A Attribute Mappings Between Oracle Identity Manager and Oracle Internet Directory

The following table discusses attribute mappings between Oracle Identity Manager and Oracle Internet Directory:

Note:

Apply the following guideline while performing provisioning operations:

Some Asian languages use multibyte character sets. If the character limit for the fields in the target system is specified in bytes, then the number of Asian-language characters that you can enter in a particular field may be less than the number of English-language characters that you can enter in the same field. The following example illustrates this limitation:

Suppose you can enter 50 characters of English in the User Last Name field of the target system. If you have configured the target system for the Japanese language, then you would not be able to enter more than 25 characters in the same field.

Oracle Identity Manager Attribute Oracle Internet Directory attribute Description

User ID

cn

Login ID

First Name

givenname

First name

Last Name

sn

Last name or surname

Organizational Unit

o

Organization to which the user belongs

Email

mail

E-mail address

ldapUserDisableAttr

orclisEnabled

This attribute specifies whether or not the user account is locked. If the value is DISABLED, then it means that the account is locked. If the value is ENABLED, then it means that the account is not locked.

ldapOrgDNPrefix

cn

Common name of an entry (for example, organization, user, role, and group)

ldapUserDNPrefix

cn

Common name of an entry (for example, organization, user, role, and group)

ldapUserUniqueAttr

cn

Common name of an entry (for example, organization, user, role, and group)

Middle Name

middleName

Middle name

ldapUserObjectClass

inetOrgPerson

Object class for the user (primary)

GroupName

uniquemember

Multivalued attribute for the group object, which shows the number of users in the group

RoleName

RoleOccupant

Multivalued attribute for the role object, which shows the number of users in the role

UserGroup

groupOfUniqueNames

Object class for the group

UserRole

OrganizationalRole

Object class for the role

ldapUserDNPrefix

cn

Common name of an entry (for example, organization, user, role, and group)

ldapObjectClass

objectclass

Object class

ldapGroupDNPrefix

cn

Common name of an entry (for example, organization, user, role, and group)

Title

title

Designation

Location

l

City of office address

Telephone

telephoneNumber

Office telephone number

Department

departmentNumber

Department name

Preferred Language

PreferredLanguage

Preferred language for communication

ldapPassword

userPassword

Password

Time Zone

orclTimeZone

Time zone

ldapRoleDNPrefix

cn

Common name of an entry (for example, organization, user, role, and group)

ldapRoleMemberAttr

RoleOccupant

Custom object class for the role

Section 4.8, "Adding Custom Object Classes for Provisioning" provides information about how to add a custom object class.

ldapUserObjectClassSecondary

orclUserV2

Object class for the user (secondary)

ldapOrgDNPrefix

cn

Common name of an entry (for example, organization, user, role, and Group)