After you install Identity Manager and the driver, you create a Driver object. A Driver object represents an instance of the Identity Manager Driver for SIF.
A driver configuration file, SIFAgent.xml, is provided to get you up and running with a minimum of customization. This section explains what the driver configuration does.
For information about Identity Manager in general, see "Overview" in the Novell Nsure Identity Manager 2 Administration Guide.
The following tables describe what the configuration does to provision user accounts and keep eDirectory updated when changes occur in the student information system.
In this section:
Change in Student Data | Synchronization in eDirectory |
---|---|
A student is added |
|
A student's information is modified |
|
A student withdraws from school or graduates |
|
A student returns to the school system (an Entry Date that is newer than the Exit Date is entered in the student information system) |
|
A student is removed from the student information system |
|
Change in Staff Data | Synchronization in eDirectory |
---|---|
Staff is added |
|
Staff information is modified |
|
Staff removed from the student information system |
|
The Identity Manager Driver for SIF uses data from the student information system to synchronize the following User class attributes in eDirectory:
The SIF Driver is generally used to provision users from a SIF-enabled student information system to eDirectory. The driver is configured, by default, to send no data from eDirectory to the Zone Integration Server (ZIS) and the student information system. The student information system is considered to be the authoritative data source.
However, the driver is capable of bidirectional synchronization and can send data to the ZIS and SIF. There are two ways you might choose to use this bidirectional capability:
If you want eDirectory to be the authoritative source for some user attributes, you could configure the driver to send certain attributes from eDirectory to SIF.
If your business practices allow users to be entered manually in eDirectory who are not entered in the student information system first, you could also configure the driver to send new users from eDirectory to SIF.
If your student information system is not SIF-enabled, but you have other SIF-enabled applications, you might choose to configure the SIF Driver to function as the authoritative source for students and staff.
In this role, the SIF Driver is the SIF provider for StudentPersonal, StudentSchoolEnrollment, SchoolInfo, StaffPersonal, and SIF Authorization objects. Being the provider means this driver responds when other SIF-enabled applications send SIF queries for information about students and staff.
For example, you could export student and staff information from your student information system and import it into eDirectory, using a database import. At the start of the school year, the other SIF Agents in the Zone would populate their databases by querying for all students. If you register the SIF Driver as the provider for the Zone, the queries would be routed to the SIF Driver. During the school year, as student and staff information in eDirectory is updated, either by database import or by updating manually, the SIF Driver would send those updates to SIF, thereby keeping the other SIF-enabled applications current.
You would not enable this option if you have a SIF-enabled student information system. Only one Agent in a Zone can be the provider. If you have a SIF-enabled student information system, we recommend that the student information system be the provider.
If you configure the Novell SIF Driver to send new users or to be the provider of all student and staff information, at a minimum you must provide the following user attributes when creating a user object in eDirectory. A new user object is not sent from eDirectory to SIF unless these attributes have values.
Type of User Account | Attribute |
---|---|
Student |
Given Name |
|
Surname |
|
DirXML-sifGrade |
|
DirXML-sifGradYear |
|
DirXML-sifSchool |
|
DirXML-sifSISID |
Staff |
Given Name |
|
Surname |
|
DirXML-sifSISID |