3.5 Setting Up the Driver on the Metadirectory Server

  1. In iManager, select the Identity Manager Utilities task New Driver.

  2. Select a driver set where you want to create the driver, then click Next.

    If you place this driver in a new driver set, you must specify a driver set name, context, and associated server.

    Only one driver set can be active on a server.

  3. Import the driver rules file.

    Select Import a driver configuration from the client (.XML file), select TopSecret-IDM3_5_0-V2.xml, then click Next.

  4. Specify the configuration settings as described in the following table, then click Next.

    Configuration Setting

    Action

    Driver Name

    Specify a name for the driver object.

    Data Flow

    Select Bidirectional, Application to Identity Vault, or Identity Vault to Application. For details, see Data Flow.

    Base Container

    Specify the Identity Vault container where synchronized users and groups reside.

    You can specify separate containers for users and groups by updating the driver properties later. For details, see User Base Container and Group Base Container.

    Set Preconfigured TSO Data

    Select Yes or No. For details, see Section 1.2.3, TSO Information Management.

    Set Preconfigured OMVS Data

    Select Yes or No. For details, see Section 1.2.2, OMVS Information Management.

    Create Using

    Specify a user to be used as a template for creating new users. For details, see Create Users With.

    Default Department

    Specify a department to be assigned to new users created by the driver. For details, see User Default Department.

    Default Group

    Specify a group to be used as the default group for new users created by the driver. For details, see User Default Group.

    User Catalog Alias

    Specify a catalog for alias entries for new users created by the driver. For details, see User Catalog Alias.

    Group Catalog Alias

    Specify a catalog for alias entries for new groups created by the driver. For details, see Group Catalog Alias.

    Enable Entitlements

    Select Yes or No. For details, see Enable Entitlements.

    Polling Interval

    Specify the number of seconds the Publisher shim waits after sending events from the change log to the Metadirectory engine. For details, see Polling Interval.

    Remote Host Name and Port

    Specify the host name or IP address and TCP port number of the driver shim on your connected system. The default port number is 8090.

    Use SSL

    Select Yes or No. For details, see Use SSL.

    Driver Object Password Remote Loader Password

    Specify secure passwords and remember them. You must enter them when you run the SETPDWDS exec while installing the driver shim on the connected system. For details, see Driver Object Password and Remote Loader Password.

    Default TSO Account Number

    Specify the default account number for new users created by the driver. For details, see User Default TSO Account Number.

    Default TSO Procedure

    Specify the default cataloged procedure name for new users created by the driver. For details, see User Default TSO Proc.

    Default TSO Unit

    Specify the default disk unit name for new users created by the driver. For details, see User Default TSO Unit.

    UID and GID Assignment

    Select Assign by Top Secret or Assign by Identity Vault. For details, see UID Assignment.

    UID Range

    Specify a range of numbers to use when the TSS command assigns UID numbers for new users. For details, see UID Range.

    GID Range

    Specify a range of numbers to use when the TSS command assigns GID numbers for new groups. For details, see GID Range.

    Default Home Directory

    Specify an HFS file path to be used as the default home directory for new users created by the driver. For details, see Default Home Directory.

    Default Program

    Specify the default login shell to be assigned to new users created by the driver. For details, see Default Program.

  5. Click Define Security Equivalences and make the driver equivalent to Admin or another high-rights user so the driver can obtain information from the Identity Vault and create users and groups there.

    For details about the rights required by the user, see Table 2-2, Base Container Rights Required by the Driver Security-Equivalent User.

  6. (Optional) Click Exclude Administrative Roles to exclude users with administrative rights from being processed by the driver.

  7. Click Finish to complete the driver installation.

  8. Start the driver.

    Click the upper right corner of the driver icon, then click Start driver.