LDAP email addresses are ch

Seite 99 - Example Group Exclusion Rules

56 Release 4.0.2 Authorizing using OAuthClick Authorize Now to set up your Authorization settings and create a verification code.Note: Customer who a

Seite 100 - 100 Release 4.0.2

Configuration 57Google Apps Proxy SettingsProvide any necessary network proxy settings here. If your server does not require a proxy to connect to t

Seite 101 - User Profiles

58 Release 4.0.2 Google Apps Exclusion RulesExclusion rules let you omit specific users, groups, org units, calendar resources, and other Google Apps

Seite 102 - User Profile Attributes

Configuration 59Exclusion rules are based on string values and regular expressions, not LDAP settings. You can exclude user profiles or shared conta

Seite 103 - Configuration 103

6 Release 4.0.2 Configuration Best Practices 51General Settings 52Google Apps Configuration 53Google Apps Connection Settings 54Google Apps Proxy Set

Seite 104 - User Profile Search Rules

60 Release 4.0.2 For instance, if you add all your IT administrators to the organization path “administrators/IT” and your security administrators in

Seite 105 - Add User Profile Search Rule

Configuration 61Custom Google Apps GroupsIf you have groups listed in Google Apps that don’t match a mailing list in your LDAP directory server, Dir

Seite 106 - 106 Release 4.0.2

62 Release 4.0.2 In the Add Exclusion Rule panel, specify the following to add an exclusion rule. Keep in mind that this is information on your Googl

Seite 107 - User Profile Exclusion Rules

Configuration 63Match Type The type of rule to match for the filter.• Exact Match: The address or organization name must match the rule exactly.Exam

Seite 108 - Add Exclusion Rule

64 Release 4.0.2 LDAP ConfigurationThe LDAP Configuration section configures how Directory Sync connects to your LDAP directory server and generates

Seite 109 - Shared Contacts

Configuration 65LDAP Connection SettingsSpecify your LDAP connection and authentication in this page.LDAP Connection Setting DescriptionServer Type

Seite 110 - How to use Shared Contacts

66 Release 4.0.2 Test ConnectionOnce you have configured LDAP Authentication settings, click Test Connection. Configuration Manager will connect to y

Seite 111 - Shared Contact Attributes

Configuration 67Org Unit MappingsThis shows a list of rules used when generating the LDAP org units.Specify how OUs on your LDAP server correspond t

Seite 112 - 112 Release 4.0.2

68 Release 4.0.2 Examples of MappingListed below are samples of common mappings. Note that the exact text of these rules will vary based on your need

Seite 113 - Shared Contact Search Rules

Configuration 69Add MappingTo add a new search rule, click Add Mapping.Specify the following:Mapping Setting Description(LDAP) DN The Distinguished

Seite 114 - 114 Release 4.0.2

Contents 7Escalating Problems 145

Seite 115 - Configuration 115

70 Release 4.0.2 Org Unit Search RulesThis shows a list of rules used when generating the LDAP org units.By default, all org units that match these s

Seite 116 - Rule Field Description

Configuration 71Add Org Unit Search RuleTo add a new search rule, click Add Search Rule and specify the fields in the dialog box. After specifying t

Seite 117 - Configuration 117

72 Release 4.0.2 Org Unit Exclusion RulesIf you have any org units on your LDAP directory server that match your search rules but should not be added

Seite 118

Configuration 73Some examples of reasons for LDAP org unit exclusion rules:• OUs for printers, conference rooms, and other non-user resources• Test

Seite 119 - LDAP Calendar Resources

74 Release 4.0.2 Sample Substring Match: Defunct OUsSeveral organizational units are no longer in use because two nearby offices combined together. T

Seite 120 - Calendar Resource Attributes

Configuration 75Rule: ou=internal-test[0-9]*,dc=ad,dc=example,dc=comAdd RuleClick Add Exclusion Rule to exclude an org unit in your LDAP server from

Seite 121 - Configuration 121

76 Release 4.0.2 User AccountsThe User Accounts section configures how Google Apps Directory Sync generates your LDAP user list for comparison. You m

Seite 122 - Add Search Rule

Configuration 77User AttributesSpecify what attributes Google Apps Directory Sync will use when generating the LDAP user list.LDAP User Attribute Se

Seite 123 - Configuration 123

78 Release 4.0.2 Google Apps Users Deletion / Suspension PolicyOptions for deleting and suspending users.Available options:• Delete only active Googl

Seite 124 - 124 Release 4.0.2

Configuration 79Additional User AttributesLDAP Extended Attributes are optional LDAP attributes that you can use to import additional information ab

Seite 126

80 Release 4.0.2 Family Name Attribute(s) An LDAP attribute that contains each user’s family name. (In the English language, this is usually the last

Seite 127 - Notifications

Configuration 81Password Attribute An LDAP attribute that contains each user’s password. If you set this attribute, your users’ Google Apps password

Seite 128 - 127.0.0.1

82 Release 4.0.2 Password Encryption Method The encryption algorithm that the password attribute uses.• SHA1: Passwords in your LDAP directory server

Seite 129 - Test Notification

Configuration 83Force new users to change passwordIf checked, new users must change passwords the first time they log in to Google Apps. This allows

Seite 130 - Logging Settings

84 Release 4.0.2 User Search RulesThis shows a list of rules used when generating the LDAP user list.By default, all users that match these search ru

Seite 131 - Logging Setting Description

Configuration 85Add Search RuleTo add a new search rule, click Add Search Rule and specify the fields in the dialog box. After specifying the fields

Seite 132 - Validation Results

86 Release 4.0.2 Suspend these users in Google AppsSuspend all users that match this LDAP user sync rule.Directory Sync suspends users that already e

Seite 133 - Configuration 133

Configuration 87User Exclusion RulesIf you have any users on your LDAP directory server that match your search rules but should not be added to Goog

Seite 134 - 134 Release 4.0.2

88 Release 4.0.2 Exclusion rules are based on string values and regular expressions, not LDAP settings. Note: To exclude individual users, add a sepa

Seite 135 - Synchronization

Configuration 89Sample Substring Match: PrintersIn this example, printers are listed as LDAP users and would match the LDAP query given. However, th

Seite 136 - Synchronization options

9About This GuideWhat This Guide ContainsThe Google Apps Directory Sync Administration Guide provides information about:• Google Apps Directory Sync f

Seite 137 - Scheduling Synchronization

90 Release 4.0.2 Add Exclusion RuleClick Add Exclusion Rule to exclude a user or organization in your LDAP server from synchronization, and specify t

Seite 138 - Linux: cron

Configuration 91GroupsSet up synchronization for Google Groups for Work in the LDAP Groups page. Google Groups for Work are similar to LDAP mailing

Seite 139 - Monitoring

92 Release 4.0.2 Group Search RulesGoogle Apps Directory Sync can synchronize Google Groups with your LDAP server’s mailing lists.This page shows the

Seite 140 - 140 Release 4.0.2

Configuration 93Add Group Search Rule (LDAP)To synchronize one or more mailing lists as Google Groups, click Add Search Rule and specify the fields

Seite 141 - Release 4.0.2 Troubleshooting

94 Release 4.0.2 Specify the following:LDAP Group Rule SettingDescriptionScope Where to apply the mail list rule.Choose which option to user:• Sub-tr

Seite 142 - Synchronization Rules

Configuration 95Group Display Name AttributeAn LDAP attribute that contains the display name of the group. This will be used in the display to descr

Seite 143 - Connections and Security

96 Release 4.0.2 Member Literal Attribute(Either this field or Member Reference Attribute is required.)An attribute that contains the full email addr

Seite 144 - LDAP Directory Server

Configuration 97Add Group Search Rule (Prefix-Suffix)You may need Directory Sync to add a prefix or suffix to the value your LDAP server provides fo

Seite 145 - Escalating Problems

98 Release 4.0.2 Group Exclusion RulesYou can exclude particular mailing lists from being imported as groups.If you have any entries in your director

Seite 146 - 146 Release 4.0.2

Configuration 99Exclusion rules are based on string values and regular expressions, not LDAP settings.This page shows the list of exclusion rules. I

Kommentare zu diesen Handbüchern

Keine Kommentare