[midPoint] couple of questions after a dry run

Jason Everling jeverling at bshp.edu
Mon Jun 22 17:40:15 CEST 2015


Correct, we don't want any extra spaces or weird DNs with null in it so I
will create 2 different ones with if/then/else,

JASON

On Mon, Jun 22, 2015 at 10:21 AM, Ivan Noris <ivan.noris at evolveum.com>
wrote:

> Hi Jason,
>
> On 06/22/2015 05:11 PM, Jason Everling wrote:
> > I did a dry run this weekend, and glad Ivan had mentioned it, over
> > 2000 accounts would have been modified/changed.
> >
> > I failed to remember the middle initial that active directory uses in
> > the DN for the account, not everyone has one or used.
> >
> > So in midpoint AD resource config I added the intials attributes
> > mapped to additionalName,
> >
> > Question though,
> >
> > If I change the DN build in the resource config to
> >
> > <code>
> >      'cn='+givenName+' '+additionalName+'
> > '+familyName+iterationToken+','+organization+''
> > </code>
> >
> > Will this work also for users without or null value for
> > "additionalName" ? Or do I need to check for value in additionalName
> > first then return 2 different codes for one with and one without
> > additionalName?
>
> Just a very wil guess: if additionalValue is null, you get two spaces
> between givenName and familyName, right? That's perhaps not what you
> need. Also I'm not sure, but in some circumstances you could get
> "cn=Peter null Smith,..." DN.
>
> So, if/then/else will be probably better.
>
> Ivan
>
> --
>   Ing. Ivan Noris
>   Senior Identity Management Engineer & IDM Architect
>   evolveum.com                     evolveum.com/blog/
>   ___________________________________________________
>   "Semper Id(e)M Vix."
>
> _______________________________________________
> midPoint mailing list
> midPoint at lists.evolveum.com
> http://lists.evolveum.com/mailman/listinfo/midpoint
>

-- 


CONFIDENTIALITY NOTICE:
This e-mail together with any attachments is proprietary and confidential; 
intended for only the recipient(s) named above and may contain information 
that is privileged. You should not retain, copy or use this e-mail or any 
attachments for any purpose, or disclose all or any part of the contents to 
any person. Any views or opinions expressed in this e-mail are those of the 
author and do not represent those of the Baptist School of Health 
Professions. If you have received this e-mail in error, or are not the 
named recipient(s), you are hereby notified that any review, dissemination, 
distribution or copying of this communication is prohibited by the sender 
and to do so might constitute a violation of the Electronic Communications 
Privacy Act, 18 U.S.C. section 2510-2521. Please immediately notify the 
sender and delete this e-mail and any attachments from your computer. 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20150622/3961b2ae/attachment.htm>


More information about the midPoint mailing list