Symas OpenLDAP Knowledge Base

Replication Best Practices

Write Traffic

  • While it is possible to direct write traffic to any provider in a multi-provider environment, it is better to direct writes to only one provider at a time and keep the other providers as standbys to take write traffic if the primary provider fails.

Server Configuration

  • Replication depends heavily on accurate timing. Make sure that all provider and consumer system clocks are synchronized with NTP or similar service.

High Availability

  • Designate which consumers are candidates for promotion and pre-configure slapd.conf (or ldif to update dynamic config) and ensure all backend configurations/folder structures are identical to the current provider
  • If using SSL/TLS for communication between servers, make sure that the security certificates on all replicas are valid for communication with the new provider