DSEE and Directory Synchronizer Question

I'm investigating using Directory Synchronizer to sync up our DSEE 6.x directory with AD.
We do not have our directory set up to where users can change their password directly. They must go to the authoritative source (our web portal) and change their password there, then have it synced out to DSEE. We are using SSHA passwords for this, but also have a SHA-1 hash of the password.
So, how will Directory Synchronizer be able to get passwords into AD? I don't think AD uses or recognizes this password format, does it?

http://docs.sun.com/app/docs/doc/819-0993/gbfza?l=Ja&a=view should help you.

Similar Messages

  • Import and directory synchronize problem

    I'm having a problem importing new pictures into an existing file directory which appears in my Lightroom catalog. The photos import normally but show up as a new directory entry off the root of the Lightroom catalog. When I attempt to move/drag them to the existing Lightroom directory I want, I'm told they can NOT be move because they are already there which I can confirm in the Windows file system. Strangely, synchronizing the directory in Lightroom does not find the files even though they are physically there but not showing up in the catalog.  This is a new problem but I can't associate it with anything I've changed in Lightroom lately.  Can anyone suggest what might be going on and more important how to fix it?  It is very irritating. I have another problem and I don’t know if it is related or not.  Lightroom will NOT remember changes I make to calalog location I make through the edit, calalog settings menu or my watch directory for auto import through file, auto import, auto import settings.  It just ignores them and uses what is already there. Again, any suggestions would be greatly appreciated.

    The idle-timeout on DSEE was set to none, which I believe is the default. I tried setting it to 1200 and 2400 seconds without success.
    h3. get-ldap-data-source-pool-prop
    <pre>
    client-affinity-bind-dn-filters : any
    client-affinity-criteria : connection
    client-affinity-ip-address-filters : any
    client-affinity-policy : write-affinity-after-write
    client-affinity-timeout : 20s
    description : -
    enable-client-affinity : false
    load-balancing-algorithm : proportional
    minimum-total-weight : 100
    proportion : 100
    sample-size : 100
    </pre>
    h3. get-ldap-data-source-prop
    <pre>
    bind-dn : none
    bind-pwd : none
    client-cred-mode : use-client-identity
    connect-timeout : 10s
    description : -
    down-monitoring-interval : inherited
    is-enabled : true
    is-read-only : false
    ldap-address : localhost
    ldap-port : ldap
    ldaps-port : ldaps
    monitoring-bind-dn : none
    monitoring-bind-pwd : none
    monitoring-bind-timeout : 5s
    monitoring-entry-dn : ""
    monitoring-entry-timeout : 5s
    monitoring-inactivity-timeout : 2m
    monitoring-interval : 30s
    monitoring-mode : proactive
    monitoring-retry-count : 3
    monitoring-search-filter : (objectClass=*)
    monitoring-search-scope : base
    num-bind-incr : 10
    num-bind-init : 2
    num-bind-limit : 1024
    num-read-incr : 10
    num-read-init : 2
    num-read-limit : 1024
    num-write-incr : 10
    num-write-init : 2
    num-write-limit : 1024
    proxied-auth-use-v1 : false
    ssl-policy : never
    use-read-connections-for-writes : false
    use-tcp-keep-alive : true
    use-tcp-no-delay : true
    </pre>

  • Oracle Login and directory oraarch question ?

    Hi,
    I installed ERP 2004 IDES.
    1. What is the default login name and password for oracle using Oracle Enterprise manager ?
    2. How can I clear the directory "oraarch" ? The size is already more than 8 G ?
    3. Can I stop oracle write to this directory ? Any impact ?
    Thanks
    Wilson

    Hi Wilson,
    1. Normally you should logon with your OPS$ user like OPS$ORA<SID> . default password for user "sys" is change_on_install and for user "system" - "manager".
    During IDES installation you had to change them though.
    2. Your archive logs are located in the "oraarch" directory. If you want to clear the directory, you'll have to backup logs (e.g. via brarchive with -sd option)
    3. To stop filling the directory you can deactivate database logging by running "alter database noarchivelog" via SQLplus. However, i would consider this option only if your system is only for solely training/test purposes and you have full DB backup which can be restored in case of hardware/software failures. Without logs you will be unable to restore your DB to the last commited transaction.
    Regards,
    Mike

  • User list synchronization and Unique userid questions

    I am new to Oracle portal and LDAP and learning more and more about Portal every day.
    Hi
    I am using Oracle 9iAS portal 3.0.9 version. I have a requirement to integrate 3rd party LDAP with Oracle Portal Single Sign On. I have white paper on Configuring Oracle9iAS Portal for LDAP authentication. I have following questions
    Paragraph from white paper (Background information):
    When using LDAP authentication or any other external repository, for that matter- the list of users for authentication is held on the external repository. However, there is also a list of users held on the Login server, which is used to associate privileges to the user. Ideally, this list is maintained transparently and automatically. In fact, if a user account is created on LDAP and a user attempts to log in, the login will succeed, and an entry is automatically created on the login server for that user, after a successful login.
    Questions:
    1.     What privileges user will be granted when synchronization process create new portal user on login server automatically?
    2.     Is it possible to customize whatever default privileges new portal user gets? If yes, how? Please provide some forum link or documentation or example.
    Unique user Id scenario.
    Our LDAP repository is setup for customers from different companies. We have requirement to integrate LDAP users with Oracle 9iAS portal 3.0.9 Single Sign On. I have two userid with same name on the LDAP from different company. For example userid jsmith from company A and jsmith from company B. Both user id do not exist on Portal Login Server. Both userids will be created automatically in Login server when LDAP and Portal synchronize user list.
    1.     How oracle portal will handle such scenario when portal requires unique userid?
    2.     Can I customize portal login screen? For example when they login they can provide userid, passwd and domain name. Where domain name could be company name.
    Let me know if you need more information. Feel free to send direct e-mail also.

    Dumlu,
    For 1, you can have the user removed from OUL in OOB scenarios, but behind IP phones it's difficult since we won't know when the PC is offline from there. Only way to know that is when CAM receives a MAC-Notification of a new MAC address being learnt. In IB, you can use heartbeat timers to log them out
    For 2, when a new MAC address is seen on the port, the MAC-Notification is sent out, and depending on your port profile the switchport will change or not. Check your port profile settings for more details on how you have it setup.
    HTH,
    Faisal

  • Active Directory synchronization working, authentication not on CUBM BE5000 8.6(1a)

    I successfully set up Active Directory synchronization between my CUCM BE5000 appliance running 8.6(1a) and our Windows 2008 Server Active Directory.  Users are replicating successfully, but authentication is not working even though I am using the same LDAP manager distinguished name and password for both.  I have a suspicion to the cause of this problem but for the record, the following is my relevant configuration:
    System/LDAP/LDAP System:
    LDAP Server Type Microsoft Active Directory iPlanet or Sun ONE LDAP Server OpenLDAP Microsoft Active Directory Application Mode
    LDAP Attribute for User ID userPrincipalName sAMAccountName mail employeeNumber telephoneNumber
    LDAP Server Type: Microsoft Active Directory
    LDAP Attribute for User ID: userPrincipalName
    System/LDAP/LDAP Directory:
    LDAP Configuration Name: bgctnv.local
    LDAP Manager Distinguished Name: CN=cm.sync,OU=BGCTNV Users,DC=bgctnv,DC=local
    LDAP User Search Base: DC=bgctnv,DC=local
    LDAP Server Information: bgctnv.local, port 389 (to query any domain controller in DNS; I have also tried specific IP addresses)
    System/LDAP/LDAP Authentication:
    LDAP Manager Distinguished Name: CN=cm.sync,OU=BGCTNV Users,DC=bgctnv,DC=local
    LDAP User Search Base: LDAP user search base is formed using the User ID information (pre-populated, I cannot change this)
    LDAP Server Information: bgctnv.local, port 3268
    All of my Active Directory users are now populated and active under End Users.  However, I am not able to log into /ccmuser among other things using my valid domain credentials.  I am a super user as well as a standard end user.
    Curiously, invalid usernames (userPrincipalName in my case) return the error "Log on failed - Invalid User ID or Password" while a valid username, with or without the correct password, returns only "Log on failed."  That seems to imply that some part of the authentication or LDAP bind is taking place.
    Here's the catch.  The base domain here is bgctnv.local while we use bgctnv.org as a valid and acceptable alternative UPN suffix in Active Directory.  Every Microsoft and every third-party program I have used will accept [email protected], but I'm beginning to think that CM will not, or is having some sort of translation issue.  I read that alternative suffixes can cause problems in Active Directory forests with multiple trees, but this is a vanilla, single domain environment.
    I don't even know where to look to debug this issue.  Has anyone seen this before or can anyone tell me where to look for logs?
    Thanks,
    John

    I found the following:
    http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/srnd/8x/directry.html
    As mentioned in the section on LDAP Synchronization, in order to support synchronization with an AD forest that has multiple trees, the UserPrincipalName (UPN) attribute must be used as the user ID within Unified CM. When the user ID is the UPN, the LDAP authentication configuration page within Unified CM Administration does not allow you to enter the LDAP Search Base field, but instead it displays the note, "LDAP user search base is formed using userid information."
    This may help in some situations where there are multiple trees in an AD forest, but it is definitely not the solution.  Even with multiple trees, it is common to use alternative UPN suffixes.  Nothing in AD requires or even recommends that you exclusively use your AD domain root as the UPN suffix.
    For example, company.local may use company.com as an alternative but primary UPN suffix to provide simplicity for users.  Users can then achieve more broad SSO capabilities by using their familiar email credentials when authenticating for company.local services.
    When using UserPrincipalName as the LDAP synchronization attribute for the CM User ID, the configuration requires that the search base for authentication be derived from the UPN suffix, regardless of whether it is a single domain or multiple trees within a forest.  This makes it impossible to authenticate by UPN unless your UPN is explicitly your root domain name.  From the example above, CM would try to bind [email protected] against DC=company,DC=com instead of the correct DC=company,DC=local.
    The logical solution would be to allow the administrator the option.  Why not have a choice of whether to generate the user search base from the userid (UPN) information, or be able to specify the search base as well like it allows with any other synchronization attribute?
    Would this be a feature request, bug report, or neither?  I'd really appreciate it if Cisco considered this but I don't know the proper channel.

  • Dynamic File Name and Directory File Sender Adapter

    Hello gurus,
    I have a question: Is there any way to make the File Name, and Directory Dynamic of a File Sender Communication Channel ?
    For example, taking it as a parameter from a Web Service Request.. (I mean, the only way with this would be a ccBPM). I don't exactly know if there is a way, I just thought about this.
    Please tell me if someone could make Dynamic these 2 parameters while picking a file.
    Regards,
      Juan

    oops,thought i was replying to the PgP question:)
    I think you should be able to achieve this via adapter module but i m not really sure how exactly it will be done .
    Thanks
    Aamir
    Edited by: Aamir Suhail on Jul 28, 2009 1:42 PM

  • LiveCycle and AD three questions.

    I have three Javascript questions. 
    1)     How would I go about finding the current domains which user is authenticated to.  What I need to do is have a form that can only be used while in certain domain.
    2)     Would also like a way of populating a forms value based on the current logged in user of the system (active directory.)
    3)      Am also looking from information on how I could use an existing AD account to sign a form, basically creating a maintaining a digital signature for user that is password synced to their existing AD account.  Allowing them to ‘sign’ the form by entering their AD credentials.    Realizing this is a complex subject I have been searching Adobe Tech support for a place to start and as yet being unsuccessful. 
    Thanks!

    I can get the process forms, but not following steps 3-4.  Please
    elaborate
    $Nith$ <[email protected]>
    09/18/2009 17:29
    Please respond to
    [email protected]
    To
    Thomas Beaty <[email protected]>
    cc
    Subject
    LiveCycle and AD three questions.
    i have one solution for your second question.
    1. Drag the process fields(from custom library) to the form
    2. A field named AWS_ASSIGNED_ID will be in invisible mode.
    3. The field will hold the currently loged in users's AD id (the column
    name is refprincipalid) in the Adobe table
    4. use this table to get all details of a user from edcPrincipal table.
    If unclear, i'm ready to make it elaborate for you.
    Nith

  • OAM and Directory Server Interaction

    I am in the middle of continued fact finding for implementing OAM. One question that has come up is how does OAM use the directory server it is configured to connect to. We would like to use AD as our authentication source but the word is Hell No if OAM is going to try to write data back into the directory server or store data in the directory server as our AD Admins are mandating that OAM will only be given read only, normal user level rights even if it requires write privileges and directory admin rights to function. I have search the manuals and have yet to find a really good explanation of how it works and uses the Database Schema and Directory Server. I suspect it is read only but I need to know ahead of time so I can make everyone aware that were going to have to run multiple directory systems due to the imposed limitation on AD access.

    Anybody??? I really need help with this....

  • SAP HCM/Active Directory synchronization

    Hi,
    I am trying to integrate SAP R/3 (master database) to Active Directory.
    And Active Directory will be used by rest all systems.Adding of new employee is done at SAP HCM and the same data should be created in Active Directory.
    I went through couple of forum threads but did not get the solution,
    Integrating SAP HR and active directory services
    LDAP/Active Directory synchronization
    http://forums.sdn.sap.com/click.jspa?searchID=47039448&messageID=7577288
    Please le me know how can achieve this.Your help is greatly appreciated...
    Regards,
    Rudradev Devulapelli

    It is a tool for user data synchronization, provisioning, compliance etc. It is an Java application so it is installed on AS Java.
    I have played with it only for a few days and I was able to use it to synchronize some data from AD and ERP. So I guess your scenario would be something like this:
    - HR adds new employee,
    - IDM synchronizes data between HCM and AD ie. it creates new user in AD,
    - user uses AD to authenticate to access, for example, file share.
    But IDM can do a lot of things besides this simple example. So I suggest you to go through "Technical Overview Presentation":
    http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/7037d982-40aa-2a10-e283-a76a9dfc93ab
    and "Working with Microsoft Active Directory":
    http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/40bba5aa-50f7-2a10-739d-e48e40730478

  • Can I delete Directory app and Directory Utility?

    Not sure this is the right forum for my question but in reading through some of the posts it seems like people here would know the answer. Can I delete the Directory app and Directory Utility from my machine, since I am not running a server or anything that would utilize those apps? I use my machine at home only, and have never had any need for those apps, seemingly. I am using Leopard 10.5.5. Thanks for input on this.

    Can I delete the Directory app and Directory Utility from my machine ?
    You can delete them, but why?
    Other than the few megabytes of disk space they take up, what do you expect to gain by doing so?

  • An interesting synchronization question

    hey all, I have an interesting synchronization question to ask you.
    Suppose that I have 20 tasks and 8 worker threads, each worker is assigned a task by the main thread, and then main thread suspends until one worker has finished its task. Then main thread create another task and handles to a new worker thread until all tasks are finished.
    so code in main thread is something like this.
    boolean has_more_task, has_more_worker;
    do {
                  if (has_more_task && has_more_worker)
                               *  create new thread and assign it a new task
                  else if ( has_more_task && !has_more_worker)
                            wait();
                   else if ( !has_more_task && has_more_worker)
                              wait();
    } while (has_more_task || has_more_worker)the problem is that I don't quite familiar with synchronized key word. so I don't know how to share a synchronized vaiable between main thread and worker thread. can anybody do me a help?
    Remember that main thread should be waken up by either of the 8 worker threads !!

    you can follow producer consumer conept
    create a queue. main thread will push task in queue.
    and worker threads will consumer task from queue.
    you just need to synchronize operation on queue.
    when there is no task in queue then worker thread will notify to main thread and
    will call wait().
    then main thread again put the more task in queue and send notification signal to worker thread and then call wait().
    Class JobQueue
    //should be called by worker thread
    public synchronized getNextTask()
    //shoule be invoked by main thread
    public synchronized addMoreTask()
    }

  • Really dumb and probably easy question

    Hey everyone. This is prob a very naive and seemingly stupid question, but how do I compile a package so that I get the .class files that I need to incorporate a library into my project? I downloaded this package I need, but it only has .java files in it. Im using Windows 95 and Borland Jbuilder.
    Thanks very much for the help!
    Rick

    You need to download the newest Java 2 Platform, Standard Edition (J2SETM) software. A release of the Java 2 Platform, Standard Edition version 1.4 software for Windows, Linux, and Solaris is now available to the Java community!
    Follow this link to download it: http://java.sun.com/j2se/1.4/download.html
    Once you get it, it can be a little tricky to install it. You may need to set you system's path setting differently depending on your OS.
    Once you get this installed you can access the file you need by going into the directory, under your command prompt (go to run, then they cmd), the .java file is and type javac (for java complier) program name.java. This will turn it into a class file.
    Example:
    javac Lala.java -> Lala.class
    Hope that helps

  • Active Directory Schema Extension for Directory Synchronization - ADFS 3.0, Office 365

    Hi Team,
    We are in a situation with extending the schema for one customer so that these additional exchange attributes may be utilized. They have a single data center where the Primary Domain Controller resides and have multiple remote sites each of which have Additional
    Domain Controllers installed.
    As recommended by Microsoft, I am going to extend the Active Directory Schema with Exchange Setup so that I can leverage targetaddress attribute from Local AD to set primary email address when directory synchronization happens.
    My Query: Do I have to extend the AD Schema with Exchange from each of these ADC's? Or the changes I make on any of them will replicate over the others also?
    Note: The customer will be using ADFS 3.0 'Single Sign On' with Office 365 and does NOT have any On-Premise Exchange deployment.

    My Query: Do I have to extend the AD Schema with Exchange from each of these
    ADC's? Or the changes I make on any of them will replicate over the others also?
    Schema extension is done against the Schema Master. Once done, it gets replicated to other DCs with the AD forest.
    For more details about Schema Extension by Exchange, you can refer to that: http://www.resdevops.com/2013/02/13/extend-ad-schema-to-allow-greater-office-365-management/
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Starting single sign-on and directory service

    i am trying to install oracle 9i infrastructure on my clean win2000 box with 2.4 GHz proc and 1GB RAM.
    i am getting falilure messages for the following:
    infrastructure instance configuration assistant: failed
    oracle 9i application server randomize password: failed
    single sign on configuration assistant: failed
    infrastructure mod-osso configuration assistant: failed
    OPMN configuration assistant: failed
    log file says:
    Configuration failed for IAS
    IAS Instance creation failed
    Configuration failed for JAZN
    JAZN configuration failed: unable to establish a directory context.
    Configuration succeeded for IASProperty
    Configuration failed for IAS
    Configuration failed for JAZN
    after which single sign-on and directory service dont start. which means no connectivity :(
    can somebody please guide me about how to avoid this failure in installation or how to manually start these after installation.
    it would be a great help
    ashish

    Hi,
    we're having exactly the same problem.
    Could you tell me what the problem is with the network ?
    You say configure it properly but what do you mean ?
    It's installed on a Windows 2000 Server machine, it's own DNS.
    Thanks,
    Yuri Arts

  • My ipod wont let me buy apps etc... keeps saying this is the first time this device has been used and to sign in and answer security questions. I have had this account for years but cant remember the answer to the security questions. How can i fix it?

    My iPod touch wont let me buy anything, i've beem using this account for a couple of years and now it says that this is the first ime this id has been used on my device... it's not.... and to sign in and answer security questions. i cant remember the answers to the questions. How can i fix this without making a new account and losing all my stuff???

    From a Kappy  post
    The Three Best Alternatives for Security Questions and Rescue Mail
       1. Use Apple's Express Lane.
    Go to https://expresslane.apple.com ; click 'See all products and services' at the
    bottom of the page. In the next page click 'More Products and Services, then
    'Apple ID'. In the next page select 'Other Apple ID Topics' then 'Forgotten Apple
    ID security questions' and click 'Continue'. Please be patient waiting for the return
    phone call. It will come in time depending on how heavily the servers are being hit.
    2.  Call Apple Support in your country: Customer Service: Contact Apple support.
    3.  Rescue email address and how to reset Apple ID security questions.
    A substitute for using the security questions is to use 2-step verification:
    Two-step verification FAQ Get answers to frequently asked questions about two-step verification for Apple ID.

Maybe you are looking for

  • CREATING NEW/Duplicate Master clips

    Hi Guys...me again. I've been reading the manual all weekend...and decided that, since I SCREWED with this compressor thing...that I'd try to prevent the problem from happening again. I need to know if I'm on the right track. I'm working on a video o

  • ABAP beginner need help~

    Hi,I am a new user for ABAP programing,even I have not entered the right interface for programing.My problem is that I want to create a new program ,I typed <b>SE38</b> to the <b>ABAP edit</b>, typed the custom program name such as <b>Z_test</b> ,aft

  • Aggregated phase in phase out profile

    I am facing one issue while running forecasting for phase in phase out profile at aggregated or base pack level. I have a scenario in which consider base pack level is "A" and under this bas pack are product codes "B", "C" & "D" I have assigned phase

  • Different File Sizes on Linux Samba - depending if bound to AD or not

    The Macs are running 10.5.7 and are bound to a 2003 Active Directory. We connect to a Redhat Linux Samba file server. The authentication is handled by AD. The issue is that all the file sizes show up too large. Anything less than a 1MB is shown as 1M

  • App just crashed now flashes "cleaning" on the names of certain apps

    So I was trying to export a 10 hour video then my iPhone says "storage almost full" then the app crashes and then says "cleaning" on certain app names. Anyone have the same issue? iPhone 5s on iOS 8. Thx