Conditional creation of accounts in a resource - required field not working

Hi,
We want to conditionally create account objects in a resource, based upon whether or not the users account has a non-empty value for a particular atttribute.
To me this seems to be what the 'required' attribute on a field is for, in theory I should be able to tag a field as required, and then if an account dosn't have a value for the attribute, it won't be created on the resource.
The Help, from IDM6.0, says the following:
Required -- If this attribute is required to create an account on the resource,
select the option. This selection applies only when creating accounts.
When I try to do this though, it fails, it goes ahead and creates the account within the resource anyway.
So what did I do wrong, or am I misunderstanding the meaning of this.
To test this, I created 2 XML Resources, Res1, and Res2.
I specified that Res1 had accountId, and email as attributes.
I specified that Res2 had accountId, and email as attributes, but ticked email as required.
I made accountId the idntity template in both cases.
I then created 2 test accounts test1, and test2, but only gave an email address to test1, but assigned both resources to both accounts.
Both resource xml files had both users listed.
For those who care more, the reason we want to do this is that we are running an LDAP with a sendmail tree, and want to populate this via IDM, all our users have email accounts, but not all have email aliases. Therefore, we only need some of the users to have entries that look like this.
sendmailMTAKey=fred.bloggs, ou=sendmail, o=anu.edu.au
sendmailMTAHost=anu.edu.au
sendmailMTAAliasValue=u1234567
sendmailMTAKey=fred.bloggs
sendmailMTAAliasGrouping=aliases
objectClass=sendmailMTA
objectClass=sendmailMTAAlias
objectClass=sendmailMTAAliasObject
objectClass=top
So I guess the question is really 2 things, what am I doing wrong with conditional account creation? Is this the right way to create these entries in the LDAP sendmail tree?

Hi again,
For those who care, I've got a resolution to the specific problem I mentioned in the above post, even if no answer to the general question of conditionally adding accounts on resources.
In this specific case, I had been given a poor description of the requirements of the sendmail schema. It turned out on closer investigation that a single ldap record could hold all the information needed. It seems the sendmai schema had been implemented inefficiently locally, before we looked to run it through IDM.

Similar Messages

  • Debug not showing & required fields not working

    I have MX 7.0.2 Developer's Version installed on W2K and MX
    7.0.2 on W2003 soon to be production server. On my Developer's
    Version the debug output shows up and the required fields using an
    input tag work. The same code on the production server, with the
    same admin settings doesn't show debug output and the required
    fields don't catch that the field is blank. I have read in the
    forum that it is very likely that the /cfide virtual mapping is not
    configured correctly, but not specifically how to fix the problem.
    I see cfide in the admin setting, mappings on the production server
    and have tried turning debug on and off, but still no debug output
    and required fields not catching and not showing validation
    message. Any help would be appreciated.

    Hi Amit,
    Do you mean to say that you are not able to see these settings in SE16 where as other users are able to? If that is the case , there might be an authorization problem for you.
    or try logging off and loginto the system. that should work sometimes. If not try to go to SU53 and check whether your auth has failed to see for this table.
    Regards
    Srini

  • Power view in SharePoint - Required fields not working!!!

    Hi,
    We have SharePoint 2013 and SQL Server 2014 and SSRS in SharePoint integrated mode.
    We have a "Microsoft BI Semantic Model for Power View"-data connection in a document library and by clicking it users can create their own Power View reports.
    We have in the document library defined a couple of columns as required.
    When a user saves their Power View report(File->Save as) to the document library, the required fields are left blank. They are not checked!!!
    WHY?
    Does Power View use REST when saving to the document library?
    This question should be in SQL Server/Power View/SharePoint -forumns, but MSDN forces you to select only one.
    How can we enforce the checking of required columns???

    It might be the result of nested script tags.
    <script type="text/javascript">
    <!--
    <!--
    Remote one of those opening tags and remove the closing tag in between the scripts.
    Also, I'm not sure if you are aware, but your site looks completely broken in Firefox. Edges are ragged and the text runs off the page in places. This is the result of using a graphics program to create your html. Image ready slices are fine for prototyping, but not suitable for production work because they create code that is fragile and too rigid.
    I also would not use the Flash header you have used just to display imges. I suggest using a more accessible method.

  • Required Fields Not Working in LiveCycle Designer 7.0

    Hi, I'm new to LiveCycle Designer and scripting. I have created a 12 page form with "User Entered - Required" fields on the first 11 pages. My problem is that once information is entered in the required fields on page 1, the form is allowing the user to submit without completing the remaining required fields. I am using the "Email Submit" button at the end of my form. Any help would be appreciated.

    Hi Sudhir,
    May be script is not generating.  Can you find the follwoing piece of code in your Submit button click event:
         ContainerFoundation_JS.SendMessageToContainer(event.target, "submit", "", "", "", "");
    Do one thing :
    open your form from Tcode: SFP in change mode.  And on top there is an option called Utilities.
    Under that select "Insert Webdynpro Script".  Activate your form.
    Regards,
    Ravi.D

  • When you install Premiere Pro as the admin on an iMac the audio functionalities work well but a second admin account on the same machine does not work. What can I do to fix this?

    When you install Premiere Pro as the admin on an iMac the audio functionalities work well but a second admin account on the same machine does not work. What can I do to fix this?

    It is a bad idea to hack computer passwords when you don't own the computer
    Good luck with the school and the parents.

  • Condition on CKF (based on replacement type formula Variable) not working

    Hello Friends,
    We have a reporting requirement where in we want to find out vendors who are being paid with the multiple currancies.For this I have created a replacemnent path formula variable with reference to currancy and created a CKF with the help of this variable.
    Now as I want to display only multiple currancies I want a condition to display value > 1 on this CKF but
    this condition is not working as the replacement path variable contains value 1 for every currancy passed to it although it shows in the report for 2 currancies value as 2.
    Can anyone guide us in this matter?
    Thanks,
    Suyog.

    Friends found the Solution so closing this thread....:)

  • Multiple account assignment switching between distribution indicators not working for service

    Hi Gurus,
    Account assignment distribution function not working post ECC6 patching activity
    we have recently completed ECC6 patching actvity and we are facing issues on processing multiple account assignment in service.
    we create Purhcase order with single account assignment and will process service with Multiple account assignment selecting distribution on qty or percentage basis till patching functionality works fine post patching we are facing issue when we are selecting distribution indicator system provides an error message switching between distribution indicator is not allowed when we continue system ask to enter in case of multiple account assignment select the distribution indicator. could you please suggest me on the issue.
    Thanks in advance.

    we have found a SAP note
    1915000 - SE685 - Switching between distribution indicators is not allowed
    This is now standard behavior.

  • Disabled Email Account Sent feature in outlook is not working

    In outlook, is easy to setup one email account just to receive emails. 
    Example:
    Account A receive/send emails
    Account B receive only.
    This is easily setup by configuring the send/receive groups (link: http://smallbusiness.chron.com/remove-send-account-outlook-2012-67137.html)
    But this is not working! I configured account B to receive only and I can send emails using Account B without any problems. Any idea? This is driving me crazy! I tested in 3 different computers with the same results.
    Any ideas?

    When you change the S/R group, you just tell it not to use that account in the group. You need to 1) use a fake SMTP server and 2) set the account in any and all S/R to not send mail (to avoid error messages). I have steps and screenshots for a
    send only POP3 here - use the same method for receive only pop3, with the servers and settings reversed.  
    Diane Poremsky [MVP - Outlook]
    Outlook & Exchange Solutions Center
    Outlook Tips
    Subscribe to Exchange Messaging Outlook weekly newsletter

  • Account Billing with Puerto Rico card not working

    I am trying to purchase on iTunes Store and am getting a message where I should get U.S. based funding- but this is a U.S. based address on both my Billing address, iTunes account and my PayPal account which also does not work.
    I have read through all the instructions, and nothing yet. There are no abbreviations on the address fields wither, so everything should match.  Does anyone have a solution for this? I tried calling support but I was sent back to online support! (?)

    On a side note:
    I've tried to activate it on 4 different computers: XP, win98, Vista, Internet on the Iphone non working.
    In total 5 hours spend on searching on google, browsing these forums for a solution.

  • Impossible to delete POP accounts from iCloud keychain and SMTP not working

    Hello,
    After an aborted Mavericks clean install, I reverted to Mountain Lion via Time Machine and started experimenting with iCloud Keychain on Mavericks using trashable Virtual Machines.
    I am hitting two serious problems with email accounts :
    1. I turned on iCloud keychain ONLY on my Mavericks test installs (not on my iOS device)
    2. First time I turned it on and used my usual AppleID, the test install retrieved all my email accounts (I have many of all types)
    3. I could not make password SMTPS work on any IMAP accounts, so I decided to delete ALL email accounts from my iCloud Keychain
    4. When you ask to delete an email account, it asks if you want to delete it from ALL your accounts, whoch is what I did (make a clean slate)
    5. Of all the accounts I have, I have two old disabled POP3 accounts. I deleted them as every other one (including FB, Twitter, LinkedIN, Exchange, ...)
    Every time I set up a new test install with iCloud keychain enabled, these two POP accounts continue to show up on the list.
    Every time I delete them again from ALL keychains they disappear, but anytime I launch Mail they come back, and if I delete them again, and then I add a new email account they come back.
    No way to delete them from ALL keychains
    And BTW user/password SMTP on SSL for IMAP accounts does not work for me. It fails all the times on my postfix server.
    So, my issues are :
    - iCloud keychains seems unstable with email accounts (probably with POP accounts only)
    - SMTP over SSL with user/password doesn't seem to work
    Anybody hit the issue ? For me is a severe showstopper for Mavericks and iCloud keychains
    Best
    Luca

    Restore it as new.  Why wouldn't you do that when purchasing a used device from another individual?

  • Restrict creation new e-mail accounts on Ipad2 4.3 does not work..

    Hello everybody
    For business use i have to secure the Ipad2. I am using the Iphone configuration utility 3.3 to block some features.
    It´s not possible to block the creation of E-mail accounts with this utility. I found out it is possible to restrict on the Ipad itselve using the restrictions option >General>Restrictions...So i have activated this option.
    However clicking the envelop on the homescreen it´s still possible to bypass and to add an e-mail account for example gmail on the Ipad ?? I was rather suprised this was still working but perhaps i am doing something wrong.
    Do you have any idea what is causing this issue or is it maybe a bug?
    Thanks for your feedback.
    Br. Dirk
    Leiden, The Netherlands

    Hi. Does anyone know the answer to this? I found this out as well, though my hardening requires me to actually seal off email usage.

  • Account lock from password_lock_time - Automatic unlock not working

    Oracle 11g database
    I have created a profile with password_lock_time = .01389 (20/1440), set up a test user, and set the user to the new profile. Then I logged in with an invalid password several times and verified from dba_users that the account_status = LOCKED (TIMED). The problem is that several hours later the account has still not unlocked. Am I missing a step or does 11g not allow a fraction to be used for the lock time?

    PASSWORD_LOCK_TIME can be specified in fraction;
    Tested in 11g and it works:
    BANNER
    Oracle Database 11g Enterprise Edition Release 11.2.0.3.0 - 64bit Production
    PL/SQL Release 11.2.0.3.0 - Production
    CORE 11.2.0.3.0 Production
    TNS for Linux: Version 11.2.0.3.0 - Production
    NLSRTL Version 11.2.0.3.0 - Production
    SQL> create profile test LIMIT FAILED_LOGIN_ATTEMPTS 1
    PASSWORD_LOCK_TIME 0.0034; --------------------------------------------------5 mts
    Profile created.
    SQL> create user dummy identified by dummy profile test;
    User created.
    SQL> grant connect,resource,create session to dummy;
    Grant succeeded.
    [oracle@test ~]$ sqlplus dummy/dummy1
    SQL*Plus: Release 11.2.0.3.0 Production on Fri Sep 28 11:35:24 2012
    Copyright (c) 1982, 2011, Oracle. All rights reserved.
    ERROR:
    ORA-01017: invalid username/password; logon denied
    11:35:31 SQL> select username,ACCOUNT_STATUS from dba_users where username like 'DUMMY';
    USERNAME ACCOUNT_STATUS
    ------------------------------ -------------------------------- ------------------> At 11:35 in locked status
    DUMMY LOCKED(TIMED)
    11:41:09 SQL> /
    USERNAME ACCOUNT_STATUS
    ------------------------------ -------------------------------- ----------------------> At 11:41 in OPEN status
    DUMMY OPEN
    [oracle@test ~]$ sqlplus dummy/dummy
    SQL*Plus: Release 11.2.0.3.0 Production on Fri Sep 28 11:41:21 2012
    Copyright (c) 1982, 2011, Oracle. All rights reserved.
    Connected to:
    Oracle Database 11g Enterprise Edition Release 11.2.0.3.0 - 64bit Production
    With the Partitioning, Automatic Storage Management, OLAP, Data Mining
    and Real Application Testing options
    Edited by: vreddy on Sep 28, 2012 9:45 AM

  • Authorisation of an old account on a new mac, Password not working, no longer have access to that email address, and security question not working. But I do have my mac authorised! ...is there anyway to copy or get authorisation info off it???

    Please help me!!!!
    I have got a new Mac, I am trying to share my itues on it as well as my old mac, I have had two itunes accounts in my life, one is current now (this account) one I have not had access to the email for years. Since I have bought music off both accounts, I wish to play it all on  both my macs. My Old mac has both accounts Authorised fine and all is good.
    My new Mac, I have thios account running fine, but keep getting prompted for the password for my old account, I have no idea what my old password is, I have not had access to that email address for 5 years, and for some strange reason the security question isn't working eaither.
    Since I do still have one Mac where it is Authorised, Is there any file I can copy accross or anyway to get the password out of the OSX 10.6.8 for my old account.
    Secondly, is there anyway to roll both accounts into just my current one.
    Many Thanks in advance for your help.
    Steve

    I too am having this same problem but I have not seen ANY solutions for it. Looks like Apple is ignoring it!!!!!!!!?

  • @Resource annotation does not work for XA resource?

    Okay, sounds absurd that it works for everything except XA, but that is all I have to go with for now. We are moving from EJB2.x to EJB3 and I am encountering an issue when using the @Resource annotation for an XA connection factory. See deployment exception at bottom of post.
    First, I deploy my-aqjms-jms.xml which contains two connection factories (sorry, I do not know the equivalent "pre" tag for this board so all formatting is lost):
    <weblogic-jms>
    <foreign-server name="MY-AQJMS-JMS">
    <foreign-connection-factory name="ForeignConnectionFactory-0">
    <local-jndi-name>my/jms/QCF</local-jndi-name>
    <remote-jndi-name>QueueConnectionFactory</remote-jndi-name>
    </foreign-connection-factory>
    <foreign-connection-factory name="ForeignConnectionFactory-1">
    <local-jndi-name>my/jms/XAQCF</local-jndi-name>
    <remote-jndi-name>XAQueueConnectionFactory</remote-jndi-name>
    </foreign-connection-factory>
    <initial-context-factory>oracle.jms.AQjmsInitialContextFactory</initial-context-factory>
    <jndi-property>
    </jndi-property>
    </foreign-server>
    </weblogic-jms>
    Next, I look at my ejb-jar.xml:
    <session>
    <description>My EJB</description>
    <ejb-name>MyEJB</ejb-name>
    <ejb-class>demo.MyEJB</ejb-class>
    <session-type>Stateless</session-type>
    <transaction-type>Container</transaction-type>
    <resource-ref>
    <description>connection factory</description>
    <res-ref-name>jms/myQCF</res-ref-name>
    <res-type>javax.jms.QueueConnectionFactory</res-type>
    <res-auth>Container</res-auth>
    <res-sharing-scope>Shareable</res-sharing-scope>
    </resource-ref>
    <resource-ref>
    <res-ref-name>jms/myXAQCF</res-ref-name>
    <res-type>javax.jms.XAQueueConnectionFactory</res-type>
    <res-auth>Container</res-auth>
    <res-sharing-scope>Shareable</res-sharing-scope>
    </resource-ref>
    </session>
    These are the resource tags I want to move into annotations. (There are matching tags in weblogic-ejb-jar.xml which map "jms/myQCF" to "my/jms/QCF" and same for XAQCF). So, I open demo.MyEJB and add the annotation for the first one:
    @Stateless(name="MyEJB")
    @Resources({
    @Resource(description="connection factory",
    name="jms/myQCF",
    type=javax.jms.QueueConnectionFactory.class,
    authenticationType=Resource.AuthenticationType.CONTAINER,
    shareable=true,
    mappedName = "my/jms/QCF"),
    I remove the resource-ref tag for "jms/myQCF" in ejb-jar and weblogic-ejb-jar.xml but keep the one for "jms/myXAQCF", re-compile, re-package, re-deploy, and test. Everything seems to work fine. So, I open demo.MyEJB and add the annotation for the second connection factory:
    @Resource(description="XA connection factory",
    name="jms/myXAQCF",
    type=javax.jms.XAQueueConnectionFactory.class,
    authenticationType=Resource.AuthenticationType.CONTAINER,
    shareable=true,
    mappedName="my/jms/XAQCF"),
    I also remove the resource-ref tag for "jms/myXAQCF" in both *ejb-jar.xml's.  But now when I try to redeploy, I get the following exception:
    [EJB:011026]The EJB container failed while creating the java:/comp/env namespace for this EJB deployment.
    weblogic.deployment.EnvironmentException: [EJB:010176]The resource-env-ref 'jms/myXAQCF' declared in the ejb-jar.xml descriptor or annotation has no JNDI name mapped to it. The resource-ref must be mapped to a JNDI name using the resource-description element of the weblogic-ejb-jar.xml descriptor or corresponding annotation.
    If I comment the XAQCF annotation it will deploy again. I have since done the same annotation replacement for jms queues and jdbc resources. However, only this one XA connection factory is giving me trouble. Is this an issue in weblogic or is there something I am missing from the annotation?
    Thanks!

    Look like a bug in Appserver. XAResourceWrapper is
    used only for debugging. May be you want to reducethe
    log level to INFO and try it.Yeah, that worked.
    But this is a bug in the app server because a switch
    in the log level shouldn't influence transaction
    behavior.Yes. There is a bug when log level in FINEST. All other log levels should be fine. Please see the bug report at
    http://developer.java.sun.com/developer/bugParade/bugs/4973434.html
    >
    The only big issue I still have is that recovery
    doesn't work. See my other message in this forum. Do
    you have a solution for this?I have asked someone who knows that area well to answer your query.
    - Binod
    >
    -- Andreas

  • Default account setting in Outlook 2010 does not work when composing new messages?

    Hello,
    I am currently using Outlook 2010 (not beta). I have two accounts, a google imap account and a pop3 account.  I have designated my IMAP account as my default account.  As I understand it, this means that when I create a new email,
    it should default to being sent from my IMAP account.  However, whenever I create a new email, it defaults to the account which I am currently viewing in Outlook.  In other words, if I am currently viewing the pop3 inbox, when I compose an email,
    it will default send from that account.  Conversely, when I compose an email while viewing the IMAP inbox, it will default send from that account. 
    Any ideas as to what is going on?  This is rather frustrating because I only rarely send with my pop3 account--only when replying/forwarding email received with that account or other unique situations.  Is there a way to make Outlook be true to
    sending from the default account, without doing something drastic like disabling the secondary account?
    Thanks in advance.
    Rom

    Of course it's a bug.
    Computing Dictionary
    bug definition
    programming 
     An unwanted and unintended property of a program or piece ofhardware, especially one that causes it to malfunction.
    The behaviour itself may be considered a feature by Microsoft, though I disagree, but the fact that one thinks one is specifying a "default" account that is not then used as the default in all cases is clearly a bug.
    It is astonishing to me that in the plethora of options, advanced options and advanced advanced options there is not a checkbox to enable this new behaviour with the default being unchecked.
    Microsoft does it again.

Maybe you are looking for

  • Up and down brightness

    Thanks to anyone who can help. I have an iMac slot loading 2001. 600mhz, 40GB harddrive, 128 mbs ram, system 9.2.2 US After being on for a half hour the monitor brightness goes up and down like once or twice a second. On top of that it goes slowly di

  • Icons for both Logic 9.2.0. and 9.1.1.

    When I upgraded to Logic Pro 9.2.0., it created a new icon for 9.2.0., as opposed to updating the previous version of Logic. This left me with two Logic Pro icons. Now that I have upgraded to 9.1.1., my original Logic Pro is updated, and the Logic Pr

  • Role of LDAP server in portal

    HI Can any one tell me what is the role of LDAP server in portal Thanks shashank

  • You are not licensed for TA Adapter. Service disabled.,

    we had error message like TIDAL Log shows " You are licensed to connect the client" to run the TIDAL batch job it's failing. 4375678,09/03/2014 03:15 AM,Audit,You are not licensed for WebService Adapter. Service disabled.,Client,,,,,1000,ENAW-VXD21P,

  • Why doesn't even freshly & cleanly installed Firefox allow MS Silverlight to run, while other browsers will?

    I've tried uninstalling, including all personal information, etc., then reinstalling without any importing of external data-- in other words, a very fresh and clean installation. Still, I can't get Silverlight to run at the Fidelity site. Internet Ex