Symantec IGA

Expand all | Collapse all

Can't read values from Oracle LDAP Endpoint.

  • 1.  Can't read values from Oracle LDAP Endpoint.

    Posted 02-09-2017 09:42 AM

    We created a LDAP connector (Connector Xpress > JNDI "common" template) to connect a Oracle LDAP Directory as endpoint, but not all User Account Attributes can be read from IAM, while they are read from a LDAP browser using same credentials.
    We added structural and auxiliary classes, specific to the endpoint, in User Account Attributes configuration in ConnectorXpress.
    Many User Account attributes are from "structural" and "auxiliary" classes.
    After the process of creating the project, the endpoint type, the endpoint, importing the roles definitios to the environment, executing explore&correlate, adding fields to IAM task "View Oracle LDAP User Account", we can't get the values shown on the view page.
    In particular, we CAN get/read the values from the fields with"standard" classes (e.g. iNetOrgPerson"), but CAN'T get/read the values from added specific classes. Anyone can help? Thank you.



  • 2.  Re: Can't read values from Oracle LDAP Endpoint.

    Broadcom Employee
    Posted 02-09-2017 09:52 AM

    Can you please share the screenshot. I think you need to check the checkbox where objectclasss names are shown and by default they are not selected.

     

    Regards,

    Sumeet

     



  • 3.  Re: Can't read values from Oracle LDAP Endpoint.

    Posted 02-09-2017 10:04 AM

    Can't find checkboxes, where should i look for? I share two screenshots with objectclasses infos.  Thanks.







  • 4.  Re: Can't read values from Oracle LDAP Endpoint.

    Broadcom Employee
    Posted 02-09-2017 10:26 AM

    Hi,

     

    'IAM task "View Oracle LDAP User Account", we can't get the values shown on the view page'.. Are you referring to IM Screen? The screen where user account attributes are shown? Please share screenshot of this screen. Or you can also share screen for default Oracle endpoint Account Template.

     

    Regards,

    Sumeet

     



  • 5.  Re: Can't read values from Oracle LDAP Endpoint.

    Broadcom Employee
    Posted 02-13-2017 07:41 AM

    Hello. I am helping customer with this problem. We observe this issue directly in Provisioning manager

    On the Connector Xpress, these fields seem correctly mapped but after an explore they don't appear on the Provisioning Manager. I attach screenshot about a field (Master AD Username) that  is populated for all users and does not appear on Provisioning Manager.

    Provisioning Manager ScreenShot

    Connector xPress Account Screen



  • 6.  Re: Can't read values from Oracle LDAP Endpoint.

    Broadcom Employee
    Posted 02-14-2017 06:26 AM

    Hello
    Maybe we found the problem.
    When customer add attributes from a custom class, Metadata are written in wrong way
    Before the attribute,  connector xpress put the Object Class name. Example. We see in new endpoint Metadata
    "inetOrgPersonCoin:masteradusername" instead of the correct form
    "masteradusername"

    Once corrected manually,  it works
    I suspect there is a bug in the connector xpress interface that add the object class to the attribute

    Thank you
    Giovanni