Configuring Driver Parameters

Use Novell iManager to make the appropriate adjustments to any of the following properties: log level, polling rate, password expiration time, security options, and startup options.

In this section:


Log Level

The log level determines the kinds of errors that are sent to the DirXML status logs, DSTrace, and Nsure Audit. For complete information about Nsure Audit and Identity Manager, see the Novell Nsure Identity Manager 2 Administration Guide.

You can set one of the following options:

To set the log level:

  1. In iManager, select DirXML Management > Overview.

  2. Select the driver set containing the driver, click the driver icon to see the driver overview, then click the driver icon again to edit driver parameters.

  3. Click the Log Level link at the top of the page, select a level, then click OK.


Polling Rate

The driver re-reads the SAM registry once each polling interval, looking for new or modified users. Setting the polling rate too fast will use up all available processing cycles. The minimum polling rate is three seconds, 3000 milliseconds. The recommended rate is one minute, 60000 milliseconds.

  1. In iManager, select DirXML Management > Overview.

  2. Select the driver set containing the driver, click the driver icon to see the driver overview, then click the driver icon again to edit driver parameters.

  3. Select a polling rate from the list, then click OK.


Password Expiration Time

The driver and the password filter have been enhanced in the following ways to improve how password synchronization is retried after a failure:

For more understanding of why these enhancements are important, review the following information.

The driver checks for changes to users in NT based on a polling interval. In contrast, the password filter is event-driven, meaning that it sends password changes from NT to the driver as soon as they occur. After a user is created in eDirectory to correspond to an NT user, this immediate response for password synchronization is helpful. But because of the differences between polling and event-driven activity, password synchronization for new users might not be immediate.

Issues such as the difference between polling and event-driven activity, and business practices such as Create policies and Password Policies, can lead to scenarios like the following. This list explains how the Password Expiration Time parameter is applicable in each case.


Security Options

Creating a new user that has Read/Write rights to the domain and to the SAM registry will make Identity Manager easier to manage. This user account will be used exclusively by the NT Domain Driver. This user is also a user you'll want to exclude from synchronization because its sole purpose is to provide rights for the NT Domain Driver. After you've created this user, you can assign the driver to use that user account.

To set up these security options:

  1. In iManager, select DirXML Management > Overview.

  2. Select the driver set containing the driver, click the driver icon to see the driver overview, then click the driver icon again to edit driver parameters.

  3. Click Driver Configuration at the top of the page, then enter the appropriate data in the Authentication fields.


Startup Options

You can set driver startup to any of the following three options:

To set startup options:

  1. In iManager, select DirXML Management > Overview.

  2. Select the driver set containing the driver, click the driver icon to see the driver overview, then click the driver icon again to edit driver parameters.

  3. Click Driver Configuration at the top of the page, then select one of the three options listed under Startup Options.