Issue with using the "sourceCondition" tag in sync.json

This topic has 1 reply, 1 voice, and was last updated 6 years, 4 months ago by Anonymous.

  • Author
    Posts
  • #3067
     Anonymous
    Inactive

    Hi,

    I found an issue while I’m testing the using “sourceCondition” tag in sync.json.
    I have an AD resource and the next role:
    {
    “name”: “AD_Account”,
    “_id”: “AD_Account”,
    “properties”:
    {
    “description”: “User Account in Active Directory”
    },
    “assignments”:
    {
    “AD”:
    {
    “attributes”:
    [
    {
    “name”: “__GROUPS__”,
    “value”: [
    “CN=IDM Users,OU=Groups,OU=Security,DC=example,DC=com”
    ],
    “assignmentOperation”: “mergeWithTarget”,
    “unassignmentOperation”: “removeFromTarget”
    },
    {
    “name”: “employeeType”,
    “value”: “Full-Time”
    }
    ]
    }
    }
    }

    In sync.json for IDM –> AD mapping I have written:
    “sourceCondition” : {
    “effectiveAssignments” : “AD”
    },

    I have assigned this role to an user (user doesn’t have account in an AD resource).
    The result is (user object):
    {

    “effectiveRoles”: [
    “openidm-authorized”,
    “managed/role/AD_Account”
    ],

    “roles”: [
    “openidm-authorized”,
    “managed/role/AD_Account”
    ],
    “effectiveAssignments”: {
    “AD”: {
    “attributes”: [
    {
    “value”: [
    “CN=IDM Users,OU=Groups,OU=Security,DC=example,DC=com”
    ],
    “assignedThrough”: “managed/role/AD_Account”,
    “assignmentOperation”: “mergeWithTarget”,
    “unassignmentOperation”: “removeFromTarget”,
    “name”: “__GROUPS__”
    },
    {
    “value”: “Full-Time”,
    “assignedThrough”: “managed/role/AD_Account”,
    “name”: “employeeType”
    }
    ]
    }
    },

    }

    When I have assigned this role to an user an account in AD has been created for him. But group ‘IDM Users’ has not been assigned and attribute ’employeeType’ has not been populated.
    Any help would be highly appreciated.
    What I’m doing wrong?

    #3068
     Anonymous
    Inactive

    I forgot to write the my configuration:
    – OpenIDM 3.1.0
    – ActiveDirectory Connector .NET 1.4.0.0
    – OpenICF Connector Server .NET 1.4.1.0
    – AD 2008 R2

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.

©2021 ForgeRock - we provide an identity and access platform to secure every online relationship for the enterprise market, educational sector and even entire countries. Click to view our privacy policy and terms of use.

Log in with your credentials

Forgot your details?