B.1 Policies Required in the Publisher Command Transformation Set

The policies listed in the Password Synchronization Policy Name column must be present in the order listed. Also, they must be the last policies in the Publisher Command Transformation policy set.

IMPORTANT:Some policy names have changed in some driver pre-configs. Some drivers use the new policy names while others continue to use the old names. To avoid any confusion about the policy names, the following tables have two columns containing old and new policy names.

Table B-1 Policies Required in the Publisher Command Transformation Set

Location in the Driver Configuration

Password Synchronization Policy Name (Old)

Password Synchronization Policy Name (New)

What the Policy Does

Publisher Command Transformation

Password(Pub)-Default Password Policy

pub-ctp-DefaultPassword

Adds a default password to an Add object if the Add object does not already contain a password.

This policy and the Password(Sub)-Default Password Policy are the only policies that you can modify or remove. For password synchronization functionality to work properly, the other policies should be used without changes.

Password(Pub)-Check Password GCV

pub-ctp-CheckPasswordGCV

Checks the GCV to determine whether you have specified that Identity Manager accepts passwords from this connected system. If not, it strips out all password elements.

The name of the GCV is enable-password-publish, and the display name is Identity Manager accepts passwords from application.

Password(Pub)-Publish Distribution Password

pub-ctp-PublishDistributionPassword

Transforms the <password> element to the form that allows it to update the Universal password.

This policy references the following GCVs:

  • publish-password-to-dp

  • enforce-password-policy

Password(Pub)-Publish NDS Password

pub-ctp-PublishNDSPassword

Allows the <password> element to go through if you have specified that the NDS password should be updated. If not, it strips out the <password> element.

This policy references the GCV named publish-password-to-nds.

Password(Pub)-Add Password Payload

pub-ctp-AddPasswordPayload

Puts in payload data that is passed around in the engine for purposes of e-mail notification.