Sun ONE Meta-Directory 5.1.1 Administration Guide |
Chapter 2
Working with ViewsIn joining data, Meta-Directory lets you view information in two ways, in Connector Views and in Meta Views. A Connector View displays data from an external data source. A Meta View displays the integrated data from a number of Connector Views.
This chapter contains the following sections:
Working with Connector ViewsA Connector View is an LDAP representation of data that resides in an external source. Connector views provide LDAP-ready information to the Join Engine, which uses this information to build the Meta View. In order for data from the Connector View to become part of the Meta View, the Connector View must be enabled as a Participating View, in effect, allowing Connector View data to flow. Only Connector Views added to the Participating Views list will synchronize entries to and from the Meta View. (Data can flow in both directions between the Meta View and the participating Connector View.)
Note
To prevent duplicate user IDs from occurring, one Connector View should not be nested as a subtree of another Connector View. Each Connector View should be a flat tree with no subentries.
To add a Connector View instance
- Select Connector Views from the Meta-Directory Console navigation tree, and right-click.
- Select New View.
The ‘New Instance Creation’ dialog box displays.
- Enter appropriate values in the fields as described in the following table:
- Once complete, click OK. The ‘Load Schema’ dialog box displays.
- Click Yes to load the schema.
If the base entry of your schema does not exist, the ‘Subschema Subentry’ dialog box displays:
This dialog box displays because Meta-Directory has proprietary attributes that are not contained in the Directory Server. Accept the default location of cn=schema, or provide another subentry, to store these attributes and click OK.
Note
While loading the schema to a Directory Server instance which does not contain the Meta-Directory configuration information, “cannot delete” error messages might result from the ldapmodify utility trying to delete an entry that does not exist. These messages are not serious. For more information, see Appendix B, "Troubleshooting Meta-Directory."
The ‘Instance Creation Succeeded’ message is displayed once the instance is created.
To remove a Connector View instance
To enter description for a connector
Working with Meta ViewThe Meta View is a unified view of entries from one or more Connector Views; it represents the result of the join process. After the Join Engine processes the information received from a Connector View, it transfers the information to the Meta View. (Like the Connector View, the Meta View is a sub-tree on a Directory Server.) From the Meta View, you can view linked entries as well as modify them and send the changes back to the original entries via the Connector Views.
When you create an instance of the Join Engine, the Meta View is created at the same time. You can see the Meta View icon in the Meta-Directory console navigation tree under the Join Engine instance you created. It is an empty Meta View until it is joined with at least one Connector View. Meta-Directory supports only one Meta View per Join Engine instance.
For information on creating instances of the Join Engine and creating a Meta View, see "Creating the Join Engine Instance" of Chapter 1, "Configuring the Join Engine."
To enter descriptive information for a Meta View
Creating New Data in the Meta View
New data can be added to the database using the Meta View. Once the Join Engine is installed and a Meta View is created, new entries, groups and organizations can be integrated with existing data.
To create an entry in the Meta View
- Select the Contents of the Meta View.
- Choose Object > New > User. The ‘Create New User’ dialog box displays.
- Enter appropriate values in the fields as described in the following table:
- Optional: Select a language and provide language-specific user information.
- Optional: If using the NT Domain connector, enable NT User Attributes and provide the necessary information.
- Optional: If using the Posix operating system, enable Posix User Attributes and provide the necessary information.
- Once complete, click OK.
The user name is displayed in the Contents of the Meta View in the Meta-Directory console.
To create a group in the Meta View
- Select the Contents of the Meta View.
- Choose Object > New > Group. The ‘Create New Group’ dialog box displays.
- Enter appropriate values in the fields as described in the following table:
Table 2-3 Description of the options and the tasks to perform for each option
Group Name
Specify the name of the group.
Description
Specify a description of the group.
- Select the entries to become members of this group.
- Optional: Select a language and provide language-specific user information.
- Once complete, click OK.
The new group name is displayed in the Contents of the Meta View in the Meta-Directory console.
To create an organization in the Meta View
- Select the Contents of the Meta View.
- Choose Object > New > Organization. The ‘Create New Organization’ dialog box displays.
- Enter appropriate values in the fields as described in the following table:
- Optional: Select a language and provide language-specific user information.
- Once complete, click OK.
The new organization name is displayed in the Contents of the Meta View in the Meta-Directory console.
To modify an entry in the Meta View
Working with Participating ViewsIn order for a Connector View to be accessed by the Meta View it must be added as a Participating View and configured to participate in the join process. Once a Connector View becomes a Participating View and is enabled, data can flow bi-directionally between that view and the Meta View.
Once a Participating View is added, it is configured by applying join process rules to it. Each participating Connector View is configured separately. Enabling the Participating View is the final step in allowing the Connector View to participate in the join process.
To add a Participating View
- From the Meta-Directory console (navigation tree), right-click the Participating Views object.
- Click Add Participating View. The ‘Select View’ dialog box displays.
- Select the Connector View or the specific views to synchronize to the Meta View.
- Once complete, click OK. Selected views are added to the navigation tree:
To remove a Participating View
Configuring a Participating View
Before enabling a Participating View, you must configure it so that data flow between the Connector View and the Meta View can be managed. Join process rules are applied to the Participating View which the Join Engine will then apply to the Connector View entries. In addition, you can specify capability settings, refresh schedules and group filters for each Participating View.
To configure a Participating View
- Select the participating Connector View to configure, and then select the Configuration tab
.- Select the appropriate combinations of rules from the list boxes, and click Save.
- Select rule sets for Attribute Flow, Join Rules, DN Mapping Rules, and Filters. The choices are derived from the rules that you set up in "Creating the Join Engine Instance" of Chapter 1, "Configuring the Join Engine."
When choosing join process rules for a Participating View, Attribute Flow rules and DN Mapping rules contain a selection called Atomic. Atomic refers to Meta-Directory default rules that flow, map, and join LDAP attributes that are clearly the same. For example, when the Join Engine applies an atomic attribute flow rule, all attributes in the source entry will flow to destination entry i.e. the entry of the source replaces the entry at destination. When the Join Engine applies an atomic DN mapping rule, the RDN of the source entry is added to the base DN of the destination view to form a full DN. For instance, an RDN of user1 in a Connector View located in cn=user1,ou=cv1,o=madisonparc.com would remain the same when applied atomically to the Meta View ascn=user1,o=mv.
- For Entry Default Ownership, select Connector or Meta View from these list boxes:
- The selection made in To Connector specifies the view that owns the entries replicated from the Meta View to the Connector View.
- The selection made in To Meta View specifies the view that owns the entries replicated from the Connector View to the Meta View.
When an entry is owned by either the Meta View or the Connector View, it can only be deleted through that view. By default, an entry is owned by the view from which it originates; the default ownership can be changed with this option.
Note
Ownership here is not the same as granularity and ownership discussed in Chapter 3, "Connectors and Connector Rules." The values discussed here refer to ownership of entries shared between the Connector View and the Meta View. Chapter 7 refers to ownership of entries shared between the data source and a Connector View.
- For Entry Default Membership, select Member of CV or Not A Member of CV from these list boxes:
- The selection made in To Connector specifies whether new entries will or will not be members of the Connector View as the data flows from the Meta View to the Connector View.
- The selection made in To Meta View specifies whether new entries will or will not be members of the Connector View as the data flows from the Connector View to the Meta View.
Membership identifies an entry within a Connector View that is native to the data source represented by the Connector View. Rules can then be configured and applied based on the attributes that are already present in the data source.
- Select the Capabilities tab. This helps you set the behavior for the data flow between the Meta View and Connector View:
- Select the Schedule tab.
In the Schedule tab, you can configure a refresh schedule for the participating Connector View. (If no schedule is configured, the view will only be refreshed manually.)
- Click New to add a new schedule entry.
The scheduler can operate as many times as once every second; therefore, the finest granularity occurs every second.
- Change the default values in the list boxes and field entries at the bottom of the window to schedule the desired task.
Alternatively, you can provide settings in a tabular format by clicking Advanced. The ‘Advanced Schedule Options’ dialog box displays.
Numerals can be used in the Advanced Schedule Options fields:
Sample data in different fields and their interpretation:
Example 1:
second specifier:12/30
minute specifier:5/15
hour specifier : 7-9
day specifier: *
month specifier:*
day of week specifier:0-6Schedule starts at 5 minutes 12 seconds past 7 and runs every 30 seconds. Schedule ends at 9. This schedule runs every day. As both seconds and minute frequency were specified minute frequency was ignored.
Example 2:
second specifier:*
minute specifier:*/45
hour specifier :7-10
day specifier:*
month specifier:*
day of week specifier:0-6Schedule starts at 0 minutes past 7 and runs every 45 minutes till 10 every day. Schedule runs at 7:00, 7:45, 8:30, 9:15
Example 3:
second specifier:*
minute specifier:*/30
hour specifier :7-9, 15-17
day specifier:*
month specifier:*
day of week specifier:0Schedule runs at 7:00, 7:30, 8:00, 8:30,15:00,15:30,16:00,16:30 every sunday.
Example 4:
second specifier: *
minute specifier:10/15
hour specifier :22-3
day specifier:*
month specifier:*
day of week specifier:0-6Schedule runs at 22:10, 22:25,22:40,22:55,23:10,23:25,23:40,23:55 every day. 22-3 in hour range was rounded off to 22-23:59 as x > y in the hour range.
- Click Update.
- Select the Group Filters tab.
The Group Filters tab enables you to create one or more filters for LDAP data sources. You can use the group filters to refresh entries of a Connector View only. The format of the filter is (attribute=value). Note that the parentheses are part of the syntax.
When you refresh groups, the Join Engine refreshes only the entries that match the group filter or filters you have specified. For information about refreshing groups, see "Join Engine Operations".
- Click Save when you finished configuring the participating Connector View.
The connector instance must be restarted to activate it’s configuration. For procedures on how to stop and re-start the connector, see Chapter 12, "Starting and Stopping Components."
Enabling a Participating View
In order to flow data, a Participating View must be enabled. Enabling is what allows data to flow. Before enabling it, a Connector View must be added and configured as a Participating View.
To enable a Participating View
- Click the Status tab from above the navigation tree window in Meta-Directory console.Select the Join Engine from the navigation tree and click the Operations tab.
For more information on Join Engine and Connector View operations, see "Operations" of Chapter 13, "Monitoring Meta-Directory Components."
- Select a Participating View listed in the View list box that is disabled.
The View list box has two columns: View and Status. (The size of the View column can be reduced by dragging the column divider to the left; this should make the Status column visible. Both columns can be increased in size by enlarging the console window.) All added Participating Views are listed in these columns along with their status: Enabled or Disabled.
- Select Enable from the Operation drop-down list.
- Click Start.
The status of the view changes from Disabled to Enabled allowing data to flow to the Meta View. Any error in the Connector View’s configuration will automatically disable the Participating View.
- Select Refresh from the Operation List Window, then select either Meta View or Connector View from the Traverse menu list.
Once the Participating View is enabled, you should refresh it to update the data.
- Click Start.
Checking Entry Links
There are several reasons why an entry in a Connector View might not link up to an entry in the Meta View. One reason is that the Join Engine found more than one entry to link to. Another possible reason is that the external data contains errors. Because of these possibilities, you should check, as a standard procedure, for errors and omissions by doing one or both of the following:
- Review the Directory Server error log for reports of failures. This can be done by using a Perl script or using the command grep -i fail *.log in the log directory.
- As discussed in Chapter 14, "Administration Tools," use the Query Tool to check for entries which were not linked.
If you find errors, you can use join commands in the Fix-It Tool to fix the problems as described in Chapter 14, "Administration Tools."
Refreshing the ViewsTo incorporate new or modified data or to bypass regularly scheduled refresh synchronizations for immediate updates, you use the Refresh option of the specific Meta-Directory component. In addition, to flow entries that preexist in a Connector View, you must refresh the Connector View’s enabled Participating View.
Refreshing Meta Views
When the Meta Views are refreshed, the join rules are applied again to every entry in the targeted view and the data is reconstructed. The other rules are then applied accordingly:
To refresh the Meta View
- Select the Status tab and the Join Engine in the Meta-Directory console’s navigation tree.
- Select the Operations tab. All Participating Views are listed in the View field.
- Select the Participating View whose data needs to be refreshed.
- Choose Refresh, Refresh Unlinked, or Refresh Groups from the Operation list box.
- If Refresh is selected, the entire view is scanned for new entries and changes to existing entries.
- If Refresh Unlinked is selected, the view is scanned for only entries that are not currently linked.
- If Refresh Groups is selected, the entire view is scanned after the application of the Group Filter. (The group filter is an LDAP filter used to select certain entries prior to refresh. Information on configuring group filters can be found on "Select the Group Filters tab.".)
- Select Meta View or Connector View from the Traverse menu.
Selecting Meta View will re-apply join rules to all entries in the Meta View and, similarly, selecting Connector View will re-apply join rules to all entries in the Connector View.
- Click Submit Request to start the operation.
Refreshing the External Data or Connector View
New or modified data flowing to the external directory or Connector View of a specific connector can be refreshed.
To refresh External Data or the Connector View
- Select the Status tab. Select the connector to refresh from the navigation tree.
- Select the Operations tab.
The Participating View of a connector is listed in the View field.
- Select the Participating View.
- Choose Refresh from the Operation list box.
- Select External Directory or Connector View from the Updates to the list box.
Selecting External Directory will refresh the external data source with new data or data modifications made in the Meta View and transferred to the Connector View. Selecting Connector View will refresh the Connector View with new data or data modifications made in the external data source.
- Click Start to begin the process. The ‘Modify Task Status’ dialog box displays.
- Select the refresh operation type, and then click OK.
If you are updating the external directory, you will be asked to choose the from the following options:
- Re-propagate all existing entries in the Connector View to the External Directory immediately.
- Propagate all existing entries in the Connector View that meet the filter criteria to the External Directory immediately.
- Select the filter desired. Only those configured for the ‘NoSubtreesExcept’ option are displayed when Select Filter... is chosen, not filters configured for the ‘AllSubtreesExcept’ option.
- Perform the above two operations in sequence.
If you are updating the Connector View, the only option is to delete from the Connector View all existing entries that originate in the external data source.
If you are refreshing the external directory, the ‘Modify Task Status’ dialog box displays.
You must select a filter for the second and third options. Only filters configured for the ‘NoSubtreesExcept’ option are displayed when you click Select Filter, not filters configured for the ‘AllSubtreesExcept’ option.