C.2 Global Configuration Values

Global configuration values (GCVs) allow you to specify settings for the Identity Manager features such as password synchronization and driver heartbeat, as well as settings that are specific to the function of an individual driver configuration. Some GCVs are provided with the drivers, but you can also add your own.

Global configuration values can be specified for a driver set as well as an individual driver. If a driver does not have a GCV value, the driver inherits the value for that GCV from the driver set.

In iManager:

  1. Click Identity Manager > Identity Manager Overview, then click Search to search for the driver set that is associated with the driver.

  2. Browse to the driver, then click the upper right corner of the driver icon.

  3. Click Edit Properties > Global Config Values.

    See Table C-6 for a list of the global configuration values.

In Designer:

  1. Open a project in the Modeler, then right-click the driver line, then select Properties > Global Config Values.

    See Table C-6 for a list of the global configuration values.

Table C-6 Global Configuration Values > Driver Configuration

GCV Name

Description

GroupWise Domain Database Version

The version of the GroupWise domain database to which this driver should connect.

  • GroupWise 7

  • GroupWise 6.5

  • GroupWise 6.0

  • GroupWise 5.5

Default Sync Source: eDir Container/Subtree

Specify the eDirectory container in which object changes are detected and synchronized. Synchronization occurs for objects subordinate to the specified source location. Object events occurring outside of the specified subtree are vetoed by the driver. Specify the entire eDirectory tree [root] with a backslash if you want all containers within the tree to be monitored for synchronization.

Default Sync Destination: GroupWise PostOffice

Specify the GroupWise Post Office in which newly added eDirectory objects are created. Use the browse button to select the GroupWise Post Office or specify the GroupWise Post Office name as an eDirectory Distinguished Name (DN) in slash format. For example: GW\GWSystem\PO1.

Enforce Admin Lockout Setting

Enforces the Minimum Snap-in Release Version and Minimum Snap-in Release Date set in the Admin Lockout Settings tab of System Preferences in ConsoleOne. If the domain to which the driver connects has overridden these settings, they are used. This means the GroupWise driver must be running with GroupWise support files equal to or later than these settings.

Normally, it is set to True. You might need to set it to False, if the GroupWise support pack is installed and ConsoleOne is configured to lock out previous versions. True enforces this lockout setting. False disables this lockout setting.

Synchronize Groups

Allows the driver to synchronize eDirectory groups to GroupWise distribution lists. True enables the synchronization. False disables the synchronization.

Cleanup Group Membership

Available, only if Synchronize Groups is set to True. Removes the user from the Group Membership attribute when the user is removed from the GroupWise Distribution lists.

Synchronize GroupWise Distribution Lists

Allows the driver to synchronize eDirectory GroupWise Distribution List objects with distribution lists in GroupWise. True enables the synchronization. False disables the synchronization.

Synchronize GroupWise External Entity Objects

Allows the driver to synchronize eDirectory GroupWise External Entity objects with external users in GroupWise. True enables the synchronization. False disables the synchronization.

Sync GroupWise External Entities to this Domain

Available only if Synchronize GroupWise Distribution Lists is set to True. Specify a Non-GroupWise Domain name that exists within the GroupWise system. This Domain must host at least one external post office, defined in Sync GroupWise External Entities to this External Post Office.

Sync GroupWise External Entities to this External Post Office

Available only if Synchronize GroupWise Distribution Lists is set to True. Specify an External Post Office name that exists within the GroupWise system. This Post Office must be subordinate to the GroupWise domain defined in Sync GroupWise External Entities to this Domain.

Synchronize eDir OrgUnit to GroupWise External Post Office

Allows the driver to synchronize eDirectory Organizational Units to GroupWise External Post Offices. True enables the synchronization. False disables the synchronization.

Create External Post Offices in the Non-GroupWise Domain

Available only if Synchronize eDir OrgUnit to GroupWise External Post Office is set to True. Specify a Non-GroupWise Domain name that exists within the GroupWise system. This Domain hosts the external post offices created by the GroupWise driver when synchronizing eDirectory Organizational Units to GroupWise Post Offices.

Create Nicknames

Allows the driver to create GroupWise nicknames when GroupWise accounts are renamed or moved to another post office. True creates nicknames when the accounts are renamed or moved. False does not create nicknames when the accounts are renamed or moved.

NOTE:This option should not be used with GroupWise 6.5.0 or earlier.

Reassign Resource Ownership

The driver reassigns ownership of resources when GroupWise accounts are disabled or expired.

True assigns the resources to the default User ID you specify in the next parameter. This setting does not apply when a GroupWise account is deleted because the resources must be reassigned. False is the default.

Default Resource Owner User ID

Specify the prefix of the default user to become the new owner of resources that are reassigned. The default is IS_admin.

You must specify this name even when the Reassign Resource Ownership option is False. When a GroupWise account is deleted, its resources are assigned to this account. If the default User ID does not have a GroupWise account in the post office of the deleted account, an account is created.

IMPORTANT:The driver does not start if a default user prefix is not specified.

Create Accounts During Migration

Allows the driver to create new GroupWise accounts for users without a current account during a migration from eDirectory. True allows the accounts to be created. False does not create the accounts.

Migration causes Identity Manager to examine every object specified. When an object does not have a driver association, the Create policy is applied. If the object meets the Create rule criteria, the object is passed to the driver as an Add event. When you specify True, the driver creates a GroupWise account. When False is specified, the Add event is ignored and the driver issues a warning that this option is set to False. The default value is False.

Migration sets the driver association on all users with GroupWise accounts. See Section 4.6.6, Migrating eDirectory Users to GroupWise for more information.

Action on eDirectory User Delete

Specify the action you want the driver to take on an associated GroupWise account when a user is deleted in eDirectory:

  • Delete the GroupWise Account

  • Disable the GroupWise Account

  • Expire the GroupWise Account

  • Disable and Expire the GroupWise Account

Action on eDirectory User Expire/Unexpire

Specify the action you want the driver to take on an associated GroupWise account when its user login in eDirectory is expired or unexpired:

  • Expire/Unexpire the GroupWise Account

  • Disable/Enable the GroupWise Account

  • Disable/Enable and Expire/Unexpire the GroupWise Account

Action on eDirectory User Disable/Enable

Specify the action you want the driver to take on an associated GroupWise account when its user login in eDirectory is disabled or enabled:

  • Expire/Unexpire the GroupWise Account

  • Disable/Enable the GroupWise Account

  • Disable/Enable and Expire/Unexpire the GroupWise Account

Remove GW Account from All Distribution Lists on Expire

Set this option to True, if you want the driver to remove the GroupWise account from all distribution lists when the next event is processed, otherwise select False.

Remove GW Account from All Distribution Lists on Disable

Set this option to True if you want the driver to remove the GroupWise account from all distribution lists when the next event is processed, otherwise select False.

Action on eDirectory GroupWise External Entity Delete

When a GroupWise External Entity is deleted in eDirectory, specify the action you want the driver to take on the associated GroupWise account. The options are:

  • Delete the GroupWise Account

  • Disable the GroupWise Account

  • Expire the GroupWise Account

  • Disable and Expire the GroupWise Account

Action on eDirectory GroupWise External Entity Expire/Unexpire

When a GroupWise External Entity login in eDirectory is expired/unexpired, specify the action you want the driver to take on the associated GroupWise account:

  • Expire/Unexpire the GroupWise Account

  • Disable/Enable the GroupWise Account

  • Disable/Enable and Expire/Unexpire the GroupWise Account

Action on eDirectory GroupWise External Entity Disable/Enable

When a GroupWise External Entity login in eDirectory is disabled/enabled, specify the action you want the driver to take on the associated GroupWise account:

  • Expire/Unexpire the GroupWise Account

  • Disable/Enable the GroupWise Account

  • Disable/Enable and Expire/Unexpire the GroupWise Account

Remove GroupWise External Entity from all Distribution lists on expire

Select True if you want the driver to remove the GroupWise External Entity from all Distribution Lists when the GroupWise account is expired; otherwise, select False.

Remove GroupWise External Entity from all Distribution Lists on disable

Select True if you want the driver to remove the GroupWise External Entity from all Distribution Lists when the GroupWise account is disabled; otherwise, select False.

Publisher Heartbeat Interval

Specify the Publisher channel heartbeat interval in minutes. Enter 0 to disable the heartbeat.

If entitlements are enabled in the driver, there are additional GCVs, shown in Table C-7.

Table C-7 Global Configuration Values > Entitlements

GCV Name

Description

Action On GroupWise Account Entitlement Add

Entitlement option only.

When a user is created in eDirectory with a GroupWise account entitlement, select the action you want to occur on the associated GroupWise account:

  • Disable the GroupWise Account

  • Enable the GroupWise Account

Action On GroupWise Account Entitlement Remove

Entitlement option only.

When a user’s GroupWise account entitlement is removed in eDirectory, specify the action you want the driver to take on an associated GroupWise account:

  • Disable the GroupWise account

  • Delete the GroupWise account

  • Expire the GroupWise account

  • Disable and expire the GroupWise account

The following GCVs are password synchronization options:

IMPORTANT:Password synchronization settings are GCVs, but it’s best to edit them in the graphical interface provided on the Server Variables page for the driver, instead of the GCV page. The Server Variables page that shows Password Synchronization settings is accessible as a tab like other driver parameters, or by clicking Password Management > Password Synchronization, searching for the driver, and clicking the driver name. The page contains online help for each password synchronization setting.

Table C-8 Global Configuration Values > Password Synchronization

Option

Description

Set the initial/default GroupWise password on account creation

If True, the GroupWise initial/default password is set when an account is created. The initial password value is specified in the Create Policy. If False, the initial password is not set.

GroupWise has two passwords, the initial password and the regular password. The initial password is stored in clear text and can be seen by an admin. The regular password is encrypted and cannot be viewed. When it is set, the regular password is used by GroupWise instead of the initial password. When a GroupWise user changes his or her password, it is stored as the regular password. For security, the initial password is never set to a password sent from eDirectory.

Synchronize the eDirectory password to the GroupWise regular password

If True, allows passwords to flow from eDirectory to GroupWise. If False, the regular password is not set.

GroupWise has two passwords, the initial password and regular password. The initial password is stored in clear text and can be seen by an admin. The regular password is encrypted and cannot be viewed. When it is set, the regular password is used by GroupWise instead of the initial/default password. When a GroupWise user changes his or her password, it is stored as the regular password. For security, the initial password is never set to a password sent from eDirectory.