YardenBH Absent Member.
Absent Member.

Subscriber channel of AD driver not support object GUID

Hi all,

I encountered an issue with an irritate AD Sub channel behavior regarding group membership management, and I hope someone around here could advise.
Our client environment include single IDM engine connected to four ADs in a single forest (all domains are trusted).
Since one IDM user can be associated to one or more AD user (yet only one at each domain), we use four AD drivers.

We have several cases where users in domain B (or C..) need to be assigned/removed from group in domain A . In order to escape schema mapping issue, we implemented a code that convert the user's eDirectory dn to AD dn, using custom ADContext multi valued field we maintain. The code works quite well, but while working on it we noticed strange AD Subscriber behavior.
As far as we aware, ldap group membership operations can accept two formats. Either the shim provided with a plain text of the user specific AD dn format, or with the user's association value (the AD object GUID), where the latter include an 'association-ref' xml attribute, indicating the shim should use the GUID value for the ldap operations.
When sending AD shim a group member modify event, where the member value is the user's association value (not AD dn) the shim manage to perform ldap operations only with association value of the current driver. The ldap operations involving association values, a valid AD object GUID, from other AD drivers are simply ignored.

One can easily dismiss this selective approach stating the driver can only process the assocition values of its own, yet we inquired the issue a bit farther.
Events coming up the publisher channel include an 'association-ref' xml attributes for users from a different domain, so the lack of GUID support is unique for the subscriber channel alone.

Does anyone else had encountered this issue? Or faced a cases where the group and its member were not in the same domain and can offer another method for that?
Labels (1)
2 Replies
ScorpionSting Absent Member.
Absent Member.

Re: Subscriber channel of AD driver not support object GUID

You really need to post this in the specific forum for IDM: Engine-Drivers

Visit my Website for links to Cool Solution articles.
Knowledge Partner
Knowledge Partner

Re: Subscriber channel of AD driver not support object GUID

YardenBH wrote:

> Does anyone else had encountered this issue?

Yes we have.

However as has already been mentioned, I suggest you repost this in specific
forum for 'IDM: Engine-Drivers'.

We don't move mis-posted threads like this to the correct place, instead it is
the responsibility of the original poster to re-post in the correct place.

If you find this post helpful, and are viewing this using the web, please show
your appreciation by clicking on the star below
Alex McHugh - Knowledge Partner - Stavanger, Norway
Who are the Knowledge Partners
If you appreciate my comments, please click the Like button.
If I have resolved your issue, please click the Accept as Solution button.
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.