SECJ0100 - Reconcile LDAP Security Entries

Purpose

This job is used to maintain entries in an LDAP directory.

SubSystem

Security

Normally Run By Administration specialist
Anticipated Frequency As required
Structure   No Parameters

 

This job is used to maintain entries in an LDAP directory. The entries are based on security information held within the Callista SMS. The security entries will be translated to user and page/role information within the LDAP directory.
The Security Role concept within Callista SMS will not be represented in the LDAP directory. Rather the Security Role will be translated to give the users within the role access to the relevant pages.

Configuration options give clients the option of whether the process will be allowed to create or delete user entries. If configuration does not allow this then it is assumed these entries are maintained by an external means. If user entries are created by this process then the user must exist in the ldap_user table before they will be included in the reconcile.

When this job creates LDAP users or allocates existing LDAP users to pages, it derives the person’s LDAP username by checking the SMS Identifier value in SECF0100. If this is set to Person ID then it assumes the person’s LDAP username is their Callista Person ID. If the value is set to Username, then it assumes the person’s LDAP username is their Oracle username or if it is set to Alternate Person ID, then the job will assume the person’s LDAP username is the alternate person id mapped to the person_id_type recorded for the Alternate Person ID Type in SECF0100.

Further information about this process can be gained from the technical information in the Callista Product Centre (wiki.callista.com.au/display/CPC).

This job can be accessed via the Callista SMS menu and does not have parameters


Last Modified on 18-Aug-2015 9:13 AM

History Information

Release Information Project Change to Document
18.0.0.2 2011 - Calipso 41512 Updated tech doc reference to the CPC wiki space.
12.0.0.2 1595 - Security 2009 Added new paragraph relating to the derivation of LDAP usernames.
11.0.0.0.0.0 1416 - Apprentice Management New page