Identity Manager 8.0 - Administration Guide for Connecting to IBM Notes

Managing IBM Notes Environments Setting up IBM Notes Synchronization Basic Configuration Data Notes Domains Notes Certificates Notes Templates Notes Policies Notes User Accounts Notes Groups Mail-In Databases Notes Servers Using AdminP Requests for Handling IBM Notes Processes Reports about Notes Domains Appendix: Configuration Parameters for Synchronization with a Notes Domain Appendix: Default Project Template for IBM Notes

General Master Data for a Notes Domain

Enter the following data on the General tab:

Table 26: General Master Data for a Notes Domain
Property Description
Full name Full domain name.
Display name The display name is used to display the domain in the user interface.

Account definition (initial)

Initial account definition for creating user accounts. These account definitions are used if automatic assignment of employees to user account is used for this domain resulting in administered user accounts (state "Linked configured"). The account definition's default manage level is applied.

User accounts are only linked to the employee (state "Linked") if no account definition is given. This is the case on initial synchronization, for example.

Target system managers Application role in which target system managers are specified for the domain. Target system managers only edit the objects from domains that are assigned to them. Each domain can have different target system managers assigned to it.

Select the One Identity Manager application role whose members are responsible for administration of this domain. Use the button to add a new application role.

Synchronized by Type of synchronization through which data is synchronized between the domain and One Identity Manager.
Table 27: Permitted Values
Value SynchronizationClosed by ProvisioningClosed by

One Identity Manager

IBM Notes connector

IBM Notes connector

No synchronization



NOTE: You can only specify the synchronization type, if you add a new domain. No changes can be made after saving.

One Identity Manager is used when you create a domain with the Synchronization EditorClosed.

NOTE: If you select "No synchronization" you can define custom processes to exchange data between One Identity Manager and the target system.
User ID file path Path of the gateway server used for creating new user ID files. This data is only required if the configuration parameter "TargetSystem\NDO\StoreIDInAddressbook" is not set.
Description Spare text box for additional explanation.
ID vault enabled Specifies whether IBM Notes ID vault function is used to restore user ID files.
Specifying Categories for Inheriting Notes Groups

In One Identity Manager, groups can be selectively inherited by user accounts. For this, groups and user accounts are divided into categories. The categories can be freely selected and are specified by a template. Each category is given a specific position within the template. The template contains two tables; the user account table and the group table. Use the user account table to specify categories for target system dependent user accounts. Enter your categories for the target system dependent groups, administrative roles, subscriptions and disabled service plans in the . Each table contains the category items "Position1" to "Position31".

To define a category

  1. Select the category IBM Notes | Domains.
  2. Select the domain in the result list.
  3. Select Change master data in the task view.
  4. Switch to the MappingClosed rule category tab.
  5. Expand the respective base node of the user account or group table.
  6. Click to enable category.
  7. Enter a name for the user account and group categories in the current language.
  8. Save the changes.
How to Edit a Synchronization Project

SynchronizationClosed projects, in which a domain is already used as a base object, can also be opened using the Manager. You can, for example, check the configuration or view the synchronization log in this mode. The Synchronization EditorClosed is not started with its full functionality. You cannot run certain functions, such as, running synchronization or simulation, starting the target system browser and others.

NOTE: The Manager is locked for editing throughout. To edit objects in the Manager, close the Synchronization Editor.

To open an existing synchronization project in the Synchronization Editor

  1. Select the category IBM Notes | Domains.
  2. Select the domain in the result list. Select Change master data in the task view.
  3. Select Edit synchronization project... from the task view.
Notes Certificates

Notes Certificates

Certificates are loaded into the One Identity Manager database through synchronization, so they can be referenced when new user accounts are added. User accounts, which are added with One Identity Manager contain a reference to the certificate in use. This means, you can recover their ID files with this certificate at anytime. The certificate is the deciding factor for mapping more user account properties when managing user accounts with account definitions.

You can only synchronize Domino Directory certificates. If a user in the target system has been created with an external certificate, the One Identity Manager cannot determine the certificate and therefore cannot allocate it to the user account.

To edit a certificate

  1. Select the category IBM Notes | Certificates.
  2. Select a certificate in the result list. Select Change master data in the task view.
  3. Enter the required data on the master data form.
  4. Save the changes.
