In this section:
Novell® provides a sample configuration file (LegacyNDS.xml). You can use this file to add the NDS driver to your driver set.
In Novell iManager, select DirXML Utilities > Overview.
Browse to and select the driver set, then click Search.
Click Add Driver, select In an Existing Driver Set, then click Next.
Click Import a Driver Configuration from the Client (.XML File), browse to and select the LegacyNDS.xml file, then click Next.
Name the driver, specify user account information, and provide information about the NDS system.
The wizard provides help so that you can set these parameters.
Configure data flow.
The Data Flow setting controls whether the Publisher channel filter and the Subscriber channel filter are synchronized or ignored. The setting determines whether data flows from both NDS and eDirectoryTM or either NDS or eDirectory. The Data Flow settings use policies to control the flow of data.
The following figure illustrates filter settings. In this example, all attributes except Initials are set for bidirectional data flow. On the Initials attribute, the Publisher channel synchronizes data. Because the Subscriber channel is set to Ignore, NDS is the authoritative source.
Select how to place synchronized objects.
Mirrored: Synchronizes objects hierarchically between the NDS tree and eDirectory.
This option in the driver configuration synchronizes User, Group, Organization, Country, and Organizational Unit objects. It also mirrors the structure of a subtree in another tree.
When new User objects are created in one directory, they are placed in the matching hierarchical level of the mirrored container in the other directory.
The Mirrored option doesn't require a Create rule.
Flat: Synchronizes User and Group objects into specific containers.
Regardless of where synchronization begins or where objects appear in the NDS tree, this option places all users in one container and all groups in another container in eDirectory. A similar process occurs from eDirectory to the NDS tree. The user and group containers are the same in both the NDS tree and eDirectory.
With this configuration, you must specify a container for User objects (to hold all new User objects) and a separate container for Group objects (to hold all new Group objects). This option doesn't create the containers that hold the users and groups. You must create the containers manually.
Any changes in a user or group container in one system appear in the user or group container in the other system. The Placement policy places the objects and makes changes appropriately.
The Create rule for the Flat option requires users to have a given name and a surname, so that users are unique when they appear in the other system.
Department: Synchronizes users and groups by department (OU).
This option synchronizes User and Group objects and places all users and groups in a container based on the Department field in your management console.
On either side, you define a container where all User objects are placed. You also define a department that the users belong to.
A department (OU) attribute must already exist in the appropriate base container.
This option doesn't create the containers for each department. You must create the containers manually. The must be the same as the container specified when you add or import the driver.
The Create rule for the Department option requires a given name, surname, and OU.
Scenario: Using Department Containers
At the DigitalAirlines company, a Department container exists in the NDS tree. The network administrator has created (in the Department container) subdirectories named after departments that people belong to: R&D, Marketing, Corporate Sales, and Human Resources. Upon creating a user, the administrator assigns the user to a department name. Through the NDS driver, the Department attribute is created in the correct container in eDirectory.
Configure the base container, remote base container, Publisher channel, and (optionally) the keystore file and password.
Click Next, then specify a polling interval.
(Conditional) If you selected the Flat placement, specify a Local Group Container in eDirectory.
This is the base container for synchronization in eDirectory. Groups are placed here.
Click Next.
Define a security-equivalent user.
Click Define Security Equivalences, then browse to and add a user.
Click Exclude Administrative Roles, then browse to and add a user who is to be excluded from administrative roles.
Click Next, review settings, then click Finish.
In iManager, select DirXML Management > Overview.
Select the driver set containing the driver, then click Search.
Click the driver icon to see the driver overview, then click the driver icon again to display the Modify Object page.
Click Driver Configuration at the top of the page, then select one of the three options listed under Startup Option.
You can set driver startup to any of the following three options:
Automatic: Whenever the DirXML engine starts, the driver starts automatically. After you have configured the driver, you should use this option.
Manual: Starts the driver manually. This option is often used during driver modification and testing cycles. The engine buffers the changes to be processed when the driver starts.
Disabled: If you use this option, Identity Manager does not cache events. Data changes made in eDirectory during the time a driver is disabled are not synchronized upon driver startup.
Click OK.
For more information, refer to the DirXML (Identity Manager) Administration Guide.