Creating Join View Adapters

Creating and Configuring Oracle Virtual Directory Adapters 12-29 7. Enter the name of the adapter you want to perform a bind verification with into the Bind Adapter field, or click Browse and select the adapter. While an LDAP client can bind with a DN based on the primary adapter, it may be that the password will be verified against a joined entry in another adapter. The Bind Adapter must be either the primary adapter or one of the joined adapters.

8. Click Next. The Summary screen appears displaying a summary of the Join View

Adapter settings.

9. Review the Join View Adapter settings and click Finish to create the Join View

Adapter. The new Join View Adapter appears in the Adapter tree. After you create the Join View Adapter you can configure it using the procedures in Configuring Local Store Adapters .

12.4.1 Configuring Join View Adapters

This section describes how to configure Join View Adapter settings, including: ■ Configuring Join View Adapter General Settings and Join Rules ■ Configuring Adapter Routing ■ Configuring Adapter Plug-ins and Mappings

12.4.1.1 Configuring Join View Adapter General Settings and Join Rules

After you create the Join View Adapter you can configure the general settings and Join Rules for the adapter by clicking the adapter name in the Adapter tree, clicking the General tab, setting values for the following fields, and clicking Apply: Root This field defines the root DN that the adapter provides information for. The DN defined, and the child entries below it, comprise the adapter’s namespace. The value you enter in this field should be the base DN value for returned entries. For example, if you enter dc=mydomain,dc=com in the field, all entries end with dc=mydomain,dc=com. Active An adapter can be configured as active enabled or inactive disabled. An adapter configured as inactive does not start during a server restart or an attempted adapter start. Use the inactive setting to keep old configurations available or in stand-by without having to delete them from the configuration. The default setting is active. The following fields appear in the Settings section of the General tab: DN Attributes List of attributes to be treated as DNs for which namespace translation is required, such as member, uniquemember, manager. For example, when reading a group entry Note: After defining and debugging a Join View, you can set the primary adapter’s Visibility routing setting to Invisible to hide un-joined entries from LDAP clients. Caution: Ensure that the root DN of the Join View Adapter is different from that of its primary adapter or any of the joined adapters, otherwise you can cause unexpected duplicate results. 12-30 Oracle Fusion Middleware Administrators Guide for Oracle Virtual Directory from a proxied directory, Oracle Virtual Directory automatically converts the DN for the group entry itself and the uniquemember or member attributes if these attributes are in the DN Attributes list. To add attributes to the Map DN Attributes list:

1. Click Add. The Select DN Attribute dialog box appears.

2. Select the attribute you want to add.

3. Click OK.

Primary Adapter The primary adapter is the primary driver of data in the Join View and is used by the Join View Adapter to construct its directory hierarchy. Entries in the Join View Adapter only exist if they exist in the primary adapter. The primary adapter can be any adapter. Refer to Join View Adapters Primary Adapter on page 2-14 for more information. Bind Adapter A list of one or more adapter names to be used for bind processing. By default, the primary adapter is used, however you can override this and list one or more other adapters. The Join View Adapter attempts to complete joins against the target adapter and process the bind. If the bind succeeds, processing stops and success is returned to the client. If the bind fails, the Join View Adapter continues trying each adapter in the Bind Adapter list. Only when all bind adapters have failed is a bind failure returned. This is useful when user identities exist in multiple directories and you want to give clients the opportunity to try password validation against multiple directories. Join Rules Perform the following steps to create join relationships for Join View Adapters:

1. Click the Create button. The Join Rule dialog box appears.

2. Select the adapter from the Adapter list to join with the Join View adapter. 3. Select the type of join relationship for the Join View Adapter by choosing a join relationship from the Type list. Refer to