DIRECTORY SERVICES


Extended Directory Catalogs
You can set up servers to use an Extended Directory Catalog. You create an Extended Directory Catalog from the PUBNAMES.NTF template, the same template used to create the IBM® Lotus® Domino® Directory. An Extended Directory Catalog combines advantages of a Domino Directory and a condensed Directory Catalog. It aggregates entries from multiple Domino directories into a single directory database as does the condensed Directory Catalog, but it retains the individual documents and the multiple, sorted views available in the Domino Directory to facilitate quick name lookups.

Although you can set up servers to use a condensed Directory Catalog, there are several advantages to using an Extended Directory Catalog instead.

Multiple views

The Extended Directory Catalog uses the same design as the Domino Directory, so it includes multiple views that sort names in different ways. Regardless of the format of a name, there's a view in the Extended Directory Catalog that a server can use to quickly find the name. A condensed Directory Catalog has one view used for lookups, which you choose how to sort when you configure it. To look up a name in a condensed Directory Catalog that doesn't correspond to the selected sort order, the server uses the full-text index to search for the name, which takes longer than a view search.

Using an Extended Directory Catalog on servers that route mail is a particular advantage, because a mail server can use views to quickly find an address regardless of the address format. When a mail server uses a condensed Directory Catalog, mail routing can back up if the Router uses the full-text index to look up addresses, for example, some Internet addresses, that don't correspond to the selected sort order.

When a IBM® Lotus® Notes® user with a condensed Directory Catalog on the client sends mail to a group, if the client's directory catalog doesn't contain the members of the group, there can be a delay while a server does a full-text search of a condensed Directory Catalog to look up the members. Delays when sending mail to groups are not an issue if mail servers use Extended Directory Catalogs.

Ease of application access

Applications can access information in an Extended Directory Catalog as easily as they can in a Domino Directory. Application access to a condensed Directory Catalog however is restricted by the nature of the aggregate documents and the number of views.

Multiple-view, enterprise directory

Users can open an Extended Directory Catalog and see an enterprise-wide directory with multiple views that sort by entry type. In a condensed Directory Catalog, there is only one view to display the different types of entries.

Groups for database authorization

Servers can use groups in only one directory configured in a directory assistance database, in addition to the primary Domino Directory for authorizing database access. Using an Extended Directory Catalog for this purpose, effectively allows servers to use groups in any secondary Domino Directory aggregated in the directory catalog for database access control.

Remote lookups

Servers use Directory Assistance to locate an Extended Directory Catalog, so you need to replicate the Extended Directory Catalog only to two or a few strategic servers to which the Directory Assistance database then points. You can configure failover so that if one replica of the directory catalog is unavailable, servers can use an alternate.

Each server that uses a condensed Directory Catalog requires a local replica of the directory catalog, which makes its smaller size less of an advantage overall.

Administrator control over rebuilds

Rebuilding a directory catalog removes all of the existing aggregated information, and then re-aggregates the information from the source Domino Directories. Since this process is time consuming, the Dircat task only rebuilds an Extended Directory Catalog when an administrator indicates. Changing almost any field in the configuration document for a condensed Directory Catalog, by contrast, triggers the Dircat task to rebuild the directory catalog automatically.

Extended ACL and LDAP access control settings

You can use an extended ACL to refine the overall database access to an Extended Directory Catalog. For example, you can deny access to sensitive fields, to entire documents associated with a particular part of a name hierarchy, and so forth. An extended ACL on an Extended Directory Catalog is independent of any Extended ACLs set on the individual source Domino Directories.

You can also create a Configuration Settings document in an Extended Directory Catalog and use access control settings on the LDAP tab of the document to control anonymous LDAP search access to the directory catalog.

These access control features are not available for a condensed Directory Catalog.

Native documents

You can add documents manually to an Extended Directory Catalog, in addition to aggregating documents through Dircat task processing. These "native" documents that originate in the database are not affected by Dircat task processing. You cannot add native documents to a condensed Directory Catalog.

Full-text index advantages

An Extended Directory Catalog has multiple, sorted views, so in general no full-text index is required for lookups, which helps minimize disk space usage. A full-text index is required, however, if you want the LDAP service to use an Extended Directory Catalog to process searches that use search filters based on something other than names or mail addresses.

A full-text index is always required for a condensed Directory Catalog.

If you choose to create a full-text index on an Extended Directory Catalog, users can do full-text searches of it from the Notes client. Users can't do full-text searches of a condensed Directory Catalog from the Notes client.

One server using more than one

A server can use more than one Extended Directory Catalog, for example one that aggregates directories that are trusted for Internet client authentication, and another that aggregates directories that are not trusted for client authentication.

A server can use one condensed Directory Catalog only.

Integration into a primary Domino Directory

Because an Extended Directory Catalog uses the same design as a Domino Directory, you can build an Extended Directory Catalog directly into the primary Domino Directory for a domain, so that one directory contains the information for an entire enterprise.

Server documents

You can aggregate Server documents into an Extended Directory Catalog, but not a condensed Directory Catalog.

Related topics