Provisioning to OUD using the OIM connector for OUD

OIM provides an extensive list of connectors, including a connector to Oracle Unified Directory (OUD). OIM Connector for OUD is described at http://docs.oracle.com/cd/E22999_01/doc.111/e28603/toc.htm

The Lookup.LDAP.UM.ProvAttrMap lookup definition maps process form fields with OUD target system attributes. This lookup definition is used for performing user provisioning operations.

For the default user fields that you can specify or modify values during provisioning operations , see Section 1.9.2.2, "User Fields for Provisioning an OUD Target System."

For example, the Process Form Field "Common Name" is mapped on cn on the OUD side.

Some specific Process Form Fields are mapped differently. For instance the "Login Disabled" Process Form Field is mapped to the __ENABLED__ keyword in the default mapping file. __ENABLED__ does not directly correspond to any OUD attribute. It is a keyword that is associated with an effective OUD attribute in the OUD Connector configuration, as described in http://docs.oracle.com/cd/E22999_01/doc.111/e28603/deploy_oud.htm#CEGDHHHH. The OUD attribute used to store account state is specified  by the enabledAttribute. By default, it is set to ds-pwp-account-disabled.

The same indirection mechanism apply to the NsuniqueID and Password Process Form Fields mapped to __UID__ and __PASSWORD__ that are provisionned to the OUD attributes defined by uidAttribute and passwordAttribute (entryUUID and userPassword by default).



Comments:

Can the OIM OUD Connector intercet OUD password changes?

Posted by Eli Kleinman on May 01, 2014 at 03:58 PM CEST #

Technically, the connector could detect password changes from the OUD change log however it would have access to the encoded password form, not the plain text password, so it is not possible to update the OIM DB with it.

Posted by Sylvain Duloutre on May 12, 2014 at 04:33 PM CEST #

Thanks for the reply,
We are looking for a replacement of the ISW functionality using a plugin in ODSEE to get password changes, we would hope to get the same functionality in OIM + OUD.

Thnaks,
Eli

Posted by Eli Kleinman on May 12, 2014 at 04:57 PM CEST #

Post a Comment:
  • HTML Syntax: NOT allowed
About


I am Sylvain Duloutre, I work as a Software Architect in the Oracle Directory Integration Team, the customer-facing part of Directory Services & Identity Management Product Development, working on Technical Field Enablement.

The views expressed on this blog are my own and do not necessarily reflect the views of Oracle.

Search

Archives
« May 2015
SunMonTueWedThuFriSat
     
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
20
21
22
23
24
25
26
27
28
29
30
31
      
Today