Symantec IGA

 View Only
  • 1.  CA Identity Manager Provisioning server integration as primary and secondary

    Posted Nov 23, 2020 07:11 AM

    Hi,

    Can we have integration as primary and secondary between 2 set of CA Identity manager with Provisioning server each connected to different endpoints (Active Directory) ?

     Please let me know if any options available for the above.

    Thank you,
    Regards,

    Samarendra Routray
    email:- samarendra.java@gmail.com



  • 2.  RE: CA Identity Manager Provisioning server integration as primary and secondary

    Broadcom Employee
    Posted Nov 23, 2020 08:03 AM
    I am not too clear on what you are asking.

    The two IM Servers would be parts of a cluster. The two Provisioning Servers would have replication in the Provisioning Repository (Directory) layer so the AD endpoint managed would be the same.


  • 3.  RE: CA Identity Manager Provisioning server integration as primary and secondary

    Posted Nov 24, 2020 04:12 AM

    We have two different domains in different network.
    For each domain, we pare planning one identity manager with provisioning server with the endpoint connected to the identity management system. 
    So here we have 2 identity management system connected with their endpoints in different domain and different network.

    Here we look for integration between both of the identity management system, where one as primary and another as secondary. Please let us know the possibility.

    Thank you,
    Samarendra Routray




  • 4.  RE: CA Identity Manager Provisioning server integration as primary and secondary

    Broadcom Employee
    Posted Nov 24, 2020 02:34 AM
    Are you trying to connect a single Identity Manager server to 2 separate / independent Provisioning Servers (no replication between them)? - this is not an available option.
    If you need to separate Active Directory endpoint management you might choose to dedicate different connectors servers to each endpoint.
    But as Kenny stated, this requirement is not too clear.
    Regards
    Rinat


  • 5.  RE: CA Identity Manager Provisioning server integration as primary and secondary

    Posted Nov 24, 2020 04:13 AM
    We have two different domains in different network.
    For each domain, we pare planning one identity manager with provisioning server with the endpoint connected to the identity management system.
    So here we have 2 identity management system connected with their endpoints in different domain and different network.

    Here we look for integration between both of the identity management system, where one as primary and another as secondary. Please let us know the possibility.

    Thank you,
    Samarendra Routray


  • 6.  RE: CA Identity Manager Provisioning server integration as primary and secondary

    Broadcom Employee
    Posted Nov 24, 2020 08:52 AM
    It is still not clear to me. 

    If there are multiple IM Servers that share the same database and IME then they all need to be part of a cluster.

    If there are multiple IMEs they cannot point at the same userstore or Provisioning Server.

    If there are multiple Provisioning Servers that share the same Provisioning Repository Directory they will contain the same acquired endpoints and point to a single IME.

    If we are talking about two completely separate stacks where IM_1 has Provisioning_1 with Endpoint_1 and IM_2 has Provisioning_2 with Endpoint_2 and these IM Servers are not a cluster and not shared the database or userstore and these Provisioning Servers are not sharing Repository Directory then they would not be called primary and secondary as they are completely separated. And if that is the case and you wanted work triggered on IM_2 stack by the IM_1 stack then you would need to look at maybe a PX Policy sending SOAP calls (i.e. TEWS requests) over to the IM_2 stack from the IM_1 stack.


  • 7.  RE: CA Identity Manager Provisioning server integration as primary and secondary

    Posted Nov 30, 2020 06:23 AM
    Thank you Kenneth and Rinat, my question has been answered.

    Kind Regards,
    Samarendra