Skip Headers
Oracle® Identity Manager Connector Guide for Novell eDirectory
Release 9.0.2

Part Number B32161-01
Go to Documentation Home
Home
Go to Table of Contents
Contents
Go to Index
Index

Go to previous page
Previous
Go to next page
Next
View PDF

3 Testing and Troubleshooting

After you deploy the connector, you must test it to ensure that it functions as expected. This chapter discusses the following topics related to connector testing:

Running Test Cases

You can use the troubleshooting utility to identify the cause of problems associated with connecting to the target system and performing basic operations on the target system.

To use the troubleshooting utility:

  1. Specify the required values in the global.properties file.

    This file is in the OIM_home\xellerate\eDir\troubleshoot directory. The following table describes the sections of this file in which you must provide information for running the tests.

    Section Information
    Novell eDirectory Server Parameters Parameters required to connect to Novell eDirectory

    Refer to the "Defining IT Resources" section for information about the values that you must provide.

    Create User Parameters Values required to create a user on the target system
    Modify User Parameters Values required to modify a user
    Delete User Parameters DN of the user to be deleted

  2. Add the following to the CLASSPATH environment variable:

    OIM_home\xellerate\lib\xlLogger.jar
    OIM_home\xellerate\lib\xlUtils.jar
    OIM_home\xellerate\JavaTasks\eDirProv.jar
    OIM_home\xellerate\JavaTasks\ldap.jar
    OIM_home\xellerate\ext\log4j-1.2.9.jar
    
    
  3. In the log.properties file in the same directory:

    1. Set the path of the directory in which you want to create the log files as the value of the following parameter:

      log4j.appender.logfile.File=log_file_path
      
      

      Here, log_file_path is the path of the directory in which you want to create the log file.

    2. Specify any one of the following log levels:

      - DEBUG

      - INFO

      - WARN

      - ERROR

      - FATAL

      For example, if the log level for DEBUG is to be enabled, then you must add the following entry file:

      log4j.rootLogger=INFO,stdout
      
      
  4. Create an ASCII-format copy of the global.properties file as follows:


    Note:

    You must perform this procedure every time you make a change in the contents of the global.properties file.

    1. In a command window, change to the following directory:

      OIM_home\xellerate\eDir\troubleshoot
      
      
    2. Enter the following command:

      native2ascii global.properties troubleshoot.properties
      
      

      The troubleshoot.properties file is created when you run the native2ascii command. The contents of this file are an ASCII-format copy of the contents of the global.properties file.

  5. Run the following tests:

    • Enter the following command to create a Novell eDirectory user:

      java  -DpropertyFile=OIM_home\xellerate\eDir\troubleshoot\troubleshoot.properties -Dlog4j.configuration=file:\OIM_home\xellerate\eDir\troubleshoot\log.properties TroubleShootingUtilityLdap createUser
      
      
    • Enter the following command to modify a Novell eDirectory user:

      java  -DpropertyFile=OIM_home\xellerate\eDir\troubleshoot\troubleshoot.properties -Dlog4j.configuration=file:\OIM_home\xellerate\eDir\troubleshoot\log.properties TroubleShootingUtilityLdap modifyUser
      
      
    • Enter the following command to delete a Novell eDirectory user:

      java  -DpropertyFile=OIM_home\xellerate\eDir\troubleshoot\troubleshoot.properties -Dlog4j.configuration=file:\OIM_home\xellerate\eDir\troubleshoot\log.properties TroubleShootingUtilityLdap deleteUser
      
      

Troubleshooting

This section provides instructions for identifying and resolving some commonly encountered errors of the following types:

Connection Errors

The following table provides solutions to some commonly encountered connection errors.

Problem Description Solution
Oracle Identity Manager cannot establish a connection to Novell eDirectory.

Returned Error Message:

LDAP connection exception

Returned Error Code:

INVALID_CONNECTION_ERROR

  • Ensure that Novell eDirectory is running.
  • Ensure that Oracle Identity Manager is running.

  • Ensure that all the adapters have been compiled.

  • Use the IT Resources form to examine the Oracle Identity Manager record. Ensure that the IP address, admin ID, and admin password are correct.

Target not available.

Returned Error Message:

Connection error - unable to create initial LDAP

Returned Error Code:

TARGET_UNAVAILABLE_ERROR

Ensure that the specified Novell eDirectory connection values are correct.
Returned Error Message:

Connection error - unable to create initial LDAP.

Returned Error Code:

AUTHENTICATION_ERROR

Ensure that the specified Novell eDirectory connection values are correct.

Create User Errors

The following table provides solutions to some commonly encountered Create User errors.

Problem Description Solution
Oracle Identity Manager cannot create a user.

Returned Error Message:

Required information missing

Returned Error Code:

INSUFFICIENT_INFORMATION_PROVIDED

  • Ensure that the specified IP address, admin ID, and administrator password are correct.
  • Ensure that the following information has been provided:

    User ID

    User password

    User container

    User first name

    User last name

Oracle Identity Manager cannot create a user.

Returned Error Message:

User already exists

Returned Error Code:

USER_ALREADY_EXISTS

A user with the assigned ID already exists in Novell eDirectory.
Oracle Identity Manager cannot create a user.

Returned Error Message:

Connection error - unable to create initial LDAP context

Returned Error Code:

INVALID_NAMING_ERROR

  • Ensure that the specified Novell eDirectory connection values are correct.
  • Check if the value for an attribute violates the schema definition.

Oracle Identity Manager cannot create a user.

Returned Error Message:

User creation failed

Returned Error Code:

USER_CREATION_FAILED

The user cannot be created because one or more attribute values violate the schema definition.
The Create User function failed because a value was being added to a nonexistent attribute.

Returned Error Message:

Attribute does not exist

Returned Error Code:

ATTRIBUTE_DOESNOT_EXIST

In the AttrName.Prov.Map.EDIR lookup definition, check if the decode values are valid attribute names in the target system.
The Create User function failed because an invalid value was specified.

Returned Error Message:

Invalid value specified for an attribute

Returned Error Code:

INVALID_ATTR_VALUE_ERROR

Check the values specified during user creation.

Modify User Errors

The following table provides solutions to some commonly encountered Modify User errors.

Problem Description Solution
Oracle Identity Manager cannot modify the value of a user.

Returned Error Message:

Invalid attribute value or state

Returned Error Code:

INVALID_ATTR_MODIFY_ERROR

Check the attribute ID and value that were specified.
The Modify User function failed because a value was being added to a nonexistent attribute.

Returned Error Message:

Attribute does not exist

Returned Error Code:

ATTRIBUTE_DOESNOT_EXIST

  1. From the corresponding process task, get the value specified for AttrName of the connector.
  2. Using the name obtained in the previous step, check in the AttrName.Prov.Map.EDIR lookup definition if the decode value is a valid attribute name in the target.

The Modify User function failed because an invalid value was specified.

Returned Error Message:

Invalid value specified for an attribute

Returned Error Code:

INVALID_ATTR_VALUE_ERROR

Check the value entered.
The Modify User function failed because a value was specified for an attribute that does not exist in the AttrName.Prov.Map.EDIR lookup definition.

Returned Error Message:

One or more attribute mappings are missing

Returned Error Code:

ATTR_MAPPING_NOT_FOUND

  1. From the corresponding process task, get the value specified for AttrName of the connector.
  2. Using the name obtained in the previous step, check if an entry has been made in the AttrName.Prov.Map.EDIR lookup definition.

Error caused because a duplicate value was specified for an attribute.

Returned Error Message:

Duplicate value

Returned Error Code:

DUPLICATE_VALUE_ERROR

The attribute specified already exists for another user in the system.
Oracle Identity Manager cannot move a user from one container to another.

Returned Error Message:

Moving user to different container failed

Returned Error Code:

USER_MOVE_FAILED

Generic error. Review the log for more details.
Oracle Identity Manager cannot add a user to a security group.

Returned Error Message:

Group does not exist

Returned Error Code:

SEC_GROUP_DOESNOT_EXIST

The specified user security group does not exist in Novell eDirectory.
Oracle Identity Manager cannot add a user to a security group.

Returned Error Message:

User is already a member of this group

Returned Error Code:

DUPLICATE_VALUE

The user is already a member of the specified security group.
Oracle Identity Manager cannot add the trustee tight to a user.

Returned Error Message:

Trustee tight already added

Returned Error Code:

DUPLICATE_VALUE

Check if the trustee right has already been assigned to the user in Novell eDirectory.
Oracle Identity Manager cannot add a role to a user.

Returned Error Message:

Role does not exist

Returned Error Code:

ROLE_DOESNOT_EXIST

The specified role for the user in Oracle Identity Manager does not exist in Novell eDirectory. Create the role in Novell eDirectory.
Oracle Identity Manager cannot add a role to a user.

Returned Error Message:

Error while updating user info

Returned Error Code:

USER_UPDATE_FAILED

Generic error. Review the log for more details
Oracle Identity Manager cannot add a role to a user.

Returned Error Message:

User has already been assigned this role

Returned Error Code:

DUPLICATE_VALUE

The user has already been assigned this role.
Oracle Identity Manager cannot remove an assigned role from a user.

Returned Error Message:

Removing assigned role failed

Returned Error Code:

USER_DELETE_ASSIGNED_ROLE_FAILED

Generic error. Review the log for more details.
Oracle Identity Manager cannot add a network restriction.

Returned Error Message:

This network restriction already exists

Returned Error Code:

DUPLICATE_VALUE

The specified network restriction already exists for this user in Novell eDirectory.

Delete User Errors

The following table provides solutions to a commonly encountered Delete User error.

Problem Description Solution
Oracle Identity Manager cannot delete a user.

Returned Error Message:

User does not exist in target

Returned Error Code:

USER_DOESNOT_EXIST

The specified user does not exist in Novell eDirectory.