Slashdot Mirror


Red Hat Acquires Netscape Server Products

KrisWithAK writes "According to a press release, Red Hat is acquiring parts of the Netscape Enterprise Suite including the directory server and certificate management system. I am definitely looking forward to more open source competition with OpenLDAP!"

23 of 257 comments (clear)

  1. Netscape Enterprise Server? Really? by jea6 · · Score: 2, Interesting

    I didn't even realize there still was a standalone Netscape offerring. We migrated from Netscape to iPlanet to Sun Web to Sun Java One (or something like that). Anybody out there stick with the Netscape product?

    --

    sarchasm: The gulf between the author of sarcastic wit and the person who doesn't get it.
    1. Re:Netscape Enterprise Server? Really? by Ford+Prefect · · Score: 2, Interesting

      Anybody out there stick with the Netscape product?

      I've fairly regularly seen little Netscape 'N' logos as the favourites icon in Safari. I can't imagine anyone intentionally setting it to such a thing, so are they from Netscape servers where the icon is still set to the default?

      --
      Tedious Bloggy Stuff - hooray?
  2. AOL already uses it..... by ARRRLovin · · Score: 4, Interesting

    ....it must be good!

    I hope they can advance enough to make some real competition for Microsoft Active Directory. I know a huge reason Windows shops never consider an alternative is because the AD GPO allows for some very granular management of AD resources.

    --
    -Randy
  3. Does OpenLDAP even work? by Offwhite98 · · Score: 3, Interesting

    I have tried ever few months to set up OpenLDAP using newer releases with instructions on their website and it never would work. I always had some issue with the DBM libraries or the commands in the tutorial were inaccurate and not current with the updated command-line options. It goes to show that no matter if the software actually works, if the documenation is not at least half decent the software is still incomplete.

    I have maintained Netscape/iPlanet LDAP servers before and they may not be perfect, but they worked. Perhaps a good open source LDAP server will help LDAP become a viable alternative to Windows Directory or other authentication systems.

    I thought I read about a Java LDAP server once, but never looked into it much.

    --
    Brennan Stehling - http://brennan.offwhite.net/blog/
    1. Re:Does OpenLDAP even work? by tylernt · · Score: 3, Interesting

      I feel your pain. OpenLDAP and the other products may compare at the user-level, but for administration, OpenLDAP just sucks. I have yet to find a good administration tool for it. Maybe one is hiding out there or is being developed as I speak.

      Novell sucks because there are some things you can do only in NWAdmin, others you can do only in ConsoleOne. Dumb. That's from Netware 5.1 and 6.0 though, maybe their newer stuff has improved.

      Lotus Domino's admin software sucks because everything is buried under 17 layers and if you click the wrong 'X' in the interface, you lose all 17 layers and have to start over. I hate Domino.

      iPlanet/SunOne's GUI interface isn't too bad but seems to be really slow, even on a 2GHz server with very few users(?). For advanced config options, you sometimes have to resort to editing a text file (albeit still within the admin GUI), which is one weak point.

      AD seems to have got it right with the ADUC and other MMC snap-ins, although if you get in and start messing around with permissions and GPOs you'd better know exactly what the heck you are doing because it's real easy to change things in ways you never expected (or in other words, break AD). The only drawback is, you don't have much low-level control over LDAP attributes and things -- you're just kind of stuck with 'the Microsoft Way' of doing things.

      In short, there is no perfect solution. I favor OpenLDAP just because it's OSS but the installation (from source) and the learning curve are both unpleasant. If you're a clueless MCSE-type and just want a quick LDAP directory, I'm afraid AD is the least painful route... if you don't mind clicking a soul-sucking EULA and bleeding ridiculous licensing fees to the Evil Empire.

      --
      DRM 'manages access' in the same way that a prison 'manages freedom'
  4. Please tell me about Netscape LDAP server ACL by Etyenne · · Score: 4, Interesting

    In the past, RedHat have been open-sourcing pretty much every applications they acquired AFAIK (see Sistina GFS, for example). Thus, I am pretty confident we will soon have a second Open-Source LDAP server from this deal. There is no garatee, but I am looking forward to it.

    For those who are familiar with Netscape LDAP server, could you teach me a bit about its ACL management capability ? OpenLDAP, in this regard, is pathetic. The ACL have to be written in some kind of filter language *inside* the config file, which need a restart/reload to take effect. It is very error-prone and basically the part of OpenLDAP that give me the most troubles. How is Netscape in this regard ? Can you define by-object ACL ? How are they stored ? How do you manage them ?

    Thanks for you insights !

    --
    :wq
  5. Re:That's still around? by Penis_Envy · · Score: 3, Interesting

    For me, the Directory Server product is very very interesting. If they could offer up some of the multi-master replication to openLDAP, or the Active Directory integration, big headway could be made in enterprise environments in the Directory Server space.

    That's the only thing of interest to me, personally. I think apache's web server eclipsed them a while ago.

  6. What's the point? by DogDude · · Score: 2, Interesting

    I don't understand what Red Hat is trying to do. It's ancient software. The brand "Netscape" is now. They already sell a competing product.
    The schizophrenia that Red Hat is displaying makes Sun & Oracle look sane by comparison.

    --
    I don't respond to AC's.
  7. Netscape Directory Server... by MadMorf · · Score: 3, Interesting

    I was responsible for a pair of Netscape Directory Servers, version 6.1 IIRC, at a former employer.

    They were relatively trouble free, much more so than some of the other "Netscape" products (Calendar Server)...

    Once in awhile they would hang, without any sort of error indication, no log entries or the like, which made troubleshooting them very problematic.

    The management interface was a Java app, which seemed fairly primitive,compared to NDS/eDirectory which I have used for about 9 years and AD which I have used since late 2000.

    Overall, I'd say my experience with Netscape Directory Server was positive, but it really could use some updating, if it hasn't been already...

  8. Re:are they gonna open source it? by LnxAddct · · Score: 5, Interesting

    Everything Red Hat has, does, or buys becomes open source. This is equally true for their patents (which are aquired for defensive reasons). Here is their patent policy. In short, it states that any patents they hold may be used by any free software project without fear of any infringement.
    Regards,
    Steve

  9. The significance of this... by Pivot · · Score: 4, Interesting

    is that now the best LDAP server in the marketplace in terms of functionality (4 way clustering, complete in-tree ACL support, enterprise level scalability) now becomes available as open source. The iplanet offering comes with a per entry licensing fee of about $1 (less if you need more than one million entries). Our company actually went out and bought Sun servers to avoid this, since Solaris includes a decent number of entry licenses per server. Now we can deploy on linux servers instead without the licensing hassle. Another nail in the Sun coffin...

  10. Re:Sun vs. AOL by danuary · · Score: 2, Interesting

    ...All of which means that Red Hat did NOT just buy all of the fun and interesting products that iPlanet produced -- Messaging/Calendar/et al are actually useful, mature, stable products -- but instead bought a stable LDAP server whose codebase probably hasn't changed much in several years.

  11. Re:That's still around? by LnxAddct · · Score: 5, Interesting

    If you've ever had to use openLDAP then you will never be happier once RH releases this. The features are limitless, but two things off the top of my head are that it has a significant improvement as far as speed and system resources go, and also it has good, advanced replication. It's easy to use and just an all around good architecture. Try it out when its released, it will speak for itself. Personally, I'm more interested in the Certificate Server.
    Regards,
    Steve

  12. A smart move by IGnatius+T+Foobar · · Score: 4, Interesting

    This is a smart move on Red Hat's part. It's clear to them that in order to remain competitive in the enterprise space, they have to have a "middleware stack" (as the industry has been calling it). Sun has SunOne/N1, Microsoft has ADS, and of course Novell has NDS/eDirectory which is soon to be a major Linux product. It would have quickly become a big gap in Red Hat's offering.

    By acquiring this software, Red Hat immediately improves the value proposition of their platform. By open sourcing it, the software can quickly gain mindshare and installed base. Imagine what would have happened if Novell had done this in, say, 1999. There'd be NDS everywhere, and Active Directory wouldn't have nearly the penetration it does today.

    --
    Tired of FB/Google censorship? Visit UNCENSORED!
  13. Finally linux for CertServer and Calendar Server? by Forget4it · · Score: 3, Interesting

    Netscape and then Sun stopped just when they were getting the plot. The Calendar Server has a backend that does the conflict resolution inc case of double-booking. It is time to integrate that with Mozilla Calender client. The Certificate Management system played nice with LDAP and but had a top-heavy administration server. It was a nice web-based GUI that an CertAuthority might be delegated to use. It will be a big win for OSS if these servers can now supported in linux - Sun were never going to do that properly. my 2 cents

    --
    Artificial intelligence is the study of how to make real computers act like the ones in the movies.
  14. Re:That's still around? by kjs3 · · Score: 2, Interesting
    We use it where I work.

    We run iPlanet on several hundred web servers and have a SunONE pilot looking to cover around 25 million users. iPlanet stuff seems to be smooth; SunONE has been...challenging.

    As I understand, tho, what RedHat got isn't the new stuff we are using.

  15. 3rd Party Source code to be removed. by xyleen · · Score: 2, Interesting

    AOL has 21 days to remove all 3rd party source code from the builds of all of the products Redhat is acquiring. One of the key components of Enterprise Mail server is the Mail Transfer Agent (MTA).

    The MTA is written by Innosoft International (www.innosoft.com). So the question is will they be leaving out a vital component of the mail server or will they just have to give away the MTA as well.

    --
    This is not my sig
  16. Apache? by emil · · Score: 2, Interesting

    Will Red Hat dump the Apache webserver over the new noxious licensing?

    OpenBSD has done so (by halting with an old release).

  17. Re:OpenLDAP vs Netscape's LDAP server by Anonymous Coward · · Score: 2, Interesting

    I can confidently say that you mis-configured the Netscape Server. The Netscape Server has always been a lot faster than OpenLDAP, even while doing more stuff (like multi-master replication - which openLDAP cannot, and doesn't seem to want to do).
    The Netscape DS does not require or use multiple processes - it is a multi-threaded server. If configured correctly it will scale into the millions of entries, and 100's operations per second. For most deployments (and the server was pretty much sold into Fortune 500 environments exclusively) this server doesn't even break a sweat. It is also btw coded to scale well up to 4 processors.
    Since around the 3.1/4.0 versions it has been the fastest Directory Server of any and all comers, period. It is also one of the most standards compliant and the most stable servers. I recall at a DS meet, Kurt from OpenLDAP had a pretty mean test suite designed to break directory servers which they (obviously) had coded to pass. That test suite broke every vendor in the room (and that means every major DS vendor) to varying degrees except the OpenLDAP and Netscape servers - and this was post iPlanet. Active Directory for example, managed to get through only a few minutes of a test suite that lasted about an hour.
    I have always been an admirer of the OpenLDAP product since they produced a good product with comparitively fewer resources. However, it is not (perhaps not yet) in the same league as the Netscape DS when it comes to scaling.

  18. Re:What';s wrong with OpenLDAP? by LuSiDe · · Score: 2, Interesting

    Widely acknowledged fact: OpenLDAP performs extremely slow. I don't have any real benchmarks though.

    --
    WE DON'T NEED NO BLOG CONTROL.
  19. Re:I never thought I'd see the day... by amper · · Score: 2, Interesting

    It should be mentioned that most of Netscape's products started out as free software:

    1. Netscape Directory Server was derived from the UMich LDAP implementation.

    2. Netscape Messaging Server started life as Cyrus and Post.Office hacked together.

    3. Netscape Collabra Server was an enhanced INN.

    4. etc. and of course, let's not forget NCSA Mosaic...

  20. Re:ldap vs. sql by kris · · Score: 2, Interesting

    Yes a Directory Server is a database.

    A database that is not even in 1st normal form.

    Other highlights include a hiarchical tree structure to store entries and extensive standard schema for many object types.

    And primary keys called "dn"s (distinguished names) that reflect the tree structure in a kind of path, so that when you move objects around in the tree, the dn changes. You'll have to change all other attributes that contain this dn as a value in order to keep the tree consistent. There are no mechanisms in LDAP that help you to do this, i.e. there are no constraints.

    But that isn't really a problem, because you wouldn't want to use dn valued entries anyway - LDAPs query language has no join operation at all, so in order to resolve a mail alias object containing dn valued entries for the rhs of the mail alias, you'd be forced to program that resolution in a loop by hand on the client side. For each client supporting it.

    In order to minimize dn volatility, you end up flattening your tree structure, for example by putting all users into the same level just below "ou=users,dc=example,dc=com". Which has the added benefit of making a lot of queries easier and faster. You know, LDAP has tree structures just like XML does, but the LDAP query language does not have axes the way XPath has. You would not have been able to leverage the tree structure in LDAP queries anyway. There is no way to formulate "find me all machine objects that have person objects at some level above them where the person is at management level" in term of the LDAP query language. It would be trivial in XPath.

    And that is just before you start to think about missing bulk replication protocols, language variants of attribute values or the internal structure of Netscape aci attributes.

    LDAP is the single worst designed database structure you can come across. It is not "not in normal form", it is the anti-normal, a complete deviation.

  21. Active Directory's little brother ADAM by Anonymous Coward · · Score: 1, Interesting

    If you are running Windows XP or have access to a Windows 2003 Server, download ADAM and give it a openminded look. I think you will find that it works very well for application development. The ADAM/adsiedit utility will allow you to quickly interact and begin development and management of ADAM. Multimaster replication, multiple data partitions on a single server, robust authentication and authorization, scalability and expandability.

    And in the end if you cannot overlook the fact that you must have a copy of Windows XP or 2003 server to run it, at least you will have a good example of something one of you (or a group of you) can copy when developing or improving an open source alternative.