[midPoint] Problem with auxiliaryObjectClass definition in LDAP Connector on midPoint 4.6

Patrik Sidler patrik.sidler at itconcepts.ch
Thu Nov 24 15:08:54 CET 2022


Hi All,

I am having a problem, configuring the auxiliaryObjectClass on my LDAP Connector (Version 3.5) running on midPoint 4.6.


The configuration midPoint 4.4.3 (LDAP Connector) worked perfect:

<objectClass>ri:inetOrgPerson</objectClass>
<auxiliaryObjectClass>ri:ipaObject</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:iamUser</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:inetUser</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:ipaSshUser</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:krbTicketPolicyAux</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:krbPrincipalAux</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:aspectraUser</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:posixAccount</auxiliaryObjectClass>
<auxiliaryObjectClass>ri:ipaNTUserAttrs</auxiliaryObjectClass>
<auxiliaryObjectClassMappings>
    <tolerant>true</tolerant>
</auxiliaryObjectClassMappings>


With midPoint 4.6 and LDAP Connector 3.5, the configuration looks the following:

<objectType id="4">
    <kind>account</kind>
    <intent>ldapAccount</intent>
    <displayName>LDAP Account</displayName>
    <default>true</default>
    <delineation>
        <objectClass>ri:inetOrgPerson</objectClass>
        <auxiliaryObjectClass>ri:ipaObject</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:iamUser</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:inetUser</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:ipaSshUser</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:krbTicketPolicyAux</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:krbPrincipalAux</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:aspectraUser</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:posixAccount</auxiliaryObjectClass>
        <auxiliaryObjectClass>ri:ipaNTUserAttrs</auxiliaryObjectClass>
    </delineation>

But I am not able to set the auxiliaryObjectClassMappings to tolerant. I also found no description/example to do this with the new Wizard thing...

Anyone an Idea how to solve this problem?

Thank you in advance for your help.

Best regards
Patrik

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20221124/904c68a8/attachment-0001.htm>


More information about the midPoint mailing list