B.0 Global Configuration Values

The following table contains the various Global Configuration Values available for the SIF driver on the Global Config Value page. After the driver is created, review these setting to make sure the proper options are set for your environment.

Table B-1 Global Configuration Values

Field Name

Description

Driver Configuration

 

Search container DN

The container below which User IDs must be unique.

When creating a new User object, the driver searches the Identity Vault to verify that the new User ID is not already in use. This container and all subcontainers are searched. Choose the district container or a container that is high enough in the tree that user IDs are unique for all students and staff.

For example, for the environment shown in Figure 2-6, you would specify the District container. This search container is used for all zones.

If you select Yes in the Send New Users to SIF field, only users in this container and its subcontainers are sent to SIF.

Manage preexisting eDirectory users

This option lets you decide whether you want the driver to manage accounts that you already have created in the Identity Vault, before using this driver.

The SIF Driver can match students and staff in the Student Information System (SIS) with preexisting Identity Vault users only if the Identity Vault user attribute DirXML-sifSISID contains the student’s or staff’s ID number.

Select Yes if one of the following is true:

  • You want to manage preexisting Identity Vault users, and the DirXML-sifSISID is set on all users.
  • No users currently exist in the Identity Vault, and you plan to let the driver create them all using the Migrate into the Identity Vault command.

Otherwise, select No.

If Yes is specified, the Migrate into the Identity Vault command can be used to add or update all SIF users into the Identity Vault.

If No is specified, the Migrate into the Identity Vault command is ignored to prevent duplicate users from being created in the Identity Vault.

This field does not apply to users added to the Identity Vault by this driver. Identity Manager can always match these Identity Vault users with Student Information System users, and these Identity Vault users are always kept current with changes from the Student Information System.

For more information on how to make this decision, see Section 5.4, Synchronizing the Identity Vault the First Time.

Send user updates to SIF

Select Yes if you want changes made to users in the Identity Vault to be sent to SIF. You might want to do this for the following reasons:

  • the Identity Vault is the authoritative source for some student information and you want SIF applications notified when it changes.
  • Your Student Information System is not SIF-enabled and you want the Novell SIF Driver to inform SIF of changes to student and staff information.

Otherwise, select No.

Send new users to SIF

Select Yes if you want new users in the Identity Vault to be sent to SIF. You might want to do this if your Student Information System is not SIF-enabled and you want the Novell SIF Driver to inform SIF of new students and staff.

If you select Yes you should also set “Send user updates to SIF” to Yes.

Otherwise, select No.

Send email notification

Send an e-mail notification when an Identity Vault account’s User ID is renamed or when a new user is created with a non-standard User ID.

User IDs must be unique. When the driver receives information for a new student from the Student Information System, it follows the format for creating the User ID that you chose in the User ID Format. Before creating the User object, the driver searches for a duplicate ID starting with the container you specified in the Search container DN. If the driver finds the user ID already exists, the driver creates a unique ID by appending a digit to it. For example, if Dawn Smith had the User ID of DSmith, and a new user named David Smith were added, the driver place him in the appropriate container and would give David the User ID: DSmith1.

Also, when an Identity Vault user account is renamed by the driver, an e-mail notification can be sent. Select Yes if you want e-mail notifications sent. You must have a local SMTP server. Otherwise, select No.

If you select Yes, you are presented with the following four additional prompts:

  • Recipient’s email address

    Replace the sample e-mail address with the recipient’s e-mail address, for example, admin@school.com

  • SMTP server address

    Replace the sample address with the address of an SMTP server, for example, mail.school.com. You must have a local SMTP server.

  • Optional user account on SMTP server

    Optional credential for authentication to the SMTP server. If the SMTP server requires authentication, enter the user account name. Otherwise, leave the field blank.

  • Optional password for user account on SMTP server

    Optional credential for authentication to the SMTP server. If the SMTP server requires authentication, enter the password for the user account. Otherwise, leave the field blank.

    For more information, see the following fields below: Rename student users when naming attributes change and Rename staff users when naming attributes change.

Specify the Student Information System you are using

Select the Student Information Management System you are using.

  • CSIU Administrative Software
  • Apple PowerSchool
  • NCS Pearson SASIxp
  • SunGard Pentamation eSchoolPlus
  • Visual Software

This information is used to accommodate unique features about each SIS. Select Other if the SIS you are using is not listed.

Select Yes if you want to manage student accounts in the Identity Vault, otherwise select No.

Student Configuration

Manage student accounts

Select Yes if you want to manage student accounts in the Identity Vault. Otherwise, select No.

Student user ID format

Configure the Student user ID format. The format is composed of five parts. The five parts are concatenated to produce the user ID.

See the description and example in Section 2.4, Specifying the Pattern for User IDs.

Rename student users when naming attributes change

Select Yes if you want student user accounts in the Identity Vault renamed when any of the attributes change that are used to build the User CN (the attributes you select in Student user ID format). Otherwise, select No.

See Send e-mail notifications in the Driver Configuration options above.

Student placement is by

Select the criteria used to place students in the Identity Vault tree.

  • School and Grade - Students are placed based on their school and grade level.
  • School and Graduation Year - Students are placed based on their school and graduation year.
  • Grade Only - Students are placed by grade level only.
  • Graduation Year Only - Students are placed by their graduation year only.
  • School Only - Students are placed by their schools only.

Student password format

Select a password format for students.

  • Student ID - Student ID number.
  • Preset text - The password is the text specified in the field below.
  • No password - No password is specified; the user logs in without a password.

Student preset text for password

If you selected Preset text in the Student password format field above, specify the password you want to be assigned to new student users. Otherwise, leave this field blank.

Staff and Employee Configuration

Manage staff and employee accounts

Select Yes if you want to manage staff and employee accounts in the Identity Vault. Otherwise, select No.

Typically StaffPersonal objects are maintained by the SIS and EmployeePersonal objects are maintained by the HR system.

When you select Yes, there are additional options. These options are documented below.

SIF Staff and Employee objects to manage

  • StaffPersonal - provisions SIS data into the Identity Vault.
  • EmployeePersonal - provisions HR data in the Identity Vault.
  • StaffPersonal and EmployeePersonal - Provisions both.

Staff user ID format

Configure the Staff user ID format. The format is composed of five parts. The five parts are concatenated to produce the user ID.

See the description and example in Section 2.4, Specifying the Pattern for User IDs.

Rename staff users when naming attributes change

Select Yes if you want staff user accounts in the Identity Vault renamed when any of the attributes change that are used to build the User CN (the attributes you specify in Staff user ID format). Otherwise, select No. See Send email notification in the Driver Configuration options above.

Staff password format

Select a password format for staff.

  • Staff ID - Staff ID number.
  • Preset text - Password is the text specified in the prompt below.
  • No password - No password is specified; the user logs in without a password. You can modify the formats in the Publisher Create style sheet.

Staff preset text for password

If you select Preset text in the Staff password format field above, specify the password you want to be assigned to new staff users. Otherwise, leave this field blank.

Zone Configuration

Zone 1

Configuration information for each SIF Zone the driver connects to.

Select Show to use the zone. Select Hide if you do not need the zone.

The driver can connect up to ten Zones. You can use as many or as few Zones as needed for your environment. The order of the Zones is not important.

Zone 1 through Zone 10 contain the same fields. You specify the information for each Zone.

Connection to Zone

Select Enabled if the driver is to connect to this Zone. Select Disabled if the driver is to ignore these parameters. The connection to a configured Zone is disabled, for example, when testing an individual Zone or when a Zone is offline.

Zone URL

The URL of the SIF Zone Integration Server (ZIS) this driver connects to. The URL can be obtained from the ZIS administrator. It is case sensitive.

The protocol is HTTP (Hypertext Transfer Protocol) or HTTPS (Secure Hypertext Transfer Protocol).

If you have DNS, you can use the hostname; otherwise, use the IP address.

Example URLs are http://www.myzis.com/Zone1 https://1.2.3.4:123/Zone2

When https is specified, the CA certificate for the ZIS must be placed in the java-home\jre\lib\security\jssecacerts keystore file. For more information on how to set this up after importing the driver, see Section 6.2, Setting Up Security.

Incomplete Container DN

The DN of the Incomplete container.

If the grade or school for a student is not provided by the Student Information System, the user is created in the Incomplete container with login disabled. No template is used when creating the user. When the Student Information System provides the missing information, the user is deleted from this container, and created in the correct container.

Browse and select the Incomplete container you created for this Zone.

This is the Incomplete container that you created during planning, in Identifying “Incomplete” Containers.

Disabled container DN

A student’s login is disabled when he or she withdraws from school. If you want the student moved when the login is disabled, browse and select the Disabled container you created for this Zone. If you do not want the user moved, leave this field blank.

Staff container DN

If you are managing SIF staff users, browse and select the container where you want staff users to be placed for this Zone. Leave this field blank if you are not managing staff users.

Staff template DN

If you are managing SIF staff users, browse and select the eDirectory Template object you want to be used when creating staff users. Leave this field blank if you are not managing staff users or if you are not using a template.

Student Placement

School 1

Use this field to separate school configurations. Use this section to configure the placement of students in the same school. It places students in an eDirectory container based on their school code, graduation year, or grade level.

You need to know the values your Student Information System (SIS) uses for schools, graduation years, and grades. Complete as many Student group placement entries as you need to in order to place all students.

Use Show to use the School fields. Use Hide if you do not need all ten options.

School 1 through School 10 contain the same fields. Use the additional School field to define information specific for each school you administer.

School code or ‘all’

The value of this field is based on your Student placement is by criteria. If you specified School and Grade, School and Graduation Year, or School Only enter the school code for this group of students exactly as it is specified in the Student Information System. Contact the administrator to find out the school code. This code might be alpha, numeric, or a combination.

If you specified Group Only or Graduation Year Only in Student placement is by, type all. It must be all lowercase.

Student Group 1 Placement

This section lets you configure the placement of a group of students in the Identity Vault. Students are placed in an eDirectory container based on their school code, graduation year, or grade level. You need to know the values your Student Infomration System (SIS) uses for schools, graduation years and grades. Complete as many Student Group x Placements entries as you need to place all students.

Student Group 1 Placement through Student Group 6 Placement contain the same fields. Use the additional Student Group Placement fields to place additional groups of users.

To use a Student Group Placement fields set the option to Show. If you do not need all six fields, set any fields not in use to Hide.

If you need more than six Student Group Placements for this school, use additional Student Group Placements with the same school code.

Grade code, graduation year, or ‘all’

Fill in this field based on your choice in the Student Placement is by field, in the STUDENT CONFIGURATION section.

If you specified School and Grade or Grade Only in Student Placement is by field, specify the grade level code exactly as it is specified in the SIS.

If you specified School and Graduation Year or Graduation Year Only in Student Placement Is by, specify the graduation year exactly as it is specified in the SIS.

If you specified School Only in Student Placement Is by, type all. It must be all lowercase.

Student container DN

Browse and select the eDirectory container where you want this group of students to be placed.

Student template DN

Browse and select the eDirectory template you want to be used when creating users for this group of students. Leave this field blank if you are not using a template.

SIF Provider Configuration Configure this section only when this driver is the SIF provider for student and staff information, as described in Sending Data from the Identity Vault to SIF. You might want to do this if your Student Information System is not SIF-enabled, and you want the driver to be the SIF provider of student and staff information. Being the provider means this driver responds to SIF queries for information about students and staff.

Be the SIF default provider for students and staff

Select Yes if you want this driver to be the SIF provider for student and staff information. If you select Yes, other settings are displayed.

You might want to do this if your Student Information System is not SIF-enabled and you want the Novell SIF Driver to be the SIF provider of student and staff information. Being the provider means this driver responds to SIF queries for information about students and staff. See Sending Data from the Identity Vault to SIF.

If you select Yes, you must also set Send User Updates to SIF to Yes and Send New Users to SIF to Yes, and configure one or more sets of School Information.

Otherwise, select No.

School information

This field is used to separate school configurations.

This prompt and its sub-prompts are only used if you set Be the SIF Default Provider for Students and Staff to Yes.

This information is used so the SIF Driver can provide the SIF SchoolInfo objects. You need to know the value your Student Information System uses for each school. Complete as many School Information entries as you need to define all schools.

School code

Specify the school code exactly as it is specified in the Student Information System.

School name

Specify the school name as it is specified in the Student Information System.

Zone number

Specify the Zone number (1-10) this school belongs to.

Password Configuration By default, this section has a setting of Hide. It is used only if you want the driver to exchange passwords between the Identity Vault and the SIF zones.

Password Configuration Parameters

The only settings you should edit here are the ones listed in this table.

The others are GCVs regarding Password Synchronization that are common to all drivers. They should be edited using iManager in Passwords > Password Synchronization, not here. Some of them have dependencies on each other that are represented only in the iManager interface. They are explained in Password Synchronization across Connected Systemsin the Novell Identity Manager 3.0.1 Administration Guide.

SIF Driver sends user passwords to the Zone

If set to True, the SIF driver sends user passwords in the Identity Vault to the Zone. Passwords are sent as SIF Authorization objects. Other SIF-enabled applications can subscribe to the Zone to receive the passwords.

You would set this parameter to True when other SIF-enabled applications want to use the user’s network password. When a Distribution Password is set for a new user or when a Distribution Password is changed in the Identity Vault, the Novell SIF driver sends a SIF Authorization object containing the password to the Zone.

SIF Driver accepts user passwords from the Zone

If set to True, the SIF Driver sets user passwords in the Identity Vault to the passwords received from the Zone. The passwords are received as SIF Authorization objects. The passwords are published to the Zone by other SIF-enabled applications.

You would set this parameter to True if you want the network password to be generated by another SIF-enabled application. For example, you have a SIF-enabled application in the Zone that generates a password for each user. When the Novell SIF driver receives the password in a SIF Authorization object, the corresponding user’s eDirectory password is set to this value.

If this parameter is set to True, we recommend that the Novell SIF driver also be configured to set a password for each new user. There might be a delay between the creation of the user account and when the password is received, and it is best to make sure the account is protected by a password at all times.