coping with Active Dir nested groups and Identity Manager 2
Posted on 2006-07-19
i am busy setting up our publisher channel to sync objects back into our edir using IM2 and am just testing what happens when nesting groups within AD..
Obviously IM picks this up as a change of membership and throws an error in the DStrace as follows
Message: Code(-8011) Error processing reciprocal linking attribute (\tree\company\ou\adgroup#Security Equals): novell.jclient.JCException: modifyEntry -608 ERR_ILLEGAL_ATTRIBUTE
how do people cope with group nests when using identity manager? it does seem that it adds the object in to the group in edir but obviously it wouldnt operate as a nest.
is there anyway to veto out all nests and what do people do at migration time?