Solved

Synchronizing existing users between AD and Identity Vault

Posted on 2007-11-15
2
2,238 Views
Last Modified: 2008-02-01
I am currently testing OES 2 running on SLES10.1. I have installed Identity Manager 3.51 on the OES machine running as the metadirectory server. My connected system is Windows 2003 Server R2. I am unable to synchronize existing users, but if I create a new user in either AD or Edir the user is replicated to the other connected system.

Below is the error:

Message 1:
Thu Nov 15 14:17:08 SAST 2007
Warning
No description provided.
Code(-8003) Unable to synchronize reference to \TEST_TREE\testou\admin from attribute Owner.

Message 2:
Thu Nov 15 14:17:08 SAST 2007
Warning
No description provided.
Code(-8003) Unable to synchronize reference to \TEST_TREE\testou\users\testuser from attribute Member.

Message 6:
Thu Nov 15 14:17:08 SAST 2007
Warning
<status level="warning">Code(-8017) Operation vetoed by object creation policy.<application>DirXML</application>
      <module>Active Directory</module>
      <object-dn>\TEST_TREE\testou\users\testuser</object-dn>
      <component>Subscriber</component>
</status>
\TEST_TREE\testou\users\testuser

Any ideas ?
0
Comment
Question by:dielem10
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 19

Accepted Solution

by:
alextoft earned 250 total points
ID: 20293191
Firstly, ignore the "unable to sync reference" warnings. The problem is in the veto message. Have a look at your creation policies and work through them, examine the rules to see what is veto'd and why.

As I remember, IDM 3.5 will veto create operations if a user does not have the universal password populated in eDir. If you're trying to export a pre-existing user, this may well be the case. Have you setup the Universal Password policies correctly?

Alternatively, up your trace level to 5 in order to get a more detailed log output.
0
 

Author Comment

by:dielem10
ID: 20296511
Thanks. I thought the universal password for the user was set, but I was wrong. Once I set it, it all worked fine.
0

Featured Post

SharePoint Admin?

Enable Your Employees To Focus On The Core With Intuitive Onscreen Guidance That is With You At The Moment of Need.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Security Check - Log the files accessed by specific Novell users or IP Addresses? 5 248
Novell VM migrate to ESXi 4 1 807
log in log 7 558
Novell CNE now top 15 paying cert? 5 374
Facebook has became the #1 social media platform. People share many funny videos there, yet you don't know how to download them? Now you can download Videos from Facebook in just 3 simple steps.
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question