Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Next revision Both sides next revision
tutorial:adm:manage_ldap [2019/08/08 15:11]
poulm
tutorial:adm:manage_ldap [2019/10/07 17:10]
apeterova base contexts - note
Line 18: Line 18:
 Switch on **Use VLV Controls** and set **VLV Sort Attribute** to the same value as **Uid Attribute**. Otherwise, searching of accounts doesn't work well in the current version of LDAP connector (first result is skipped due to a bug). Switch on **Use VLV Controls** and set **VLV Sort Attribute** to the same value as **Uid Attribute**. Otherwise, searching of accounts doesn't work well in the current version of LDAP connector (first result is skipped due to a bug).
 </note> </note>
 +
 +==== Base Contexts ====
 +
 +The property **Base Contexts** contains one or more starting points in the LDAP tree that will be used when searching the tree.
 +
 +When you run synchronization in the reconciliation mode, the connector starts the search for every value in the Base Context separately. The search uses paging, which means that the entries are processed in blocks consisting of (by default) 100 records according to the configured (VLV) sort. Be careful, when you have multiple values in the Base Contexts and you **modify distinguished name** of the entries **during the reconciliation**. If entries are moved to a different base, then other entries may omitted due to the paging and they fall to the **Missing account** state. 
  
 ===== Scheme ===== ===== Scheme =====
Line 67: Line 73:
 You can leave the rest of configuration at the default values. You can leave the rest of configuration at the default values.
  
-//Example provisioning results://+//Example provisioning results:// TODO
  
 +===== Create LDAP role in IdM =====
 To provision an account to LDAP, one must create a role for the system with LDAP provisioning mapping. To provision an account to LDAP, one must create a role for the system with LDAP provisioning mapping.
- +  * Create a role e.g. "LDAP - user" and save it 
 +  * Go to System tab on role detail and add a system LDAP created in this tutorial and save.
  
 +To provision a user to LDAP, assign them a role "LDAP - user". The provisioning will be provided as soon as the role is assigned to the user. The state of the provisioning you can check at the user profile detail at the tab "provisioning".
  • by apeterova