What's New in Oracle Identity Manager Connector for UNIX SSH?

This chapter provides an overview of the updates made to the software and documentation for the UNIX SSH connector in release 9.0.4.15.

Note:

Release 9.0.4.15 of the connector comes after release 9.0.4.12. Release numbers 9.0.4.13 and 9.0.4.14 have not been used.

The updates discussed in this chapter are divided into the following categories:

Software Updates

The following sections discuss software updates:

Software Updates in Release 9.0.4.15

The following are software updates implemented in release 9.0.4.15:

Support for New Target System

From this release onward, the connector adds support for HP-UX version 11iv3 (11.31) as the target system.

See Section 1.1, "Certified Components" for the full list of certified target systems.

Support for Importing Request Dataset XML Files

From this release onward, the connector provides support for importing a request dataset XML file into Oracle Identity Manager by using the Deployment Manager on Oracle Identity Manager 11g release 1 (11.1.1).

The installation media of this release includes a request dataset file, SSHConnectorRequestDatasets.xml, which is available in the xml directory.

See Section 2.5.5.1, "Importing Request Datasets Using Deployment Manager" for more information.

Resolved Issues in Release 9.0.4.15

The following table describes issues resolved in release 9.0.4.15:

Bug Number Issue Resolution

12547932

The performance of the connector was slow.

This issue has been resolved. The reconciliation of records can now be initiated in parallel, which reduces the time taken for reconciliation.

9314911

The connector did not support AIX 6.1 as a target resource.

This issue has been resolved. AIX 6.1 is now supported as a target resource.

11737066

When running the SSH User Target Resource Reconciliation Task, if the number of users to be reconciled is greater than the batch size, an exception is thrown.

This issue has been resolved. The reconciliation task runs successfully for multiple batches.

7498112

The connector did not support HP-UX11I V2,V3 as a target resource.

This issue has been resolved. HP-UX11I V2,V3 is now supported as a target resource.


Software Updates in Release 9.0.4.12

The following are the software updates in release 9.0.4.12:

Support for New Oracle Identity Manager Release

From this release onward, the connector can be installed and used on Oracle Identity Manager 11g release 1 (11.1.1). Where applicable, instructions specific to this Oracle Identity Manager release have been added in the guide.

See Section 1.1, "Certified Components" for the full list of certified Oracle Identity Manager releases.

Support for Request-Based Provisioning

From this release onward, the connector provides support for request-based provisioning on Oracle Identity Manager 11g release 1 (11.1.1).

See Section 3.6.2, "Request-Based Provisioning" for more information.

Support for New Target System

From this release onward, the connector adds support for IBM AIX 5L Version 6.1 as the target system.

See Section 1.1, "Certified Components" for the full list of certified target systems.

Support for User Account Status Reconciliation

From this release onward, the connector can reconcile user account status information from the target system

Resolved Issues in Release 9.0.4.12

The following table lists issues resolved in release 9.0.4.12:

Bug Number Issue Resolution

7374688

Reconciliation of user records in the sudo mode failed because the connector attempted to run a shell.

This issue has been resolved.

9295029

When an update task failed, the status of the corresponding process task adapters changed from Provisioned to Provisioning.

This issue has been resolved. The status of the process task adapters do not change when the corresponding update task fails.

9611960

When performing a Create User provisioning operation on AIX, the group name must be specified as the value of the Primary Group Name lookup field. However, instead of displaying group names, the Primary Group Name lookup field displayed group IDs. The happened due to the following reason:

After performing lookup field synchronization by running the TelnetSSHGroupLookupReconTask scheduled task, the Code Key column of the UD_Lookup_SSH_PrimaryGroupNames lookup definition contained the group IDs, and the Decode column contained the group names.

This issue has been resolved. After you perform lookup field synchronization, the connector now reconciles group names into the Code Key column, and group IDs into the Decode column of the UD_Lookup_SSH_PrimaryGroupNames lookup definition. Therefore, for AIX and the other target systems, the connector passes the group name instead of the group ID.

9611211

The Confirm Password field on the process form required users to enter their passwords 2 times.

The Confirm Password field has been removed from the process form.


Software Updates in Release 9.0.4.11

The following table lists issues resolved in release 9.0.4.11:

Bug Number Issue Resolution

9100879

The Delete User provisioning operation did not work.

This issue has been resolved. The Delete User provisioning operation now works correctly.

9195323

The Create User provisioning operation failed when it was retried.

This issue has been resolved. The Create User provisioning operation can be retried.


Software Updates in Release 9.0.4.7

The following table lists issues resolved in release 9.0.4.7:

Bug Number Issue Resolution

7520249

During reconciliation, you could not transform values of the target system field before they were stored in Oracle Identity Manager.

This issue has been resolved. You can now transform the values of the target system fields before they are stored in Oracle Identity Manager.

See the "Transforming Data Reconciled Into Oracle Identity Manager" chapter in the connector guide for more information.

7563415

During reconciliation, the Group Name field was reconciled as a number and not as the exact name because it was stored directly as the group ID in the target system.

This issue has been resolved. During reconciliation, the exact name of the Group Name field is reconciled.

8341984

In the Create User process task, the default value of the Map To variable was IT Resource. This value was incorrect.

This issue has been resolved. The Map To variable in the Create User process task displays the correct default value. The default value of Map To variable is now Process Data.

8396795

During connector deployment, the lib/xliSSH.jar file on the installation media was not automatically copied into the OIM_HOME/xellerate/ScheduleTask directory.

This issue has been resolved. The lib/xliSSH.jar file is now automatically copied to the OIM_HOME/xellerate/ScheduleTask directory.


Software Updates in Release 9.0.4.6

The following table lists issues resolved in release 9.0.4.6:

Bug Number Issue Resolution

7478452

You use the IT resource to specify the credentials of the SUDO user that you want to use for connector operations. If this SUDO user did not have the required permissions, then the target system did not allow you to perform Disable User provisioning operations. This is expected behavior. However, the status of the user was set to Disabled on Oracle Identity Manager even though the status of the user on the target system remained unchanged.

This issue has been resolved. If the SUDO user does not have the permissions required to disable users on the target system, then an appropriate message is displayed on the Administrative and User Console.

7503701

The target system does not allow you to delete a user who is logged in to the system. This is expected behavior. However, even when the target system did not allow the deletion of a user, the status of the user (resource) on Oracle Identity Manager was changed to Deleted (Revoked).

This issue has been resolved. If the target system does not allow the deletion of a user, then an appropriate message is displayed as the outcome of the Delete User provisioning operation.

The item describing this issue has been removed from Chapter 6, "Known Issues".


Software Updates in Release 9.0.4.5

The following are software updates in release 9.0.4.5:

Support for Role-Based Access Control (RBAC) on Solaris

In earlier releases, you had to provide the credentials of the root or sudo user for letting Oracle Identity Manager communicate with the Solaris target system. This release supports the role-based access control (RBAC) feature of Solaris. From this release onward, Oracle Identity Manager can communicate with Solaris by using a user account to which you assign the minimum required privileges.

See Section 2.3.3.1.2, "Creating an RBAC User Account for Connector Operations" on for more information.

The following are some of the changes made in the IT resource:

See Chapter 2, "Deploying the Connector" for information about these parameters.

Resolved Issues in Release 9.0.4.5

The following table lists issues resolved in release 9.0.4.5:

Bug Number Issue Resolution

5503263

The "Create Home Directory" field is a check box on the Administrative and User Console. If you selected this check box, the numeral 1 was displayed on the page that summarizes input you provide during provisioning operations.

The check box has been changed to a radio button. If you select the "Create Home Directory" option, then the word "Yes" is displayed on the page that summarizes input. If you do not select the option, then the word "No" is displayed.

7133380

A user for whom an SSH account was created on AIX through a provisioning operation was forced to change the password at first login.

Password change at first login is not enforced for newly created SSH accounts on AIX.

7225692

To stop a scheduled task, you use the Stop Execution option in the Design Console. This option did not work in earlier releases.

You can now use the Stop Execution option to stop scheduled tasks.

Note: When you stop a batched reconciliation run, reconciliation stops at the end of the batch being reconciled.

7345302

During a provisioning operation, the home directory was not created if you specified an invalid path on the target system host computer. However, the status of the process task was Completed.

If an invalid home directory path is specified, then the "Invalid Home directory" error message is displayed on the Administrative and User Console.

7347256

An error was thrown when a user connected to an HP-UX target system was updated through a provisioning operation performed on Oracle Identity Manager. The response from the target system was not correctly parsed and displayed as an error message on the Administrative and User Console.

The "User currently in use" message is displayed if you try to update any attribute of a user who is currently logged in to the target system.


Software Updates in Release 9.0.4.4

The following are software updates in release 9.0.4.4:

Using the Connector Installer

From Oracle Identity Manager release 9.1.0 onward, the Administrative and User Console provides the Connector Installer feature. This feature can be used to automate the connector installation procedure.

See Section 2.4, "Installing the Connector on Oracle Identity Manager Release 9.1.0.x or Release 11.1.1" for details.

Software Updates in Release 9.0.4.3

The following are software updates in release 9.0.4.3:

Software Updates in Release 9.0.4.2

The following are software updates in release 9.0.4.2:

Documentation-Specific Updates

The following sections discuss documentation-specific updates:

Documentation-Specific Updates in Release 9.0.4.15

The following are documentation-specific updates in release 9.0.4.15:

Documentation-Specific Updates in Release 9.0.4.12

Major changes have been made to the structure of the guide. The objective of these changes is to synchronize the guide with the changes made to the connector and to improve the usability of the information provided by the guide.

Documentation-Specific Updates in Release 9.0.4.11

The following are documentation-specific updates in release 9.0.4.11:

Documentation-Specific Updates in Release 9.0.4.7

The following are documentation-specific updates in release 9.0.4.7:

Documentation-Specific Updates in Release 9.0.4.6

At some places in this guide, corrections have been made to address some documentation issues.

Documentation-Specific Updates in Release 9.0.4.5

The following are documentation-specific updates in release 9.0.4.5:

Documentation-Specific Updates in Releases 9.0.4.1 Through 9.0.4.4

The following documentation-specific updates have been made in releases 9.0.4.1 through 9.0.4.4: