Step 5: Customizing the IBM Tivoli Directory Server Connector to Synchronize Deletions

22-2 Oracle Fusion Middleware Administrators Guide for Oracle Directory Integration Platform

22.2 Configuring Basic Synchronization with Novell eDirectory or OpenLDAP

You can use the expressSyncSetup command to quickly establish synchronization between Oracle Internet Directory and Novell eDirectory or OpenLDAP. expressSyncSetup uses default settings to automatically perform all required configurations To use expressSyncSetup to synchronize with Novell eDirectory or OpenLDAP, refer to Creating Import and Export Synchronization Profiles Using expressSyncSetup on page 17-2. 22.2.1 Synchronizing Multiple Profiles from eDirectory or OpenLDAP to One Oracle Internet Directory Container When synchronizing multiple profiles from eDirectory or OpenLDAP to one Oracle Internet Directory container, you must filter out only the specific users to be reconciled to prevent the reconciliation process from inadvertently deleting users. You can filter out only the specific users to be reconciled by performing either of the following steps: ■ Modify the mapping rule so each profile creates the user in a different container. Refer to Customizing Mapping Rules on page 17-9 for more information. ■ Modify the reconciliation rules in the mapping file to synchronize only a specific subset of users. Refer to How Do I Define a Reconciliation Rule? on page 22-5 for more information.

22.3 Configuring Advanced Integration with Novell eDirectory or OpenLDAP

When you install Oracle Directory Integration Platform, sample import and export synchronization profiles are automatically created for each of the supported third-party directories. The sample synchronization profiles created for Novell eDirectory are: ■ Novell eDirectoryImp—The profile for importing changes from Novell eDirectory to Oracle Internet Directory ■ Novell eDirectoryExp—The profile for exporting changes from Oracle Internet Directory to Novell eDirectory The sample synchronization profiles created for OpenLDAP are: ■ OpenLDAPImport—The profile for importing changes from OpenLDAP to Oracle Internet Directory ■ OpenLDAPExport—The profile for exporting changes from Oracle Internet Directory to OpenLDAP You can also use the expressSyncSetup command or Oracle Enterprise Manager Fusion Middleware Control to create additional synchronization profiles. The import and export synchronization profiles created during the install process or with Note: To reconcile correctly, additions and deletions must be performed from only one of the synchronized directories. In other words, you can perform additions and deletions from Oracle Internet Directory or eDirectoryOpenLDAP, but not both. However, modifications can be performed from either directory. Integrating with Novell eDirectory or OpenLDAP 22-3 expressSyncSetup are only intended as a starting point for you to use when deploying your integration of Oracle Internet Directory and Novell eDirectory or OpenLDAP. Because the default synchronization profiles are created using predefined assumptions, you must further customize them for your environment by performing the following steps in the order listed: ■ Step 1: Planning Your Integration ■ Step 2: Configuring the Realm ■ Step 3: Customizing the Search Filter to Retrieve Information from Novell eDirectory or OpenLDAP ■ Step 4: Customizing the ACLs ■ Step 5: Customizing Attribute Mappings ■ Step 6: Customizing the Novell eDirectory or OpenLDAP Connector to Synchronize Deletions ■ Step 7: Specifying Synchronization Parameters for the Advanced Configuration Information Attribute ■ Step 8: Configuring the OpenLDAP Connector to Synchronize Passwords ■ Step 9: Synchronizing in SSL Mode ■ Step 10: Configuring the Novell eDirectory or OpenLDAP External Authentication Plug-in ■ Step 11: Performing Post-Configuration and Administrative Tasks

22.3.1 Step 1: Planning Your Integration

Plan your integration by reading Chapter 16, Third-Party Directory Integration Concepts and Considerations , particularly Novell eDirectory and OpenLDAP Integration Concepts on page 16-30. Be sure to create a new profile by copying the existing eDirectory or OpenLDAP template profile by following the instructions in Creating Synchronization Profiles on page 7-1.

22.3.2 Step 2: Configuring the Realm

Configure the realm by following the instructions in Configuring the Realm on page 17-7. 22.3.3 Step 3: Customizing the Search Filter to Retrieve Information from Novell eDirectory or OpenLDAP By default, the Novell eDirectory or OpenLDAP Connector retrieves changes to all objects in the container based on the modifytimestamp attribute. If you are interested in retrieving changes to specific types of objects, such as changes to users and groups, then you should configure an LDAP search filter. This filter screens out changes that are not required when the Novell eDirectory or OpenLDAP Connector queries Novell eDirectory or OpenLDAP. The filter is stored in the connected directory matching filter attribute orclodipcondirmatchingfilter in the synchronization profile. The Novell eDirectory and OpenLDAP sample import profiles are configured to retrieve changes to users, groups, and container objects from Novell eDirectory and OpenLDAP, respectively. Computers are not retrieved. The value of the searchfilter attribute is set as follows: