Re: AD/Exchange 2007 provisioning not working
I am zipping a new ISM-IDV image which will be available for download. Here is the list of changes made to the image that should enable AD user provisioning. Please be aware that disabling AD accounts does not work. Our engineers have moved away from login disabled as a global account trigger and I have not yet determined what I will use to replace it.
Entitlements Service Driver
- Remove/Add Accounts Payable Group
- Remove/Add Accounts Receivable Group
- Restart
Modified Active Directory 36 Driver
- GCV | Credential Provisioning | Application Credential ID = ExchangeCred
- GCV | Credential Provisioning | SecureLogin Passphrase Question = What is your employee id?
- GCV | Credential Provisioning | SecureLogin Passphrase Answer Value Attribute = workforceID
- Publisher Input Transformation Policy | Insert lib-CredProv-ProcessPayload-itp-V1.Library.driverset.system
- Filter | User | Add Attribute
- workforceID (employeeID) = Notify on Subscriber/Ignore on Publisher
- OU (department) = Sync on Subscriber/Sync on Publisher
- Publisher Input Transform | Insert existing lib-CredProv-ProcessPayload-itp-V1.Library.driverset.system policy
Modified JDBC HR Driver
- Publisher Command Transform | Insert FixupWFID (attached) to Add NSL Operation Data policy
Modified Credential Provisioning Configuration
- SecureLogin Server SSL Certification Path = /opt/novell/eDirectory/lib/dirxml/classes/RootCert.der
Provisioning Request Updates (Designer)
- Request Sales Mailing List Access | DirXML-Entitlement-Parameter = 9690fab2327c334a8af03bdd6a128641
- Remove from Sales Mailing List | DirXML-Entitlement-Parameter = 9690fab2327c334a8af03bdd6a128641
|