Differences
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
tutorial:adm:manage_ldap [2019/08/08 15:11] poulm |
tutorial:adm:manage_ldap [2019/10/07 17:10] apeterova base contexts - note |
||
---|---|---|---|
Line 18: | Line 18: | ||
Switch on **Use VLV Controls** and set **VLV Sort Attribute** to the same value as **Uid Attribute**. Otherwise, searching of accounts doesn' | Switch on **Use VLV Controls** and set **VLV Sort Attribute** to the same value as **Uid Attribute**. Otherwise, searching of accounts doesn' | ||
</ | </ | ||
+ | |||
+ | ==== Base Contexts ==== | ||
+ | |||
+ | The property **Base Contexts** contains one or more starting points in the LDAP tree that will be used when searching the tree. | ||
+ | |||
+ | When you run synchronization in the reconciliation mode, the connector starts the search for every value in the Base Context separately. The search uses paging, which means that the entries are processed in blocks consisting of (by default) 100 records according to the configured (VLV) sort. Be careful, when you have multiple values in the Base Contexts and you **modify distinguished name** of the entries **during the reconciliation**. If entries are moved to a different base, then other entries may omitted due to the paging and they fall to the **Missing account** state. | ||
===== Scheme ===== | ===== Scheme ===== | ||
Line 67: | Line 73: | ||
You can leave the rest of configuration at the default values. | You can leave the rest of configuration at the default values. | ||
- | //Example provisioning results:// | + | //Example provisioning results:// |
+ | ===== Create LDAP role in IdM ===== | ||
To provision an account to LDAP, one must create a role for the system with LDAP provisioning mapping. | To provision an account to LDAP, one must create a role for the system with LDAP provisioning mapping. | ||
- | + | * Create a role e.g. "LDAP - user" and save it | |
+ | * Go to System tab on role detail and add a system LDAP created in this tutorial and save. | ||
+ | To provision a user to LDAP, assign them a role "LDAP - user". The provisioning will be provided as soon as the role is assigned to the user. The state of the provisioning you can check at the user profile detail at the tab " |