How to configure IM to create dynamic group in CA Directory?
Release: 14.X
Component: IDMGR
Assumption: IM is working and can create static group.
Dynamic roles are based on the dxMemberURL attribute of the following object classes:
You can add these attributes to a groupOfNames or groupOfUniqueNames object class, respectively so that dxMemberURL can be included.
set dynamic-group [tag] = {
objectclass = object-class
url-attr = attribute
member-attr = attribute
};
For example:
objectclass="dxDynamicGroupOfUniqueNames"
and modifying
physicalname="memberURL" to physicalname="dxMemberURL"
to managed object attribute %DYNAMIC_GROUP_MEMBERSHIP%
For example,
<ImsManagedObjectAttr physicalname="dxMemberURL" description="Dynamic Group Query" objectclass="dxDynamicGroupOfUniqueNames" displayname="DynamicGroup Query" valuetype="String" multivalued="true" wellknown="%DYNAMIC_GROUP_MEMBERSHIP%" maxlength="0" hidden="true" system="true" searchable="false"/>
All users with title contains “Manager” are now added as members:
From JXplorer, the dynamic group looks like this: