The following configuration parameters are additionally available in One Identity Manager after the module has been installed.
Configuration parameter | Description |
---|---|
TargetSystem | LDAP |
Preprocessor relevant configuration parameter for controlling the database model components for the administration of the target system LDAP. If the parameter is set, the target system components are available. Changes to this parameter require the database to be recompiled. |
TargetSystem | LDAP | Accounts |
This configuration parameter permits configuration of user account data. |
TargetSystem | LDAP | Accounts |
This configuration parameter specifies whether a random generated password is issued when a new user account is added. The password must contain at least those character sets that are defined in the password policy. |
TargetSystem | LDAP | Accounts | |
This configuration parameter specifies to which employee the email with the random generated password should be sent (manager cost center/department/location/business role, employee’s manager or XUserInserted). If no recipient can be found, the password is sent to the address stored in the TargetSystem | LDAP | DefaultAddress configuration parameter. |
TargetSystem | LDAP | Accounts | |
This configuration parameter contains the name of the mail template sent to provide users with the login data for their user accounts. The Employee - new user account created mail template is used. |
TargetSystem | LDAP | Accounts | |
This configuration parameter contains the name of the mail template sent to provide users with information about their initial password. The Employee - initial password for new user account mail template is used. |
TargetSystem | LDAP | Accounts | |
This configuration parameter contains the mail template used to send notifications if default IT operating data mapping values are used for automatically creating a user account. The Employee - new user account with default properties created mail template is used. |
TargetSystem | LDAP | Accounts | |
This configuration parameter allows configuration of settings for privileged LDAP user accounts. |
TargetSystem | LDAP | Accounts | |
This configuration parameter contains the postfix for formatting login names for privileged user accounts. |
TargetSystem | LDAP | Accounts | |
This configuration parameter contains the prefix for formatting login names for privileged user accounts. |
TargetSystem | LDAP | Authentication |
This configuration parameter allows configuration of the LDAP authentication module. For detailed information about the One Identity Manager authentication modules, see the One Identity Manager Authorization and Authentication Guide. |
TargetSystem | LDAP | Authentication | Authentication |
This configuration parameter specified the authentication mechanism. Permitted values are Secure, Encryption, SecureSocketsLayer, ReadonlyServer, Anonymous, FastBind, Signing, Sealing, Delegation, and ServerBind. The value can be combined with commas (,). The default is ServerBind. |
TargetSystem | LDAP | Authentication | Port |
LDAP server port. The default is port 389. |
TargetSystem | LDAP | Authentication | RootDN |
The configuration parameter contains a pipe (|) delimited list of root domains to use for finding the user account for authentication. Syntax: DC=<MyDomain>|DC=<MyOtherDomain> Example: DC=Root1,DC=com|DC=Root2,DC=de |
TargetSystem | LDAP | Authentication | Server |
This configuration parameter contains the name of the LDAP server. |
TargetSystem | LDAP | DefaultAddress |
The configuration parameter contains the recipient's default email address for sending notifications about actions in the target system. |
TargetSystem | LDAP | |
The configuration parameter specifies whether computers are added to groups on the basis of group assignment to roles. |
TargetSystem | LDAP | |
This configuration parameter contains the maximum runtime for synchronization. No recalculation of group memberships by the DBQueue Processor can take place during this time. If the maximum runtime is exceeded, group membership are recalculated. |
TargetSystem | LDAP | |
This configuration parameter specifies the mode for automatic employee assignment for user accounts added to the database outside synchronization. |
TargetSystem | LDAP | |
This configuration parameter specifies whether employees are automatically assigned to disabled user accounts. User accounts do not obtain an account definition. |
TargetSystem | LDAP | |
This configuration parameter specifies the mode for automatic employee assignment for user accounts added to or updated in the database through synchronization. |