Novell Security Manager appliance is not eDirectory-enabled

Opinion
Mar 8, 20053 mins

* Novell's latest appliance will write directly to Active Directory, but not to eDirectory

In a newsletter last month about Novell’s new security offering, “Novell Security Manager powered by Astaro”, I speculated about the future of BorderManager (see editorial link below). I figured it would draw out some response from those using BorderManager, and it did. What I hadn’t counted on was the content of the messages I received. Virtually no one had a good word to say about BorderManager!

One reader, admittedly a bit more enthused about the new product because of his familiarity with Astaro, nevertheless summed up what many others were hoping or wishing for:

“I ran various versions of BorderManager from its initial release until Jan. 1, 2004. Being a MCNE (Master Certified Novell Engineer) with CNI (Certified Novell Instructor) certification on BorderManager, I was always very comfortable with the product. However, a year ago, I eliminated it from my home network, by replacing it with Astaro Security Linux v4. Astaro is simply better. It is easier to manage, via its secure Webadmin interface, and it has far more configurable features and reporting capabilities. And the VPN functions work nicely with the built-in VPN capabilities of Win NT 5.0 and higher.”

Even more damning, though, were the words used by those still using BorderManager. Most were similar to this from a longtime reader:

“BorderManager has been in bad need of an overhaul for a long time now. The only feature of BorderManager we even use in most installations is the eDirectory integrated proxy server with access control. I guess what I’m saying is, I’m open to the possibility that they are killing BorderManager, as long as we still have an eDirectory integrated access control system to replace it with.”

That last phrase could be the telling point, though. The new appliance is not eDirectory enabled! That’s not made clear in the press materials sent out announcing “Novell Security Manager powered by Astaro”, but was confirmed by a Novell spokesman when I asked directly. You could use eDirectory (treating it as a generic LDAP repository), but the appliance doesn’t leverage any of the superior benefits of that directory system. In fact, what I was told by Novell was that the appliance “…can authenticate users via an LDAP call to eDirectory, via a RADIUS server, via Active Directory in a Microsoft network environment (or SAM in an NT environment) or via local user lists.”

What?!? It will write directly to Active Directory, but not to eDirectory? Do you know how many pages of articles, papers, slideshows and press releases Novell has dedicated to telling us how vastly superior eDirectory is to Active Directory? Many thousands of them. Yet Novell couldn’t take the time to get this one “right”, that is, to eDirectory-enable it. When I asked why, press aide Rod Anderson replied: “The release is targeted at bringing in new customers to Novell, not at existing NetWare customers. In addition, the next version of Security Manager will include native eDirectory authentication.” Last I looked, eDirectory didn’t require a NetWare server – it runs quite happily on Windows, Unix and Linux so the “new customers” argument is specious, at best.

Bottom line, for me: This may become a good offering from Novell, once it’s complete. It shouldn’t have been released before it was complete.