Oracle® Identity Manager Connector Guide for IBM Lotus Notes and Domino Release 9.0.4 Part Number E10428-07 |
|
|
View PDF |
Oracle Identity Manager automates access rights management, security, and provisioning of IT resources. Oracle Identity Manager connectors are used to integrate Oracle Identity Manager with third-party applications. This guide discusses the procedure to deploy the connector that is used to integrate Oracle Identity Manager with IBM Lotus Notes and Domino.
This chapter contains the following sections:
Note:
At some places in this guide, IBM Lotus Notes and Domino has been referred to as the target system.Reconciliation involves duplicating in Oracle Identity Manager the creation of and modifications to user accounts on the target system. It is an automated process initiated by a scheduled task that you configure.
See Also:
The "Reconciliation" section in Oracle Identity Manager Connector Concepts for conceptual information about provisioningBased on the type of data reconciled from the target system, reconciliation can be divided into the following types:
Lookup fields reconciliation involves reconciling group names from the target system to populate the lookup definition used for the Group Names lookup field on the process form.
User reconciliation involves reconciling the following fields:
The following target system fields are reconciled:
FirstName
MiddleName
LastName
ShortName
OrgUnit
MailInternetAddress
Location
Comment
ForwardDomain
SecurityType
GrpName
OldLastName
OldFirstName
OldMiddleName
OldOrgUnit
UniversalID
ExpirationDate
The following target system fields are reconciled only if trusted source reconciliation is implemented:
User ID
First Name
Last Name
Organization
User Type
Employee Type
Provisioning involves creating or modifying a user's account information on the target system through Oracle Identity Manager. You use the Oracle Identity Manager Administrative and User Console to perform provisioning operations.
See Also:
The "Provisioning" section in Oracle Identity Manager Connector Concepts for conceptual information about provisioningFor this target system, the following fields are provisioned:
FirstName
MiddleName
LastName
ShortName
Password
OrgUnit
MailInternetAddress
Location
Comment
ForwardDomain
EndDate
SecurityType
Grp
ID File Name
The following table lists the functions that are available with this connector.
Function | Type | Description |
---|---|---|
Add User | Provisioning | Creates a user |
Delete User | Provisioning | Deletes a user |
Update User Last Name | Provisioning | Updates the last name of a user |
Update User First Name | Provisioning | Updates the first name of a user |
Update User Middle Name | Provisioning | Updates the middle name of a user |
Update User Organizational Unit | Provisioning | Updates the organizational unit of a user |
Update User Short Name | Provisioning | Updates the short name of a user |
Update User Mail Internet Address | Provisioning | Updates the e-mail address of a user |
Update User Location | Provisioning | Updates the location of a user |
Update User Comment | Provisioning | Updates the comment of a user |
Update User Forward Domain | Provisioning | Updates the e-mail address to which e-mail for the user must be forwarded |
Update User Password | Provisioning | Updates the user password and resets (or updates) the ID file |
Disable User | Provisioning | Disables a user |
Enable User | Provisioning | Enables a user |
Reconcile lookup field | Reconciliation | Reconciles the lookup fields |
Reconcile User Data | Reconciliation | Trusted source reconciliation: Reconciles user data from IBM Lotus Notes and Domino to Oracle Identity Manager. A corresponding user is created in Oracle Identity Manager. If the user already exists in Oracle Identity Manager, then this user is updated.
Target resource reconciliation: Reconciles user data from IBM Lotus Notes and Domino to Oracle Identity Manager. A user is not created in Oracle Identity Manager. |
Note:
The Delete User provisioning function is implemented by using the DeleteUser Administration Process (AdminP) function of IBM Lotus Notes and Domino. Similarly, the RenameNotesUser AdminP function is used to implement the following provisioning functions:Update User Last Name
Update User First Name
Update User Middle Name
Update User Organizational Unit
The connector supports the following languages:
Arabic
Chinese Simplified
Chinese Traditional
Danish
English
French
German
Italian
Japanese
Korean
Portuguese (Brazilian)
Spanish
See Also:
Oracle Identity Manager Globalization Guide for information about supported special charactersThe files and directories on the installation media are listed and described in Table 1-1.
Table 1-1 Files and Directories On the Connector Installation Media
File in the Installation Media Directory | Description |
---|---|
config/adminP.properties |
This file is used to specify a value for an AdminP command that is run on the Domino server. |
configuration/IBM Lotus Notes Domino-CI.xml |
This XML file contains configuration information that is used during connector installation. |
config/attributemapping_prov.properties |
This file contains the parameters required for provisioning. |
config/attributemapping_recon.properties |
This file contains the parameters required for reconciliation. |
lib/xlLotusNotesProvision.jar |
This JAR file contains the class files that are used to implement provisioning. During connector deployment, this file is copied into the following directory: OIM_HOME/xellerate/JavaTasks
|
lib/xlLotusNotesRecon.jar |
This JAR file contains the class files that are used to implement reconciliation. During connector deployment, this file is copied into the following directory: OIM_HOME/xellerate/ScheduleTask
|
Files in the |
Each of these resource bundles contains language-specific information that is used by the connector. During connector deployment, these resource bundles are copied into the following directory: OIM_HOME/xellerate/connectorResources
Note: A resource bundle is a file containing localized versions of the text strings that are displayed on the user interface of Oracle Identity Manager. These text strings include GUI element labels and messages displayed on the Administrative and User Console. |
test/config/log.properties |
This file is used to specify the log level and the directory in which the log file is to be created when you run the testing utility. |
test/config/config.properties |
This file is used to specify the parameters and settings required to connect to the target system by using the testing utility. |
test/scripts/lotusNotes.bat |
This file contains the script required for running test calls from the Oracle Identity Manager server on Microsoft Windows platforms. |
test/scripts/lotusNotes.sh |
This file contains the script required for running test calls from the Oracle Identity Manager server on UNIX-based platforms. |
test/config/config_unid.properties |
This file is used to store the value of the See "Testing the Connector" for more information about this file. |
xml/xlLotusNotes_XellerateUser.xml |
This XML file contains the configuration for the Xellerate User (OIM User). You must import this file only if you plan to use the connector in trusted source reconciliation mode. |
xml/xlLotusNotesConnector.xml |
This XML file contains definitions for the following components of the connector:
|
You might have a deployment of an earlier release of the connector. While deploying the latest release, you might want to know the release number of the earlier release. To determine the release number of the connector that has already been deployed:
In a temporary directory, extract the contents of the following JAR file:
OIM_HOME/xellerate/JavaTasks/xlLotusNotesRecon.jar
Open the manifest.mf
file in a text editor. The manifest.mf
file is one of the files bundled inside the xlLotusNotesRecon.jar
file.
In the manifest.mf
file, the release number of the connector is displayed as the value of the Version property.