Global configuration values (GCVs) are values that can be used by the driver to control functionality. GCVs are defined on the driver or on the driver set. Driver set GCVs can be used by all drivers in the driver set. Driver GCVs can be used only by the driver on which they are defined.
The LDAP driver includes many GCVs. You can also add your own if you discover you need additional ones as you implement policies in the driver.
To access the driver’s GCVs in iManager:
Click to display the Identity Manager Administration page.
Open the driver set that contains the driver whose properties you want to edit.
In the
list, click .If the driver set is not listed on the
tab, use the field to search for and display the driver set.Click the driver set to open the Driver Set Overview page.
Locate the driver icon, click the upper right corner of the driver icon to display the
menu, then click .or
To add a GCV to the driver set, click
, then click .To access the driver’s GCVs in Designer:
Open a project in the Modeler.
Right-click the driver icon or line, then select
or
To add a GCV to the driver set, right-clickthe driver set icon , then click
.The global configuration values are organized as follows:
Table A-6 Driver Parameters
Table A-7 Entitlements
Option |
Description |
---|---|
|
Select to display the global configuration values for entitlements. Select to not have the global configuration values displayed.The driver can use entitlements to manage user accounts and group memberships in the connected LDAP directory. When using entitlements, the driver works in conjunction with entitlement agents such as the Identity Manager User Application or Role-Based Entitlements to control the conditions under provisioning occurs. See Entitlements for more information. |
|
Select to enable the driver to manage LDAP accounts based on the driver’s defined entitlements.Select to disable management of LDAP accounts based on the entitlements. |
|
Select the action that you want to occur in the LDAP directory if a user in the Identity Vault does not have the LDAP account entitlement. Select to not affect the LDAP directory, or select to remove the user’s LDAP account. |
Table A-8 Password Management
Option |
Description |
---|---|
|
Select to display the global configuration values for password management. Select to not have the password management global configuration values displayed.In Designer, you must click the icon next to an option to edit it. This displays the Password Synchronization Options dialog box that has a better view of the relationship between the different GCVs. In iManager, you should edit the Password Management Options on the tab rather than under the GCVs. The Server Variables page has a better view of the relationship between the different GCVs.For more information about how to use the Password Management GCVs, see |
|
If , allows passwords to flow from the Identity Manager data store to the connected system. |
|
If , allows passwords to flow from the connected system to Identity Manager. |
|
Use the password from the connected system to set the non-reversible NDS password in eDirectory. |
|
Use the password from the connected system to set the NMAS Distribution Password used for Identity Manager password synchronization. |
|
If , applies NMAS password policies during publish password operations. The password is not written to the data store if it does not comply. |
|
If , on a publish Distribution Password failure, attempts to reset the password in the connected system by using the Distribution Password from the Identity Manager data store. |
|
If , notify the user by e-mail of any password synchronization failures. |
Table A-9 Account Tracking
Option |
Description |
---|---|
|
Select to display the global configuration values for account tracking through Novell Sentinel. Select to not have the global configuration values displayed.The account tracking GCVs enable Sentinel to track Active Directory* accounts based on unique identifiers that you define. You must have both Sentinel 6.1 and the Identity Manager Driver for Sentinel 6.1 installed in order to track account information. For information about Sentinel, see the Sentinel 6.1 Documentation Web site. The Identity Manager Driver for Sentinel 6.1 is included with the Novell Compliance Management Platform. For information, see the Identity and Security Management product Web site. |