OIM 11.1.2 AD Provisioning problem

I added custom fields for AD resource. Reconciliation and create(create a new user into the target system with the custom attributes) operations works successful.
I try to update custom attributes and not update into the target system.
Thanks.

The custom attributes is created in AD Form not in USR definition.
I already added the attribute in the provisioning lookup.
I tried your procedure and it did not work
In the Resource History not displays the Task of the extended attribute.
The logs no displays any errors.
Thanks.

Similar Messages

  • User provisioning problem from OIM 10g to Siebel CRM

    Hi Team,
    I am facing User provisioning problem from OIM 10g to Siebel CRM.Please find the log details.
    Running Get Attribute Mapping
    Running Siebel Create User
    <com.siebel.common.common.CSSException>
    <Error><ErrorCode>8716601</ErrorCode> <ErrMsg>Socket had incorrect word size: 0.(SBL-JCA-00313)</ErrMsg></Error>
    </com.siebel.common.common.CSSException>
            at com.siebel.om.conmgr.Connection.readPacket(Connection.java:550)
            at com.siebel.om.conmgr.Connection.run(Connection.java:286)
            at java.lang.Thread.run(Thread.java:619)
    [CMGR FATAL] Error: <com.siebel.common.common.CSSException>
    <Error><ErrorCode>8716601</ErrorCode> <ErrMsg>Socket had incorrect word size: 0.(SBL-JCA-00313)</ErrMsg></Error>
    </com.siebel.common.common.CSSException> connection:1
    <com.siebel.common.common.CSSException>
    <Error><ErrorCode>8716601</ErrorCode> <ErrMsg>Socket had incorrect word size: 0.(SBL-JCA-00313)</ErrMsg></Error>
    </com.siebel.common.common.CSSException>
            at com.siebel.om.conmgr.Connection.readPacket(Connection.java:550)
            at com.siebel.om.conmgr.Connection.run(Connection.java:286)
            at java.lang.Thread.run(Thread.java:619)
    [CMGR FATAL] Error: <com.siebel.common.common.CSSException>
    <Error><ErrorCode>8716601</ErrorCode> <ErrMsg>Socket had incorrect word size: 0.(SBL-JCA-00313)</ErrMsg></Error>
    </com.siebel.common.common.CSSException> connection:1ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],====================================================
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],com.thortech.xl.integration.siebel.utils.SiebelConnection : createSiebelConnection() :  Siebel Connection Exception:Could not open a session in 4 attempts. {1}(SBL-JCA-00200)
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],====================================================
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],====================================================
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],com.thortech.xl.integration.siebel.proxy.SiebelProxyEmployeeProvisionManager : createSiebelConnection() : BaseException: Siebel Connection JDB Exception: Could not open a session in 4 attempts. {1}(SBL-JCA-00200)
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],====================================================
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],====================================================
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],com.thortech.xl.integration.siebel.provision.SiebelUtilEmployeeProvisionManager : createEmployee() : BaseException: Siebel Connection JDB Exception: Could not open a session in 4 attempts. {1}(SBL-JCA-00200)
    ERROR,22 Aug 2013 12:58:27,689,[XL_INTG.SIEBEL],====================================================
    Regards,
    Ravi.

    Hi
    I facing the same error message as yours, using OIM 11g R2
    Are you able solve it ?
    Please share
    Many Thanks !!!

  • Extend Provisioning (from OIM to OID) for already provisioned resources

    We use OIM 9.1.0 to provision users to several target systems, for example OID. Not all information stored for a user in OIM is also provisioned to OID (for example department or location or phone is only stored in OIM). The provisionig task automatically is created via access policys.
    This works fine.
    Now we want to provision some more data (including department and location) to OID. So I changed the oid connector configuration to also provision these fields. This works fine for new users (which are not already provisioned to oid).
    But we also need these additional fields in OID for users which have already been provisioned in the past. How can this requirement be implemented? Is there a way to resubmit these provisiong tasks oder to automatically update the process form.

    Create a schedule task which will read the data from OIM User Profile and update the process form using tcFormInstanceOperationsIntf OIM APIs.
    Also create their Label Name updated task in OID Workflow (Process Defintion)

  • OIM Provisioning problem with EBS

    I use connector to test provisioning function with EBS, and it works.
    Besides,there have 2 CreateUser storedprocedure in EBS, and one for SSO(we
    can set GUID value when create user). I found the connector used
    the non-SSO storedprocedure. The question is can I modify the config files(
    attributemapping_prov.properties, config.properties,storeprocedures.properties)
    to utilize the SSO storedprocedure to finish the create operation during provisioning
    (I want to specify GUID by myself when create EBS' user through OIM)?
    I just tried my opinion, but the logs prompt SQLException.I do not know why?What should I do?
    Any suggestions will be helpful.
    Thanks!

    You could definitely write your own connector. We faced a similar problem and solved it by writing our own EBS Connector.
    I haven't explored the exact capabilities of the standard EBS connector so you might be able to do this by configuration. My general experience is that it is often better to bite the bullet and create your own connector rather than wasting time trying to get the out of the box connectors to do advanced operations.
    It looks like the config files are more for defining the type and number of attributes that is used during user creation rather than control which stored procedure should be called.
    Good luck
    /M

  • OIM Provision Problem--Create User or Update User

    How can we control the provision process to meet the following requirement?
    If the target application exits the user, there is no need to call the createuser task, just establish a link with the user of target application. But if it is a new user, we must complete the createuser task to provision the user to target application.
    At first, thanks for everyone's advice, I should restate my requirement in order to make it clear.
    The provisioning scenario is as follows:
    If the user exists in target application, update the user of target application. Otherwise, create the user.
    Thanks!
    Message was edited by:
    user627209

    I think it would be very helpful if you restated your exact requirements.
    As a general rule it is not advisable to just map the "object already exists" adapter return code to a task status that gives the object effect of provisioned as in some cases there is a need to copy a unique object identifier back to the process form (i.e. in AD you need to have the GUID(?)) from the target system. Without the identifier the update tasks will not be able to find the object in the target system.
    You could of course copy the identifier manually in another task but you have to make sure that you have done everything that you need to do to actually get object into a linked state.
    Another alternative is to trigger a recon task using the APIs when you run into the "object already exists" situation.
    Hope this helps
    /M

  • OIM 11g r2 Exchange connector provisioning is not working

    Hi,
    I have created one user in oim and i have provisioned this user into AD successfully.
    after that i have tried provision same user into Exchange but the user provisioning status is shows "*waiting*" and provision date also shows wrong.
    Please any body help me on this issue..
    Thanks,
    Venu

    Exchange goes to waiting status when AD is not listed in user's resource profile as Provisioned. Check whether AD is properly provisioned. It is better to always create a new process task before 'Create User' in Exchange resource object which checks whether AD is already provisioned for the user. Then this problem can be avoided.
    Also when there are multiple AD resource object instances in user's resource profile and even one of that instance is in Provisioning status, Exchange goes to waiting status
    Edited by: Durgaprasad on Mar 5, 2013 6:43 AM

  • Xellerate provisioning problems

    When I configure the xml files, do I have to assign a different resource name to each of them (e.g. AD Server, AD User, AD Group)?
    I configured the connector so the user provisioning from the OIM console took place in the AD. However, only the Name field is provisioned. How can I define the field mapping? I cannot edit it from the design console.
    Another problem: I assigned the OID and AD resources to the organization Xellerate users. Then I create a user that belongs to that organization. To provision the user in both OID and AD do I always have to select these resources formally?

    OK, I got it fixed. The instructions said to use an appid of ######.* and I was using #####.com.mycompany.* which, of course, isn't the same.
    I also needed to remove the bundle id from plist and the target and just put in any string I wanted. I'll worry about that all appids are the same later...

  • OIM 9.1 AD Account Provisioning

    Has anyone ran into the scenario where you go to provision an AD account and the process fails because the account already exist on the target which results in the resource status remaining as "provisioning". I expected that status to change to "provisioned" once a recon was ran which would link the account to the OIM user but it didn't. The recon linked the account but from the user's resource profile you can see that it didn't.

    first of all when the account with the same id is found on Ad, it may necessarily not be that of the user unless you have ascertained that. If you want the adapter to return a success what you should have done is mapping the user_already exists retrun code to C for completed instead of an R for rejected, which is why the resource is going into a provisioning status.
    BTW does your create user task or whatever task last gets executed before the provisioning is deemed as complete have the task to object status mapping set to C=Provisioned?
    What you will need to do is, revoke the AD resource from the user's resource profile list and then run the recon, the account should now be linked to the user if the owner matching rules match up to the identity in oim.

  • CUCM 10 Self Provisioning Problem with TAGs on Universal Device Template

    Hi friends.
    I've been provisioning IP Phone by Self Povisioning. The phones were provisioned almost perfectly. I notice the TAGs that i filed up on Device Template (look above), are not "translated" on Device Phone.
    Universal Device Template
    The Tags on Universal Line Template comes  perfectly to Line Description.
    Had you ever seen something like this?
    Kind Regards
    Fernando Penteado

    Hi folks. I could identify the problem with Variable and TAG. In order to Self Provisioning works fine, we need to mark Owner User on Universal Device Template.
    Look that.
    Thanks

  • ISE 1.1.3 provisioning problem for the first DOT1x connection

    Hello all,
    I am wondering how a wired dot1x client can get the NAC agent downloaded for its very first connection from ISE ?
    Should the Agent be installed before the first connection ?
    I'have set up ISE 1.1.3 for provisioning (files have been downloaded from cisco website) (upgrade mandatory)
    I have an AuthZ rule for a correct posture assessment
    and
    another AuthZ rule for an unknown posture assessment that triggers a posture remediation (file download)
    (in that order)
    NAC agent is properly configured ( FQDN...), the users gets and nothing happen !
    no NAC upgrade
    no NAC assessment.
    Any idea ?
    Does it take a while for the new agent to be downloaded ?
    Best regards.
    V.

    In order to troubleshoot the NAC agent problem, we need to check  couples of things.like
    1.)Ensure that the discovery host address on the Cisco NAC agent or  Mac OS X agent is pointing to the Cisco ISE FQDN. (Right-click on the  NAC agent icon,
    choose Properties, and check the discovery host.)
    2.) Ensure that the access switch allows Swiss communication between  Cisco ISE and the end client machine. Limited access ACL applied for the  session should allow Swiss ports:
    permit tcp any host 80.0.80.2 eq 8905 --> This is for posture
    communication between NAC agent and ISE (Swiss ports)
    permit udp any host 80.0.80.2 eq 8905 --> This is for posture
    communication between NAC agent and ISE (Swiss ports)
    deny ip any any
    3.)If the agent login dialog still does not appear, it could be a  certificate issue. Ensure that the certificate that is used for Swiss  communication on the end client is in the Cisco ISE certificate trusted  list.
    4.) Ensure that the default gateway is reachable from the client  machine.
    As per your confirmation, I am going to close the case for this specific  inquiry. We strive to provide you with excellent service. Please feel  free to reach out to me or any member of the SAC team if we can be of  any further assistance or if you have any other related questions in the  future. We value your input and look forward to serving you moving  forward.

  • OIM 11.1.1.5 provisioning role based objectclasses and attributes

    TL;DR You can't provision some attributes in our LDAP directory without the objectclass and I can't figure out the best way to inject the dynamic objectclasses into the create user process without the user being created already.
    Some background:
    I have configured our oim 11.1.1.5 instance and LDAP connector to provision ODSEE.  At another's recommendation, I put all possible LDAP attributes in a single form regardless of which objectclass was needed for them.  In ODSEE, sets of attributes are allowed through objectclasses for each 'Role'.  ie. Student, Employee, Guest, etc objectclasses.  I have all of the roles identified in OIM and can map them to an objectclass in LDAP
    My question is, how can I provision role based objectclasses along with the common ones that are configured in the lookup so that when the associated attributes are provisioned, I don't get objectclass violations? 
    Can I append objectclasses to the list stored in the Configuration lookup in ldapUserObjectClass?
    Should I create a child form containing the objectclasses and try to provision them?
    Can/should I create a child form for each set of attributes by role?  Common attribs in the LDAP_USR form and role based attribs in UD_LDAP_STU, UD_LDAP_EMP, UD_LDAP_GST, etc.  Would prepop and the rest of the main form functions work the same?
    Anything else I'm not thinking of? I am still a novice with some of these topics and may be way off base.
    Any help will be greatly appreciated and thank you in advance

    It is definitely doable if you use a custom LDAP connection implementation and just add objectclass update calls as needed as precursor tasks for the Update tasks.
    Here is a small LDAP demo tool that you can adapt to do the update: http://iamreflections.blogspot.com/2010/08/manage-ad-with-jndi-demo-tool.html
    There may be a smarter and more out of the box way to do it but this will work.
    Martin

  • OIM 11gR2 - AD Organizational Unit provisioning

    hi,
    i can provision OIM organization to AD Organizational Unit. Its work fine with "Provision Resource to Organization" forms but i can't find any simple way (without six steps form) to add AD organizational unit to OIM organization.
    Have you any suggestion or hint?
    a.

    Hi IDM Newbie,
    Please find the link of Developer Guide:-
    http://docs.oracle.com/cd/E27559_01/dev.1112/e27150/toc.htm
    And following link is for Application Instances:-
    http://docs.oracle.com/cd/E27559_01/dev.1112/e27150/resmgt.htm#CBBFAIEC

  • Cisco SPA112 provisioning problem: FXS_Port_Power_Limit

    Hi,
    We have problems provisioning specific parameter in a SPA112: FXS_Port_Power_Limit. Here is a part of our XML:
    <Force_G729a_Code ua="na">*02729</Force_G729a_Code>
    <FXS_Port_Power_Limit ua="na">4</FXS_Port_Power_Limit>
    <FXS_Port_Input_Gain ua="na">+2</FXS_Port_Input_Gain>
    <FXS_Port_Output_Gain ua="na">+2</FXS_Port_Output_Gain>
    The parameter "FXS_Port_Power_Limit" is not provisioning the XML parameter (in the example: 4). It keeps the default value (3). Other parameters in the same section like FXS_Port_Input_Gain and FXS_Port_Output_Gain gets the XML value correctly.
    Thanks for your advice,
    Alejandro.

    I looked at the spc file for this model and don't see that parameter.
    http://software.cisco.com/download/release.html?mdfid=283998771&softwareid=282562500&release=1.3.1&relind=AVAILABLE&rellifecycle=&reltype=latest

  • Provisioning Problems with Beta 7

    I read the other thread on this and tried those things.
    I'm still having problems deploying with Beta 7.
    I followed the instructions on the dev site (the pdf).
    I generated a new generic wildcard AppID called ##########.com.mycompany.*
    Then I generated 3 new provisioning profiles for my three apps .
    All three provisioning profiles now have the same wildcard
    app id (which makes me uncomfortable but thats what the doc says to do)
    In my project/getinfo/build I have "iPhone Developer" in the Code
    signing entity under "Any iPhone OS Device".
    In the code Signing Provisioning Profile I chose the profile I made
    for my first application.
    In target/myapplication/getinfo under properties under identifier I have
    ##########.com.mycompany.*
    In info.plist under Bundle Identifier I have ##########.com.mycompany.*
    Build and go gives me the unexpected error error from Organizer.
    (0xE800..01)
    So I'm obviously doing something wrong. I see the provisioning profile
    (I'm only trying the first one at the moment) in the organizer and it is checked.
    One thing that confuses my is that on the portal all three of my profiles
    now have the same ########### prefix. This doesn't seem correct as how
    am I going to differentiate between them in the future (for uploading, etc)?
    Help! Thanks!

    OK, I got it fixed. The instructions said to use an appid of ######.* and I was using #####.com.mycompany.* which, of course, isn't the same.
    I also needed to remove the bundle id from plist and the target and just put in any string I wanted. I'll worry about that all appids are the same later...

  • User records auto provisioning problem!

    My problem is:
    I configured a access policy and a group. Upon user created the record is to be provision to OID and the record state is pre-provision.
    I can let it go through by manually clicking. How can I let it do this automatically without human operation?
    Thanks!

    What do you mean by pre-provision ?
    I think it is stuck in System Validation
    Have you checked Auto Save on Process Defn of this resource. If no then check that and try provisioning again.

Maybe you are looking for

  • SOAP to RFC Scenario - Error at Sender Communication channel !!

    Hi Experts , I am trying to execute a SOAP to RFC scenario . At SOAP sender channel level I am getting the error in RWB . My findings :- 1. Error at RWB  9/24/09 4:24:10 PM   error occured                          9/24/09 4:24:06 PM   request receive

  • Index/Welcome page not coming up??

    Greetings - I am just getting things switched over from Windoze to our new iMac, and I finally figured out how to get my old web pages into iWeb for updating and publishing. I am able to get the site published to a folder (I'm not using .mac) and the

  • FCPX does not show my projects or events

    All files are where they should be. I've repaired file permissions. There's only one new event present. It's named as a date.

  • F-4 Key on Windows 8.0 what is this function for?

    I accidentally pushed F-4 Key by itself, and my screen was wider and something pop up on the right side of my screen that had 4 choices of ???  My question is what is this function for??  And after I push it again it went back to normal.  I would als

  • Event from message

    Is it possible to make an event in iCal from a message from Mail.app ?