What kind of load will PaperCut put on my directory server?
Last modified on 12 August 2020 11:43 PM
PaperCut makes use of directory servers such as Active Directory, eDirectory, Open Directory and other LDAP and similar systems to retrieve information about users and groups. This enables single entry of your user and group information and efficient re-use of your existing IT infrastructure for printing purposes. It is common for PaperCut to deployed on sites with domains containing hundreds of thousands of users.
The following sections cover the different kinds of requests PaperCut makes to directory servers, and how they are handled efficiently.
The number of groups in a domain can vary significantly - from several to several hundred thousand. Rather than track all groups in the domain, PaperCut asks the administrator which groups are relevant to printing and tracks only those. When the administrator is selecting a group PaperCut will fetch a list of all groups in the domain. Once the relevant groups are selected PaperCut can simply use its internal (cached) list of groups and does not need to fetch them from the domain.
Group memberships are used to determine things like access control, print quota entitlements and reporting.
Many of the operations outlined above, such as reporting, can occur at any time of the day. Group membership lookups can be quite intensive as there can be many users in a group and for this reason group membership is cached locally in the PaperCut database. Although relatively static in most organizations, group memberships can change, such as a student being added to a group when they become a teacher assistant so as to gain additional printing privileges, and for this reason group membership is regularly updated.
Group membership information is fetched:
Group Membership Sync in Detail
Fetching group membership information involves one or more calls per group that has been added to PaperCut (with LDAP the results are batched into groups of 500, so groups with more members than this will take multiple calls to complete). The queries to fetch group memberships are performed with best practise AD/LDAP searches and batching behavior to minimize network round-trips, connection overhead and server load. The same LDAP practises are used across all LDAP directory server types include eDirectory and Open Directory.
This category includes several user-specific fields such as full name, email address, office and department.
Similarly to group membership, this information is used in reporting and is relatively static. For this reason PaperCut will cache user details in its database and also regularly update them from the user directory. The same efficient sync and caching behavior used for group memberships updates are used here.
User details are fetched:
User authentications can including logging into the user or admin web interfaces, logging into a release station or MFP, or authenticating a print job (pop-up authentication). In line with industry best practise PaperCut never caches passwords, and authentication is performed via the directory server in realtime.
PaperCut will make realtime calls to the user directory to perform user authentication. The technologies used are: