| Oracle® Identity Manager Connector Guide for CA Top Secret Advanced Release 9.0.4 Part Number E10424-08 |
|
|
View PDF |
This chapter provides an overview of the updates made to the software and documentation for the Oracle Identity Manager Advanced Connector for CA Top Secret in release 9.0.4.7.
The updates discussed in this chapter are divided into the following categories:
This section describes updates made to the connector software.
Documentation-Specific Updates
This section describes major changes made to this guide. These changes are not related to software updates.
The following sections discuss software updates:
The following are software updates up to release 9.0.4.2:
The IBM MQ Series protocol for the message transport layer is no longer supported for this connector. All content related to this protocol has been removed from the guide.
CA Top Secret user, group, facility, and data set and resource profile commands supported by the Provisioning Agent have been added in "Functionality Supported by the Pioneer Provisioning Agent" on page 1-6.
The list of functions supported by the Provisioning Agent has been updated in "Functionality Supported for Provisioning" on page 1-7.
The commands supported by the Reconciliation Agent have been added in "Functionality Supported by the Voyager Reconciliation Agent" on page 1-7.
The list of functions supported by the Reconciliation Agent has been updated in "Functionality Supported for Reconciliation" on page 1-7.
The list of fields reconciled between Oracle Identity Manager and CA Top Secret has been updated in "Target System Fields Used for Reconciliation and Provisioning" on page 1-8.
The IT resource parameters and their corresponding descriptions and sample values have been updated in "Importing the Connector XML File".
The procedure to configure the connector for multiple installations of the target system has been added in "Configuring the Connector for Multiple Installations of the Target System" on page 2-14.
Information about reconciliation based on user status has been added in "Configuring Account Status Reconciliation".
Steps to add a new field for provisioning have been added in "Adding New Fields for Provisioning" on page 4-5.
Known issues related to the following bugs have been added in Chapter 7, "Known Issues":
6668844
6904041
7033009
Information about integrating the Reconciliation Agent exit with existing Top Secret exits has been added in "Installing or Integrating the Reconciliation Agent Exit".
The following are issues resolved in release 9.0.4.3:
| Bug Number | Issue | Resolution |
|---|---|---|
| 7583557 | Passwords were specified in unencrypted format in the beans.xml file, which is a configuration file used by the connector. |
This issue has been resolved. You can now use the propertyEncrypt script to encrypt passwords before you copy them into the beans.xml file.
See "Encrypting Passwords Used in the beans.xml File" for information about the procedure. |
The following are software updates in release 9.0.4.4:
If you use multiple resource objects for reconciliation with the target system, then from this release onward you can specify the resource objects with which you want to associate records of specific user types from the target system. See "Configuring Limited Reconciliation" for more information about this feature.
The following are issues resolved in release 9.0.4.5:
| Bug Number | Issue | Resolution |
|---|---|---|
| 8715777 | During a reconciliation run, a parsing error was encountered if there was no data between the PROFILES and INSTDATA segments fetched from the target system. | This issue has been resolved. Data is always present between the PROFILES and INSTDATA segments during a reconciliation run. |
The following are software updates in release 9.0.4.6:
The connector now supports provisioning operations corresponding to the following target system functions:
TSS ADD(acid) ASUSPEND UNTIL(DATE): An administrative user suspends a user either indefinitely (no date is entered) or up to a specified date.
TSS REMOVE(acid) ASUSPEND UNTIL(): An administrative user unsuspends a user.
TSS ADD(acid) SUSPEND UNTIL(DATE): A user suspends another user either indefinitely (no date is entered) or up to a specified date.
TSS REMOVE(acid) SUSPEND UNTIL(): A user unsuspends another user.
Note:
For a Suspend operation, you cannot specify the current date. The date specified must be either the next day or a future date.The following are issues resolved in release 9.0.4.6:
| Bug Number | Issue | Resolution |
|---|---|---|
| 8582428 | During provisioning operations, assignment of a group to a user failed. | This issue was resolved in release 9.0.4.5. Group assignment to a user does not fail during provisioning operations. |
| 8909417 | The connector allows you to create and use multiple resource objects to represent multiple user types in your organization. This is described in the "Configuring Limited Reconciliation" section of the connector guide. In earlier releases, changes to the Enabled/Disabled/Revoked status of users on the target system were not reconciled if you used multiple resource objects. | This issue has been resolved. Changes in user status are reconciled into Oracle Identity Manager even when you configure multiple resource objects. |
The following are software updates in release 9.0.4.7:
In this release, the _userStatus_ property has been added in the topsecretConnection.properties and initialTopSecretAdv.properties files. You set the value of this property to either Provisioned or Enabled depending on the status that must be set for accounts created through target resource reconciliation.
See Section 2.8, "Installing and Configuring the LDAP Gateway" for more information.
The following documentation-specific updates have been made up to the current release of the connector:
The user attribute mappings and resource profile field mappings between Oracle Identity Manager and the target system have been added in "Target System Fields Used for Reconciliation and Provisioning" on page 1-8. Appendix A, "Attribute Mapping Between CA Top Secret and Oracle Identity Manager" has been removed.
The components of the CA Top Secret Advanced connector and the connector architecture for reconciliation and provisioning have been added in "Connector Architecture". Appendix B, "Connector Architecture" has been removed.
Guidelines that were earlier documented in Chapter 7, "Known Issues" have been moved to "Guidelines on Using the Connector" on page 6-2.
Information about enabling logging on the LDAP Gateway server has been added in "Installing and Configuring the LDAP Gateway".
In the "Functionality Supported for Reconciliation" section, the following functions have been added:
Suspend users until
UnSuspend uses until
In the "User Field Mapping" section, the defaultGroup field has been removed.
Some corrections have been made in the following sections:
Environmental Settings and Requirements
Configuring the TCP/IP Connection and Started Tasks
In the "Certified Languages" section, Arabic has been added to the list of languages that the connector supports.
In Table 1-1, "Certified Components", changes have been made in the Target Systems row. Information about certified deployment configurations has been removed from "Reviewing Deployment Requirements".
Major changes have been made in the structure of the guide. In addition, in Section 1.1, "Certified Components," CA Top Secret r14 has been added to the list of certified target systems.