[midPoint] AD Groups, Getting Security Violation

Jason Everling jeverling at bshp.edu
Thu Nov 27 19:23:45 CET 2014


I cannot figure this one out, I followed the groups sync in the wiki and
from the github samples along with the metarole and role template.

When creating a role in Midpoint it attempts to create the group in AD but
I get an error, look at the debug page it has the correct DN and CN.

operation.com.evolveum.midpoint.model.impl.lens.ChangeExecutor.execute

   - Security violation during processing shadow shadow: null (OID:null):
   Attempt to add shadow with non-createable attribute {
   http://midpoint.evolveum.com/xml/ns/public/resource/instance-3}cn
   - Security violation during processing shadow shadow: null (OID:null):
   Attempt to add shadow with non-createable attribute {
   http://midpoint.evolveum.com/xml/ns/public/resource/instance-3}cn


ActivityStatusResource object (if applicable)Computing projections of the
focus objectEntitlement (group) on Active DirectoryAdd:Fatal error ->
cn=TESTER,ou=Groups,dc=test,dc=local

I attached the AD Resource, Role Template, and MetaRole

-- 


CONFIDENTIALITY NOTICE:
This e-mail together with any attachments is proprietary and confidential; 
intended for only the recipient(s) named above and may contain information 
that is privileged. You should not retain, copy or use this e-mail or any 
attachments for any purpose, or disclose all or any part of the contents to 
any person. Any views or opinions expressed in this e-mail are those of the 
author and do not represent those of the Baptist School of Health 
Professions. If you have received this e-mail in error, or are not the 
named recipient(s), you are hereby notified that any review, dissemination, 
distribution or copying of this communication is prohibited by the sender 
and to do so might constitute a violation of the Electronic Communications 
Privacy Act, 18 U.S.C. section 2510-2521. Please immediately notify the 
sender and delete this e-mail and any attachments from your computer. 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20141127/a466e36c/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: meta_role_groups.xml
Type: text/xml
Size: 2992 bytes
Desc: not available
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20141127/a466e36c/attachment.xml>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: role_template_groups.xml
Type: text/xml
Size: 1612 bytes
Desc: not available
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20141127/a466e36c/attachment-0001.xml>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ad_groups_development.xml
Type: text/xml
Size: 38114 bytes
Desc: not available
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20141127/a466e36c/attachment-0002.xml>


More information about the midPoint mailing list