* Reader reaction to eDirectory support in Novell Security Manager issue
I was surprised, somewhat, at the reaction to last week’s newsletter about Novell’s new “Novell Security Manager powered by Astaro (NSM)” appliance and its relationship to directories. You’ll remember (I hope) that I looked askance at the fact that while NSM would read and write Active Directory natively, it could only read and write eDirectory through the LDAP interface.
A number of you took the view that it must be a given that Novell’s LDAP interface to eDirectory is naturally better than Microsoft’s LDAP interface for Active Directory – so the extra step of writing directly to Active Directory is a service to the users, bypassing a “faulty” LDAP implementation. That’s plausible, certainly, given Microsoft’s track record with open standards. But it’s just not true. Microsoft’s LDAP interface is as useful as Novell’s because both are written to the LDAP standard.
But eDirectory is “More than just an LDAP data store,” according to Novell’s product marketing people. In fact, eDirectory is much more than a data store. Again, according to Novell’s own product marketing people: “Among directory services, eDirectory is uniquely capable of meeting the demands of large-scale, high-end directory deployments. It offers the compatibility, security, reliability, scalability and manageability required for internal and Internet deployments supporting millions of identities.”
Don’t they read their own writing? And if they don’t believe them, why should we?
With the exception of a couple of dinosaur directory services based on the 20-year-old x.500 system (which, because it was so difficult to use, was the catalyst for the LDAP protocol!), eDirectory is by far the most mature, easily the most manageable and certainly the most widely used directory service on the planet!
Now don’t get me wrong, the LDAP interface in eDirectory is excellent. Using eDirectory as the LDAP repository for NSM is what I would recommend to everyone – everyone who wants to use an LDAP repository. What I’m ranting about is the message that the launch of NSM sends to longtime Novell customers, as well as those folks who’ve never used anything from the company before. People will be asking:
* Is BorderManager the best way to protect my network?
* Is eDirectory the best platform for identity management?
I’m not sure the company can honestly answer “yes” to these questions any longer.




