How to configure IM to create dynamic group in CA Directory?
search cancel

How to configure IM to create dynamic group in CA Directory?

book

Article ID: 37199

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal CA Risk Analytics CA Secure Cloud SaaS - Arcot A-OK (WebFort) CLOUDMINDER ADVANCED AUTHENTICATION CA Secure Cloud SaaS - Advanced Authentication CA Secure Cloud SaaS - Identity Management CA Secure Cloud SaaS - Single Sign On

Issue/Introduction

How to configure IM to create dynamic group in CA Directory?

Environment

Release:
Component: IDMGR

Resolution

Assumption: IM is working and can create static group.

  1. Enable dynamic groups in CA Directory

Dynamic roles are based on the dxMemberURL attribute of the following object classes:

  •         dxDynamicGroupOfNames
  •         dxDynamicGroupOfUniqueNames

 

You can add these attributes to a groupOfNames or groupOfUniqueNames object class, respectively so that dxMemberURL can be included.

  1. Stop the DSA
  2. Add the following commands to the the DSA's settings under \CA\Directory\dxserver\config\settings:

 

clear dynamic-group;

set dynamic-group [tag] = {

objectclass = object-class

url-attr = attribute

member-attr = attribute

};

For example:

 

<Please see attached file for image>

 

  1. Start DSA
  2. Export corporate directory in IM

 

<Please see attached file for image>

 

 

  1. Edit the directory xml file by adding

 

objectclass="dxDynamicGroupOfUniqueNames"

and modifying

physicalname="memberURL" to physicalname="dxMemberURL"

 

to managed object attribute  %DYNAMIC_GROUP_MEMBERSHIP%

 

For example,

 

<ImsManagedObjectAttr physicalname="dxMemberURL" description="Dynamic Group Query"  objectclass="dxDynamicGroupOfUniqueNames" displayname="DynamicGroup Query" valuetype="String" multivalued="true" wellknown="%DYNAMIC_GROUP_MEMBERSHIP%" maxlength="0" hidden="true" system="true" searchable="false"/>

 

  1. Save the change, update the IM directory, and restart the environment when being prompted.
  2. Verify the change is updated into IM directory

 

<Please see attached file for image>

 

  1. Create a dynamic group via IM User Console

 

<Please see attached file for image>

 

All users with title contains “Manager” are now added as members:

 

<Please see attached file for image>

 

From JXplorer, the dynamic group looks like this:

 

<Please see attached file for image>

 

Attachments

1558723338523000037199_sktwi1f5rjvs16wt9.png get_app
1558723336646000037199_sktwi1f5rjvs16wt8.png get_app
1558723335025000037199_sktwi1f5rjvs16wt7.png get_app
1558723333256000037199_sktwi1f5rjvs16wt6.png get_app
1558723331664000037199_sktwi1f5rjvs16wt5.png get_app
1558723329592000037199_sktwi1f5rjvs16wt4.png get_app