Customizing the synchronization configuration
Having used the Synchronization Editor to set up a synchronization project for initial synchronization of a Unix host, you can use the synchronization project to load Unix objects into the One Identity Manager database. If you manage user accounts and their authorizations with One Identity Manager, changes are provisioned in the Unix-based target system.
You must customize the synchronization configuration in order to compare the database with the Unix-based target system regularly and to synchronize changes.
- To use One Identity Manager as the master system during synchronization, create a workflow with synchronization in the direction of the Target system.
- You can use variables to create generally applicable synchronization configurations that contain the necessary information about the synchronization objects when synchronization starts. Variables can be implemented in base objects, schema classes, or processing methods, for example.
- Use variables to set up a synchronization project for synchronizing different hosts. Store a connection parameter as a variable for logging onto the hosts.
- To specify which Unix objects and database objects are included in synchronization, edit the scope of the target system connection and the One Identity Manager database connection. To prevent data inconsistencies, define the same scope in both systems. If no scope is defined, all objects will be synchronized.
- Update the schema in the synchronization project if the One Identity Manager schema or target system schema has changed. Then you can add the changes to the mapping.
IMPORTANT: As long as a synchronization process is running, you must not start another synchronization process for the same target system. This especially applies, if the same synchronization objects would be processed.
-
If another synchronization process is started with the same start up configuration, the process is stopped and is assigned Frozen status. An error message is written to the One Identity Manager Service log file.
-
Starting another synchronization process with different start up configuration that addresses same target system may lead to synchronization errors or loss of data. Specify One Identity Manager behavior in this case, in the start up configuration.
For more detailed information about configuring synchronization, see the One Identity Manager Target System Synchronization Reference Guide.
Detailed information about this topic
Configuring Unix host synchronization
The synchronization project for initial synchronization provides a workflow for initial loading of target system objects (initial synchronization) and one for provisioning object modifications from the One Identity Manager database to the target system (provisioning). To use One Identity Manager as the master system during synchronization, you also require a workflow with synchronization in the direction of the Target system.
To create a synchronization configuration for synchronizing a Unix host
-
Open the synchronization project in the Synchronization Editor.
- Check whether existing mappings can be used for synchronizing the target system. Create new maps if required.
- Create a new workflow with the workflow wizard.
This creates a workflow with Target system as its synchronization direction.
- Create a new start up configuration. Use the new workflow to do this.
- Save the changes.
-
Run a consistency check.
Detailed information about this topic
Configuring synchronization of several Unix hosts
Prerequisites
- The target system schema of both hosts are identical.
- All virtual schema properties used in the mapping must exist in the extended schema of both hosts.
To customize a synchronization project for synchronizing another host
- Prepare a user account with sufficient permissions for synchronizing in the other host.
-
Open the synchronization project in the Synchronization Editor.
-
Create a new base object for the other host. Use the wizard to attach a base object.
-
In the wizard, select the Unix or AIX connector and declare the connection parameters. The connection parameters are saved in a special variable set.
A start up configuration is created that uses the newly created variable set.
-
Change other elements of the synchronization configuration as required.
- Save the changes.
-
Run a consistency check.
Related topics
Updating schemas
All the schema data (schema types and schema properties) of the target system schema and the One Identity Manager schema are available when you are editing a synchronization project. Only a part of this data is really needed for configuring synchronization. If a synchronization project is finished, the schema is compressed to remove unnecessary data from the synchronization project. This can speed up the loading of the synchronization project. Deleted schema data can be added to the synchronization configuration again at a later point.
If the target system schema or the One Identity Manager schema has changed, these changes must also be added to the synchronization configuration. Then the changes can be added to the schema property mapping.
To include schema data that have been deleted through compression and schema modifications in the synchronization project, update each schema in the synchronization project. This may be necessary if:
To update a system connection schema
-
Open the synchronization project in the Synchronization Editor.
-
Select the Configuration | Target system category.
- OR -
Select the Configuration | One Identity Manager connection category.
-
Select the General view and click Update schema.
- Confirm the security prompt with Yes.
This reloads the schema data.
To edit a mapping
-
Open the synchronization project in the Synchronization Editor.
-
Select the Mappings category.
-
Select a mapping in the navigation view.
Opens the Mapping Editor. For more detailed information about mappings, see the One Identity Manager Target System Synchronization Reference Guide.
NOTE: The synchronization is deactivated if the schema of an activated synchronization project is updated. Reactivate the synchronization project to synchronize.