LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 20-Oct-2009, 03:00 PM
Junior Member
 
Join Date: Apr 2009
Posts: 4
morganginga 0 reputation points
Default AD destination modify question

I have some strange behavior with an Active Directory driver. We do not
directly synchronize groups from eDir to AD due to stale/dirty data (we
don't want all the members in the equivalent eDir group coming into AD). I
created a rule to manually add a user to the AD Employees group if they are
a member of the eDir Employees group (I have attached an export of this
policy).

When I user is first created in AD the policy works wonderfully and the user
is added to each group that they are currently in on the eDirectory
equivalent. My problem comes when a user is added to a group after they
already exist in AD. I do not directly map the Group Membership eDir
attribute anywhere in AD, but I set the Subscriber channel to synchronize
for that attribute so that it would register when the attribute is modified
in eDirectory (at one point I even had my actions executing only if
Operational Attribute Group Membership is changing). This allows the driver
to register that a change has occured. The conditions are evaluated (the
user is a member of the group in eDir) and it kicks off the same action as
it did when a user is first created (add them to the AD group).

The problem is that, based on what I'm seeing in the trace (attached), it's
not seeing the destination side values of anything for the user in question.
When it tries to add the destinationDN attribute to the AD group attribute
member, it is empty. I changed it around several times to try to retrieve
destination information (pull destination attribute CN for example) and
everytime it comes back empty. I don't understand why it's not seeing the
destination side of things (AD) for this change, but it can execute the same
rule and get the values it needs when the user is first created.

Any help is appreciated.

-Morgan






Attached Files:
File Type: xml Groups10-19.xml (3.6 KB, 3 views)
File Type: rtf Trace.rtf (301.5 KB, 5 views)
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -6. The time now is 04:36 AM.


© 2007 Novell, Inc. All Rights Reserved.

Search Engine Friendly URLs by vBSEO 3.3.0 RC2