Is MS Identity Management for Unix / PW Sync supported in WS 2012 R2

We need to upgrade the AD forest DC servers and the FFL and DFL levels.
The current AD domain is a one-domain forest, with WS 2003 DC servers.
Our target is to install the newest Windows servers (WS 2012 R2) as DC's.
To make the job, we are going to promote new DC's first, then de-promo the old ones, and finally raise the DFL+FFL levels to the newest possible.
However, currently there are the MS Identity Management for Unix / Password Synchronization software in each of the DC's installed. To keep passwords in sync and thus the IDM to work, the software has to be installed to each of the new DC's, too.
According to MS article
http://technet.microsoft.com/en-us/library/cc731178.aspx
the pw sync can be installed to WS 2012 server.
My question is that,
- Can we go forward with WS 2012 R2 DC installation and assume that the pw sync can be used in them, too?
- Or, do we have to install older DC servers (WS 2012)?
Br,
Kari Oikkonen
Fujitsu Finland

We found the following TechNet article:
Windows Server 2012 R2 Packages
http://technet.microsoft.com/en-us/library/dn452400.aspx
According to it, the psync package is still there.
One colleague also shortly tested with R2 server by installing it with
Dism.exe /online /enable-feature /featurename:psync /all
command, and the pw sync seemed to install OK.
So, we now are encouraged to install R2 servers for DC and psync.
Br, Kari

Similar Messages

  • Identity Management for UNIX (aka Windows Services for Unix) Adding 2012 DC to a prep'd 2003 domain.

    We have been successfully using Windows Services for Unix on a 2003 domain for passwd and group maps.
    I prep'd the domain to allow a 2012 R2 server to be added and then added the IdMU role/feature on this new 2012R2 DC. Now the passwd map is still OK but the group map now shows full usernames rather than short names.
    i.e. what DID show with "ypcat group" as ...
    "infra-shared::65550:gfer,jhug,shig", now shows as
    "infra-shared::65550:Garry Ferguson,Jason Hughes,Steve Higgins"
    and so is not usable. I have had to revert to local /etc/group files on all our unix machines!!
    Help/comments would be really appreciated!
    Garry Ferguson

    Hi Gaz Ferg,
    SFU 3.5 is used to installed on windows 2003 and windows XP. SFU 3.5 cannot used on Windows 2012, that makes customer cannot user NFS and user name Mapping services on Windows
    2012.  From windows 2003 R2, NFS is a build-in component in OS, we need to add Roles/Features to use NFS.
    1. What is change in 2012R2
    IDMU component, which was used to authenticate Linux users has been removed. Now a Windows server cannot play role of NIS Master server. 
    Passwords cannot sync to the Unix Machines. Maps can not sync between Windows and Unix computers.
    2. What has not change in 2012R2
    Following methods to authenticate and map a Unix user to Window user are available:-
    Active Directory
    Active Directory Lightweight Directory Services (AD LDS)
    Username Mapping Protocol store (MS-UNMP
    Local passwd and group files
    Unmapped UNIX Username Access (UUUA) (applies to Server for NFS using AUTH_SYS only)
    You can find more information about this here –
    http://blogs.technet.com/b/filecab/archive/2012/10/09/nfs-identity-mapping-in-windows-server-2012.aspx
    http://blogs.msdn.com/b/shan/archive/2006/12/13/sfu-sua-idmu-fun-with-names.aspx
    More information:
    Install Identity Management for UNIX Components
    http://technet.microsoft.com/en-us/library/cc731178.aspx
    I’m glad to be of help to you!
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • 2008 R2 Server and Microsoft identity Management for Unix - Lost groups

    I couldn't find a group that fit this one so I'm putting in the general group-  If their is a better group please reply with it -  Thx
    We have 2 Windows 2008 R2 servers and  2 linux boxes running NIS/Kerberos.  One of the Linux servers also runs a secondary NIS server for performance reasons.  Unix Services syncs the account db in NIS format to it, the other server connects
    and auth's directly off of the AD server.  We have had this setup for over a year now and it's run with out problem.  Today I ran the Microsoft Identity Management utility and lost NIS group on the Linux server that runs it's one NIS server. 
    On the Linux server that connects directly to the AD box the groups all appear with an id command from the command line.  It looks like the Unix for Windows services app nolonger will sync to a Linux NIS server.   I feel this is a bug due to
    the fact that I recently update the two Windows 2008 R2 server to the latest patch releases a few days ago. 
    Does any one have a fix for this or could Microsoft look into it.

    Hello,
    you may ask this in
    https://social.technet.microsoft.com/Forums/en-US/home?category=identitymanagement
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  

  • ANT missing from 11.1.7 software to provision Identity Management for FA

    I am provisioning Identity Management for Fusion Applications 11.1.7 version and one of to provision identity management using runIDMProvisioning.sh is to set ANT_HOME but there is no ANT in REPOSITORY (downloaded files), is this part of any zip that I need to unzip ?
    http://docs.oracle.com/cd/E36909_01/fusionapps.1111/e21032/prov_idm.htm#CHDDJFFJ

    Hello onlineAppsDBA.com:
    The focus of this forum and the team moderating it (the Developer Relations team) is on development issues, not install questions.  That said, I'll try to find answer for you.  But you might also want to submit a service request with Oracle Support for this issue.
    Thanks,
    Oliver
    Fusion Apps Developer Relations (@fadevrel)
    http://blogs.oracle.com/fadevrel

  • Using Identity Management for Securing Web Services

    My goal is to associate my services with an Oracle Internet Directory. I made some attempts to set up SAML authentication for the web services, but it didn't have the right outcome.
    (My identity management server and OID is up and running and I have successfully made authentication modules for other web applications)
    Here is what I did:
    1. I wrote a simple java file, used jdeveloper tools to create and deploy it as a web service to OC4J. I associated an identity management server with this service through OC4J web tools as security provider.
    2. I made a data control for the web service and put it in an ADF application . (client)
    3. I deployed the client project(2) to OC4J.
    I could use the web service through the page.
    Then
    I secured the webservice to expect SAML for authentication.
    Surprisingly, the client could still communicate with the webservice, Why? Shouldn't it have rejected the request because of the problem in SAML token? (The proxy and the data control were not secured, and didn't provide any SAML tokens)
    4.
    I added login page to my client project (through ADF security wizard). It used idenity management for authentication successfully. login process completes and web service data control is displayed.
    5. I want the authentication information to be propagated through the page so that the web service receives the data and uses Identity Management.
    I know I should add <property name="oracle.security.wss.propagate.identity" value ="true"/>
    to one of the configuration files, but don't know where exactly.
    Best Regards,
    Farbod

    It doesnt matter whether the service is invoked as part of your larger process or not, if it is performing any business critical operation then it should be secured.
    The idea of SOA / designing services is to have the services available so that it can be orchestrated as part of any other business process.
    Today you may have secured your parent services and tomorrow you could come up with a new service which may use one of the existing lower level services.
    If all the services are in one Application server you can make the configuration/development environment lot easier by securing them using the Gateway.
    Typical probelm with any gateway architecture is that the service is available without any security enforcement when accessed directly.
    You can enforce rules at your network layer to allow access to the App server only from Gateway.
    When you have the liberty to use OWSM or any other WS-Security products, i would stay away from any extensions. Two things to consider
    The next BPEL developer in your project may not be aware of Security extensions
    Centralizing Security enforcement will make your development and security operations as loosely coupled and addresses scalability.
    Thanks
    Ram

  • FILE MANAGER FOR UNIX

    I am trying to write a file manager for a unix machine. Does anyone know how to 'grab' the existing file structure, l just want to copy the functionality of existing Unix file managers - then add my own graphical representation of files and directories. Any reply would be greatly appreciated.

    start off by looking at java.io.File All the methods you will need are there. listRoots(), listFiles(), isDirectory() etc.. Hint: the best plan is to use recusion to descend into the directory structure.

  • Desktop manager for mac not syncing with calendar

    Desktop manager just started to give me a sync error yesterday when syncing the calendar. I receive no error message for the contacts. I use desktop manager for mac. I have never had this issue before. I updated desktop manager yesterday after the sync error but, that did not correct the problem.
    Any suggestions?
    Solved!
    Go to Solution.

    Thanks for the reply yancy.
    What error message are you receiving?  Are you only synchronizing to Ical or Entourage?
    Also have you attempted to forget the device and the re-setup the synchronization?  
    To forget the device, go into Device>Forget Device.  Unplug the BlackBerry, plug it back into the Mac.
    I look forward to your reply.
    -ViciousFerret
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Like! for those who have helped you.
    Click  Accept as Solution for posts that have solved your issue(s)!

  • Identity Management for portal forms

    where do i find,
    Identity Management 10gR3?
    kindly,
    as Portal form, reports, discoveres installation says
    Required Additional Software:
    WebLogic Server
    Repository Creation Utility
    Identity Management
    SSO Metadata Repository Creation Assistant
    Patch Scripts
    Identity Management 10gR3
    Oracle Database
    Optional Software:
    Web Tier Utilities

    Here:
    http://www.oracle.com/technetwork/middleware/ias/downloads/101401-099957.html
    Regards

  • File manager for setting up syncs

    I have a file manager on an android tablet---foldersync---that allows me to set up synchronization via a cloud service, e.g., SugarSync, on folders used by apps that do not support the service, e.g., that don't support SugarSync.
    I see file managers that themselves will synchronize with a particular servces but the ones I've checked out so far---not that many I will admit----don't seem to be able to do what foldersync does.
    Thanks,

    FolderSync allows me to use a syncing service of my choice to set up syncing between folders so that any change in any folder is updated to the other. This is true even if changes are made by apps that don't support, i.e., don't provide access to, the syncing service selected.
    Dropbox is widely available with most apps. SugarSync less frequently. However, SugarSync supports syncing to folders in the file system. It is not limited to a special folder the way Dropbox is. There is no need to manually sync from the special folder to the file system as there is with Dropbox.
    FolderSync allows me to take advantage of this convenience even with apps that provide no access to SugarSync. I'd like to be able to do the same thing on my iPad.
    And iTunes is not very convenient at all.

  • Desktop manager for Mac not syncing with iMac

    Tried this earlier in the year and lost all contacts out of my Blackberry Tour. Tried again today and DM for Mac doesn't recognize any of the iCal calendars I have on the iMac and gives me a sync error when trying to sync Addressbook.
    Running OS 10.5.8 on iMac; v5.0.0.732 on Tour.

    Hey scoopmassad,
    Welcome to the BlackBerry Support Community Forums.
    Can you clarify what the error message is that you're receiving?
    Also what version of BlackBerry Desktop Software for Mac are you currently using?  To download the latest software go to: www.blackberry.com/desktop
    Also have you tried to Forget Device and then re-setup the synchronization with the BlackBerry.  Go to Device>Forget Device at the top of BlackBerry Desktop Software.
    I look forward to your reply.
    -ViciousFerret
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Like! for those who have helped you.
    Click  Accept as Solution for posts that have solved your issue(s)!

  • Identity Manager and SAP 5.0 support?

    Hi all,
    does anybody know if the IDM will support SAP 5.0 (ECC 5.0)? Customer is using IDM + SAP HR ActiveSync adapter and wishes to upgrade their SAP 4.7 to "ECC 5.0". I don't even know what ECC 5.0 is, but it should be "SAP 5.0".
    Will this version of SAP be supported?
    Many thanks,
    Ivan

    Hi
    IDM 6.0 supports SAP R/3 v4.5,4,6 ad 4.7 and SAP Enterprise Portal V6.20 SP2+
    Thanks

  • Crawled the UCM through SES but unable to search on Search screen. I have to use OID as identity management. How to configure SES for this??

    I have crawled the UCM through SES, but when I try to search on the Search screen nothing is searched.
    followed the following document - http://www.oracle.com/technetwork/search/oses/stellent-white-paper-178229.pdf
    But at the end I need to configure the identity management for OID not for Content Server. I have activated the OID plug-in in SES, but nothing is searched in both the foloowing cases:
    1) When I login with a OID user
    2) When i do not login, even the public data is not displayed.
    What could be the problem??

    Thanks for the reply. Authorization was use source ACL, and I tried logging in as every user that had access to the content and could not bring up anything.
    However, this is no longer an issue as we are not going to be using this content database. We are going to be using the new Beehive collaboration instead. I don't know if there will be a different plugin for SES or what, but it should be interesting.
    Jennifer

  • Enterprise Deployment Guide for Oracle Identity Management 11g

    Hi,
    I am looking for Enterprise Deployment Guide for Oracle Identity Management 11g for latest verion 11.1.1.5
    Please help
    Thanks

    Thanks for the reply.
    Actually I am looking for Enterprise Deployment Guide for Oracle Identity Management for 11.1.15(similar like E12035-06).I am not able to find same in the link provided.
    Thanks

  • Identity Management requirement

    sir,
    we have a Identity management project implementation. i am gathering IDM docs regarding where to start, what is the pre requisites for implementing Idenetity management project. i am going to take this a challenge. please give your valuable suggestions (details)
    regards
    ramesh

    Hi Ramesh,
    installation and sizing is easy, practice for complex requirements will need some time...
    Installation and Sizing:
    Have a look at the PDF for the installation overview, provided with the install files. Usually, you only need a sizing between the explained S or M.
    Practice:
    The follwing site will help you: https://www.sdn.sap.com/irj/sdn/nw-identitymanagement?rid=/webcontent/uuid/f0b68fb1-d8af-2a10-2a8e-cc431c15bb39&anchor=section2.
    Go through the tutorials for the Identity Center and make your own scenarios. Especially the "Identity Management for SAP System Landscapes: Configuration Guide" is good to set up scenarios in the Identity Center with SAP Systems and Directories. There are also prerequisities and limitations in this document. "Identity Center - Identity Store Schema" gets into details about the data model. There are additional blogs, e.g. getting HCM data via SAP PI instead of VDS, if you intend to implement this.
    Best regards,
    Nils

  • Launch Setup panel - Install Identity Manager

    Hi all
    I am installing Identity Manager for Sun Java System Application Server and (file installer) I am following this link http://docs.oracle.com/cd/E19164-01/820-0817/Ch8_java8.html
    in the step 5 .
    After installing the files, Identity Manager do not displays the Launch Setup panel.
    Why?
    do you Help me?
    Thanks

    it says a format error...
    there's some error in what you are entering.
    After copying you must rename the file as the Installation doc explains
    i still suspect when it says format error, must be something that you are entering
    nsankar

Maybe you are looking for

  • Edit Text from one screen to another screen

    Hi Experts,        Here I am having two doubts in doing functionality on SMP 2.3,The below mentioned are the doubts,                    1. In SMP 2.3 Version,When i am doing Hybrid App Designer in that  Edit Text functionality to pass the values from

  • HCM processes & form- a line is displayed in portal instead of Adobe forms

    Dear FRIENDS, In HCM PROCESSES And FORMS , when we run a process, adobe form is not displayed. In place of that a single line is displayed. When  I  implemented the SAP note 1334453 it gave dump in portal saying ASSERTION CONDITION WAS VIOLATED. Then

  • CVI: erreur ODBC sur Appli déployée

    Bonjour, Logiciel: CVI 2010 10.0.1 (419) sous Win XP32 SP3 J'utilise ODBC pour accéder à une base MySQL via son connecteur 5.2w. Sur le PC de développement CVI, la connexion ODBC fonctionnement parfaitement. Un installeur (volume setup) est généré av

  • Applying object style to all objects in a project?

    In Cp4, it was possible to change the style of an object and then apply those changes throughout the entire project. How is this accomplished in Cp5? I have set up a default style for captions but it seems like I can only change the style of individu

  • Problem in JComboBox selected Index change

    hi all Can anyone send me the code for Loading values to JComboBox & then i want to Display Particular value for that Loaded value in JTextField. Ex: I loaded category cade for JComboBox & when JComboBox selected index change the particular category