No, OpenLDAP is NOT "just as good" or any of that jazz. I'm not saying AD is the One True Way(tm) but it is good and there's a reason a lot of companies like it.
This has nothing to do with the post but I can't stand it when people say stupid $h17 like this. ahhhh, do you know what active directory is under the covers? The reason companies like AD is so idiots like you can actually implement and administer it. I would give you a hint to find out what AD is based on but i figured even a hint wouldn't help you with just a bold general statement like you just said there. Unless you are using it for windows login, ldap really doesn't need be used for alot of things and gets applied in some very bad ways. That is saying ibm's tiviol directory server (ITDS) is in the same boat as AD, building on top of open source doesn't actually make it better than the open source part that you ripped, it just means some some ass hat that made the decision to go with Active Directory just didn't know what he was getting or how to run an ldap instance. Before you say bs, I have installed, ran, and had to program to all three(ITDS, AD, and OpenLDAP) and OpenLDAP is the only solution (if i was making the decision) to use. AD is easier because its confined in a nice little box that you have to use their way with predefined schema objects to make a bad admin's life easier that went to ITT tech for 10 months rather than actually understand how a computer works. -Pete
The first rule of intelligent tinkering is to save all the parts. -- Paul Erlich