Moving user from OU to OU with modrdn fails

Hi All,
I'm trying to implement the followin scenario:
A user is created in the Actice Directory when the DN is as follows:
DN=CN=%MSKEYVALUE%,OU=%DEPARTMENT%,%$rep.LDAP_STARTING_POINT%
Now I want to implement a pass that moves the user if his department changed.
I tried doing so with the modrdn changetype, but it just wouldn't budge.
I created a job with the following passes:
From LDAP (to a table in the IDS):
objectGUID objectGUID
sAMAccountname sAMAccountname
To IDS
MSKEYVALUE %sAMAccountname%
AD_GUID %objectGUID%
To LDAP
DN <GUID=%AD_GUID%>
changetype modrdn
newdn CN=%MSKEYVALUE%
deleteoldrdn 1
newsuperior OU=%DEPARTMENT%,%$rep.LDAP_STARTING_POINT%
The first 2 passes work fine, when it comes to the thirs, I get the following error:
putNextEntry failed storing&lt;GUID=To v?M??Y??)??&gt+
Now if I specify the full DN of the user like so:
DN CN=%MSKEYVALUE%,OU=%DEPARTMENT%,%$rep.LDAP_STARTING_POINT%
putNextEntry failed storingCN=P0003312,OU=1000,OU=IDM,DC=QANESS,DC=COM
I tried encoding the GUID in the first pass to HEX and removing the prefix, but no difference. What is this putNextEntry function and why does it fail?
Thanks in advance,
Eric Labiner

Ok, so paying even closer attention to spelling does help:
dn CN=User01
changetype modRDN
newRDN CN=User01
Eric

Similar Messages

  • Moving users from One Group to another

    Hi Guys,
    I am looking for a script which will allow me to move users from One ADGroup to another ADGroup. I have checked ther scripts which are currently present. However, none of them if fixing my issue.
    Details:
    I have Different locations and users moves from one location to another location and same thing happens as they gets moved from one Tower to another Tower (Like From TOWER A to Tower B). Also users gets promoted and most of the time they are in bulk.We also
    have 2 domains one is parent and another is child domain.
    So, I hope above information is making sense and also I Completely new to PS so after going to lot of scripts i asking for help on this. I hope I can gets this sorted out as soon as possible as my work is piling up.

    You are asking a lot of questions about AD.  Do you know how to do this in AD with D tools?
    There is no magic way to guess at what you need. I recommend that you start by learning AD and PowerShell.  There are good resources here:
    http://technet.microsoft.com/en-us/scriptcenter/dd793612.aspx
    ¯\_(ツ)_/¯

  • [ESSO issue] Moving user from Org Unit

    hi all,
    i've met an issue at a customer site.
    eSSO has been deployed, synchronisation done with ESSO eDirectory.
    Users are now using it but recently some users have moved from an OU to another (something that happens frequently everywhere).
    The problem is that ESSO seems to keep the initial user location in the Current User registry and seems to always want to use this entry even though authentication fails (since user is not at the same ldap location).
    So authentication failed and users get an "Failed To Connect To Directroy".
    We don't want to change directly the registry since we think it's not really nioce and shouldn't be done.
    Is there something that must be setup to search again in the ldap structure to find when authentication with synchronizer fails ?
    ps : it's not a problem with the location parameter. It's pointing at the ldap root entry.
    thanks for the help
    -regards.

    I haven't come across the issue myself but I think if you move a user, you need to create a 'User Pointer' SSOLocater object that points the agent to where you have moved the user to.
    Good luck.

  • I am an iphone4 user from United Arab Emirates with home button/MIC not working during call problems..

    hi, i am an iphone4 user from the United Arab Emirates. I got my phone as a gift last September and it was not bundled with any carriers and was a factory unlocked piece. Within one month of usage the home button started misfunctioning. It started registering double clicks as single, triple clicks, etc. (the usual complaint of many countless users of iphone from the time of the release.) I then kind of ignored this problem and continued using the phone.
    With this problem still continuing, comes another one.
    My friend gave me a call yesterday, and we were talking happily for a minute or so and suddenly without any reason my friend failed to hear me. Five minutes was spent trying to make myself heard to him. I tried and i tried and the only solution i could find was tapping the phone gently,but firmly. Then he was able to hear me but then after sometime it was back to the same problem.
    The only solution i found was to tap in th sides.(please note that this is also a common problem with many who have call problems but no voice memo problems.) I tried adding and registering my device to my account but when i try to put in my iphone's serial number,they say that the device number is invalid.
    Now i want to get a solution to this, but since this was a gift piece i do not have any invoice of any sort. I even checked itunes.com/support and was happy to find i still have warranty till september.
    I am confused as to what to do as I was dissappointed to find even a single apple store in the UAE and do not know what do we get in terms of support. Could someone please help me?

    that is exactly the problem. I have no idea as in where this phone originates from. It was gifted to my Dad from a personnel who he was supplying for in the company. My dad then gifted it to me on my birthday. I asked my dad about the phone but he also does not know a thing. He also said that the other guy must have taken the invoice with him as he did not give anything to my dad.
    I checked it in quite a few places (like SharafDG,eMax,Axiom etc., the local electronics suppliers) to track where this phone was originally purchased from( because these people usually take down the IMEI's of the electronic devices they sell), but they all could not help me.
    Now i have no idea what to do and i do not want to spend huge amounts of cash for this matter as i am already in the warranty period. Anyways,thanks for your help in advance, but it would be helpful if you could try to get this solved for me.

  • Moving Users from one server to another

    Is it possible to move my network users from one Xserve to another? I know this used to be possible to do with NetInfo, but I haven't heard of anything like this using Ldap.

    I used Open Directory Archive/Restore in Server Admin to carry over my ldap users through a reinstall. Their UIDs, groups, passwords, etc. all came across. The home directories were on a different volume and everything basically worked after the reinstall.

  • How to get users from Organizational Unit and with worker's subgroup

    Hi
    I am looking for a f. module to get the list of users from specific Organizational Unit and with specific worker's subgroup.
    I found f. module SWI_GET_USERS_OF_ORG_UNIT but it seems not working and only returns the users, how can I narrow the selection to get only from specific worker's subgroup?
    Thank you

    Hi,
    Try with FM RH_STRUC_GET with following parameters:
    ACT_OTYPE = O
    ACT_OBJID = worker's subgroup
    ACT_WEGID = SBESX
    Most important is to specify OBJID as the workers's subgroup, values for the others parameters may vary.
    Cheers.

  • Updating Phone Directory after moving users from default "users" folder

    After moving any users from the default "users" folder in AD to a new OU the phone system no longer shows them in the Directory. How could I update the phone system after making changes to the AD structure?

    You need to re-run the AD plugin.
    And point User Search base to that new OU.
    http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_tech_note09186a0080292f6e.shtml#topic2

  • Moving user from POP to IMAP

    Hello
    I'm switching all of my mail users from POP to IMAP. In most cases, I set up their IMAP setting in there mail client. Then I drag there POP messages (stored on their local machines) to the IMAP account. That has worked for most users. I have three users with a lot of local mail messages - about 10 gb. When I try to drag the mail folder over in Apple Mail, it starts to copy them. After a while, it just stops. The messages never get over to the IMAP server. (Their names are on the door, so I can't tell them to trim down their messages.)
    My next thought was to convert the messages from Mail.app, copy them into the mailstore on the IMAP server, then reconstruct the mailbox. I have an app, Emailchemy, that converts Mail.app to following formats:
    RFC-2822 mailboxes ("mbox" format or "UNIX-style")
    Folders of individual RFC-2822 email files (.txt or .eml files)
    Comma-separated value files (.csv files)
    Maildir (qmail)
    Maildir++ (Courier IMAP)
    In a test account, I'v tried converting a single message to RFC-2822 format. After I reconstruct the mailbox, I see the header info, but the body of the message is blank.
    Is there something that I am missing? Is there a better way to move those messages.
    Thanks,
    Henry
    MacBook Pro 2.0 GHz 1 GB RAM   Mac OS X (10.4.6)  

    I've switched many users from Eudora - pop and Mail - pop to imap.
    it's very easy. - just change the client setting.
    we chose Thunderbird because it worked the same on both PC and MAC, and came with just enough options to make everyone happy.
    if all the users are set to either pop/imap combo then only the clients have to make any significant changes.
    having the pop option is great if you want your users to flush their mailbox and keep a local copy while you do updates.
    I frown upon alternate imap boxes other than defaults. if the user needs more mailboxes they can create them on their local machine. That way we don't have to deal with long reconstructs for an individual user. -lots of small files in those maildirs.

  • Moving users from one machine to another

    I am trying to move users from a Solaris 2.6 box to a new Solaris 9 box. I tried moving /etc/passwd /etc/shadow and /etc/group to the new box, but when I try to login I get the following error in /var/adm/messages
    Mar 17 17:10:15 host.name sshd[1573]: [ID 800047 auth.error] error: Could not get shadow information for NOUSER
    I also tried running pwconv to make a new shadow file from the passwd file.. no good.
    How do I move these users to this new machine?

    You shouldn't really have overwritten the whole passwd / shadow / group files - did you back them up first?
    If so, reinstate them and then just copy the entries you require.
    You'll also need the home directories for each user - if they're all in the same place, eg /export/home then you could tar it up and copy it over....
    tar cvf /tmp/home.tar /export/home
    compress /tmp/home.tar
    copy /tmp/home.tar.Z to new box and untar it.

  • Moving user from G5 to MBP

    I want to move my wife's user account from the G5 to my MBP. I created her account with the same name on the MBP, but then realized I probably can't just copy her original folders over to the MBP and drop them accordingly into the MBP folders.
    The MBP is not a new machine and already has another user's account on it so I don't want to do the whole Tiger Setup Asst. thing. The main thing I want her to be able to access on the new machine is her Mail folder (in Library). Thoughts? Thanks in advance!

    Lee, welcome, just log into you wife’s new Account and open Mail. You should be greeted by the new Account setup preferences. If not open Mail then go to Mail/Preferences and fill in the appropriate info. All settings should be exactly as they are on the original account. If these are set correctly then she should be able to open her mail account from the Mac Pro.
    This should also create a folder for her mail account in the Users/username/Mail folder (example, [email protected]). And yes you can transfer any files from the old folder on the G5 (example, [email protected]) to the new folder on the Mac Pro.
    Joe
    Mac Pro 2.66 Ghz   Mac OS X (10.4.10)   Users (RAID 0), PM G4 (10.3.9, PM 6500 (10.2.8)

  • 1     Unable to retrieve the form values entered by the user from the xpath expression(with or without s

    1.1 Description of the Workflow
    We have designed a Workflow, which has an init form HighLevelQuestionnaire.
    1. The user attempts to start the workflow by submitting this form, which has an XML schema embedded.
    2. When user submits the data, we set workflow variables to fetch data from the init-form and all the values entered by the user are stored in the database.
    3. Based on the values, value of Risk Level is calculated to be either High or Medium, and user is routed to one of the two routes.
    4. The user QPAC is used to show the next form to the user.
    Another form has been designed called AssessRisk in which user is asked to confirm the Risk Level.
    5. At this point, we use Script QPAC to print the values in the log.
    1.2 Problem description
    1. In the Point No. 6 of the workflow, the values are not printed in the log. A blank space is printed instead.
    2. Initially, we embedded the schema in the form. But when values were not printed, we removed the schema. Even then it didnt work.
    1.2.1 User QPAC Specifications
    Properties of user QPAC used in Step 4 of the workflow
    Mappings Tab: -
    Input Variable --- No variable
    Template URL ----- Form11.xdp
    Output Variable ---- myform
    Myform is a form-variable, which has template URL as Form11.xdp
    1.2.2 Script QPAC
    1.2.2.1 With XML Schema embedded
    import com.adobe.workflow.pat.service.*;
    System.out.println("----------- High Level Questions -----------");
    System.out.println("--1- the RiskLevel is: " + patExecContext.getProcessDataStringValue("/process_data/myform/form-data/data/xdp/dataset s/data/RiskLevel/general/Risk_Level") + " @@@@@");
    Note:- Here RiskLevel is the schema root of myform and Risk_Level is the schema variable mapped with textfield on the form
    1.2.2.2 Without XML Schema embedded
    System.out.println("--1.1- the RiskLevel is: " + patExecContext.getProcessDataStringValue("/process_data/myform/form-data/data/xdp/dataset s/data/fields/Risk_Level") + " @@@@@");
    1.2.2.3 Conclusion
    In both the cases, a blank value is printed. In both the cases, we get some output which is when we use
    System.out.println("--1.1- the RiskLevel is: " + patExecContext.getProcessDataStringValue("/process_data/myform/form-data/data/xdp/dataset s/data ") + " @@@@@");
    In this case all the values are printed with space in between.
    This is the basic feature which has to be used while developing workflows.

    Hi
    You might want to try using VariableLogger, at:
    http://www.avoka.com/avoka/qpac_library.shtml
    It's a little more reliable than the script QPAC, especially if one of your xpath expressions is wrong.
    Please note that embedding the schema makes no difference in how the data from the form is stored. What makes the difference is whether your fields are bound to specify schema elements, or whether they use the "normal" binding.
    Howard

  • Moving images from library to library WITH Faces information

    Ok.
    iPhoto 09/faces
    Can someone out there tell me, first off, is it even possible to move photos from one library to another library WITH all the Faces effort I've put in on those photos (say from my default library on my hard drive to another person's library on an external hard drive)?
    That way they don't have to be rescanned and then I have to go through and correct the crappy scanning effort that the program did all over again.
    I tried exporting/importing, straight copy, etc. with no dice.
    I don't want to keep having to re-correct all the faces in images I transfer between libraries.
    "Help me Obi-Wan Kenobi....You're my only hope!"

    For folks out there here is the results of Terrence's suggestion (which was a good one BTW, I don't want to dump on him - it was good thinking on his part! Thanks Terrence).
    iPhoto Lib Manager still ***** (on my system anyway - iMac OSX 10.5.6).
    I installed the thing and tried moving 1000 photos with faces info organized nicely - no dice - it crapped out.
    First make sure all the permissions are set properly and the library mounts automatically (under the options). Then it will at least ATTEMPT to copy everything (also edit prefs to reflect all the metadata that goes with the photos like faces info, dates, desc. etc).
    But while thing appear to go well, it craps out at the end leaving you stymied. It re-scans the imported images and the faces data does not come through in the end despite it's trying to do so.
    I tried it with 80 photos, just to make sure I wasn't trying to fit 20lbs of manure into a 10lb bag. Same story with the smaller transfer
    If I go any smaller, I may as well have used the public version (free) which limits you to 20 at a time.
    So bottom line - according to my experience - if you and someone else have the same photos in your separate libraries and want to share the effort one of you puts into organizing faces info - you're hooped/screwed/pooched!
    Nada - diddly - bupkiss!
    VERY DISAPPOINTING! Both the iPhoto 09 AND the failed (but valiant) attempt by iPhoto Lib Man.
    Should've stuck with iLife 08 and lived with it...sigh.

  • Manually Moving VMS from HOST to HOST *WITH* Shared SAS Storage

    Hi,
    Environment will be 2 Windows 2012 R2 Hyper-V servers.
    They will be connect via shared SAS.  These are two identical IBM servers with shared SAS storage
    I am hoping to eliminate using MS Clustering of the Hyper-V servers just to keep things straight forward.
    In the event, I had a complete failure of one of the  physical server Hyper V hosts, I was hoping be able to manually add/import (not sure what the terminology is here) and run the virtual machines on the second host until the first is repaired.
    If there is third party software that can do this, I would entertain it.
    In VMware (I had two hosts and would manually remove them from inventory on one server and add them to a second server). 
    Ideally, if I could keep both Hyper-V hosts in a Windows Workgroup and as vanilla as possible.
    Thanks in Advance,
    G

    Hi,
    Sorry for the late reply.  I have been researching all I can. And thanks to all for your patience and help!
    Let's start with the hardware to help paint the picture:
    2 @ IBM X3550 M4
    1 @ IBM V3700
    The two X3550's are going to be connected via 6GB SAS Cards (2/server for redundacy)
    Current environment (residing on VMWare with older IBM Xseries servers DS3524 connect via SAS connections)  40 users total.
    Windows servers are:
    1 @ SBS 2011 (One and only AD/PDC)
    2 @ Windows 2008 Servers that are CRM (these are Windows Member Servers)
    5 @ Windows 2003 servers that are going to be replace with Windows 2008 Servers (these are Windows Member servers) (low usage servers)
    Just to recap:
    The current environment running VMware 4.1 has both IBM X3500 servers able to see a  single 1.5 TB lun (SAS connected) presented by the DS3524.
    Currently, in VMware, I can see the same LUN on both servers.  I have all my VM's on HOSTA, if HOSTA should suffer a system board failure, I manually connect to HOSTB with the VMware client and add the VMs that I can see on the shared LUN
    and add them to HOSTB.
    My understanding is that its strongly recommend that my DC (not sure if they are implying PDC or BDC) on a physical server.  My hesitation is now I have to introduce a DC to SBS 2011 and manage a physical server and deal with with SBS 2011's quirks.
    So I was hoping that if I presented a LUN to both my HyperV hosts (In a Workgroup), and created on my VMs on hostA, if something went very bad with HOSTA,  I could connect to HOSTB and "Import" them and manually start the VMs, especially since
    SBS 2011 is sensitive.
    The client is okay with some downtime, so if the process is supported and works, then I am okay with doing the work.
    Clustering or even Replicas will add:
    Complexity to the environment
    Patching needs to be carefully planned as it would not look good to have to failover due to a Windows update on the primary host.
    The tech's that support that environment will now need to know about Clustering and/or Replication ontop of the SAN stuff
    I am looking at Veeam, Double-Take to see if they can work with 2 @ 2012 Hyper-V hosts configured in a Workgroup.
    The SBS 2011 is the "hinge" that will make or break the success of this project.  I personally love the way 2012 Hyper-V works, but it would be great if a physical server outside of the HyperV hosts was not required.
    Thanks !
    G

  • Moving data from old power pc with OS 8.6 to computer with OS X

    How can you move data from an old power pc to a new MAC? And then, how do you permanently erase the old hard disk before donating the computer?

    Which model PowerPC with 8.6 are we talking about? Does it have an Ethernet port? Do you have Broadband Ethernet? Do you have your own Router?
    Which new Mac are you moving to, and how does the iMac in your equipment line fit in to all of this?

  • Moving iTunes from PC to Mac with another itunes already on it!

    I have a click wheel ipod (approx 2 years old) and it has died on me. I'm going to get a new ipod but I want to know how I move my itunes from my PC to my boyfriend's Mac. He already has itunes (and a photo ipod) on his mac but we want to dedicate his computer to music and have both of our ipods (his current one and my new one) associated with his mac.
    How do I do this without losing either one of our itunes libraries?
    Would really appreciate some help if someone can.
    Thanks
    Beeb75

    This page may be of some help: How to move an iTunes library from a PC to Mac (and back)

Maybe you are looking for