Quantcast
Channel: SCN : All Content - SAP Enterprise Portal
Viewing all articles
Browse latest Browse all 3876

LDAP users are not coming into SAP EP

$
0
0

Hi Experts,

 

We have configured LDAP server with portal UME but we are unable to fine LDAP users into portal.

Connection test from portal identity management to LDAP server is working fine.

 

Please find XML file code as below:

 

<?xml version="1.0" encoding="UTF-8"?>

<dataSources>

    <dataSource id="PRIVATE_DATASOURCE"

                className="com.sap.security.core.persistence.datasource.imp.DataBasePersistence"

                isReadonly="false"

                isPrimary="true">

 

 

        <homeFor>

            <principals>

            <principal type="group"/>

            <principal type="user"/>

            <principal type="account"/>

                <principal type="team"/>

                <principal type="ROOT" />

                <principal type="OOOO" />

            </principals>

        </homeFor>

        <notHomeFor />

 

 

        <responsibleFor>

            <principals>

            <principal type="group"/>

            <principal type="user"/>

            <principal type="account"/>

                <principal type="team"/>

                <principal type="ROOT" />

                <principal type="OOOO" />

            </principals>

        </responsibleFor>

 

 

        <privateSection>

        </privateSection>

    </dataSource>

 

 

  <dataSource id="CORP_LDAP"

  className="com.sap.security.core.persistence.datasource.imp.LDAPPersistence"

  isReadonly="true"

  isPrimary="true">

 

 

  <homeFor/>

 

 

  <responsibleFor>

    <principal type="account">

    <nameSpace name="com.sap.security.core.usermanagement">

    <attribute name="j_user"/>

  <attribute name="j_password"/>

  <attribute name="userid"/>

  <attribute name="logonalias"/>

  </nameSpace>

    <nameSpace name="com.sap.security.core.authentication">

    <attribute name="principal"/>

    <attribute name="realm"/>

    <attribute name="domain"/>

    </nameSpace>

  </principal>

  <principal type="user">

  <nameSpace name="com.sap.security.core.usermanagement">

  <attribute name="firstname" populateInitially="true"/>

  <attribute name="displayname" populateInitially="true"/>

  <attribute name="lastname" populateInitially="true"/>

  <attribute name="fax"/>

  <attribute name="email"/>

  <attribute name="title"/>

  <attribute name="department"/>

  <attribute name="description"/>

  <attribute name="mobile"/>

  <attribute name="telephone"/>

  <attribute name="streetaddress"/>

  <attribute name="uniquename" populateInitially="true"/>

  </nameSpace>

    <nameSpace name="com.sap.security.core.usermanagement.relation">

    <attribute name="PRINCIPAL_RELATION_PARENT_ATTRIBUTE"/>

    </nameSpace>

    <nameSpace name="$usermapping$">

    <attribute name="REFERENCE_SYSTEM_USER"/>

    </nameSpace>

    </principal>

    <principal type="group">

      <nameSpace name="com.sap.security.core.usermanagement">

      <attribute name="displayname" populateInitially="true"/>

      <attribute name="description" populateInitially="true"/>

     <attribute name="uniquename"/>

  </nameSpace>

  <nameSpace name="com.sap.security.core.usermanagement.relation">

  <attribute name="PRINCIPAL_RELATION_MEMBER_ATTRIBUTE"/>

  <attribute name="PRINCIPAL_RELATION_PARENT_ATTRIBUTE"/>

  </nameSpace>

  <nameSpace name="com.sap.security.core.bridge">

  <attribute name="dn"/>

  </nameSpace>

  </principal>

  </responsibleFor>

 

 

  <attributeMapping>

  <principal type="account">

  <nameSpace name="com.sap.security.core.usermanagement">

  <attribute name="j_user">

  <physicalAttribute name="samaccountname"/>

  </attribute>

  <attribute name="logonalias">

  <physicalAttribute name="samaccountname"/>

  </attribute>

  <attribute name="j_password">

  <physicalAttribute name="unicodepwd"/>

  </attribute>

  <attribute name="userid">

  <physicalAttribute name="*null*"/>

  </attribute>

  </nameSpace>

    <nameSpace name="com.sap.security.core.authentication">

    <attribute name="principal">

    <physicalAttribute name="samaccountname"/>

    </attribute>

    <attribute name="realm">

    <physicalAttribute name="*null*"/>

    </attribute>

    <attribute name="domain">

    <physicalAttribute name="*null*"/>

    </attribute>

    </nameSpace>

  </principal>

 

 

  <principal type="user">

  <nameSpace name="com.sap.security.core.usermanagement">

  <attribute name="firstname">

  <physicalAttribute name="givenname"/>

  </attribute>

  <attribute name="displayname">

  <physicalAttribute name="displayname"/>

  </attribute>

  <attribute name="lastname">

  <physicalAttribute name="sn"/>

  </attribute>

  <attribute name="fax">

  <physicalAttribute name="facsimiletelephonenumber"/>

  </attribute>

  <attribute name="uniquename">

  <physicalAttribute name="samaccountname"/>

  </attribute>

  <attribute name="loginid">

  <physicalAttribute name="*null*"/>

  </attribute>

  <attribute name="email">

  <physicalAttribute name="mail"/>

  </attribute>

  <attribute name="mobile">

  <physicalAttribute name="mobile"/>

  </attribute>

  <attribute name="telephone">

  <physicalAttribute name="telephonenumber"/>

  </attribute>

  <attribute name="department">

  <physicalAttribute name="ou"/>

  </attribute>

  <attribute name="description">

  <physicalAttribute name="description"/>

  </attribute>

  <attribute name="streetaddress">

  <physicalAttribute name="postaladdress"/>

  </attribute>

  <attribute name="pobox">

  <physicalAttribute name="postofficebox"/>

  </attribute>

  </nameSpace>

  <nameSpace name="com.sap.security.core.usermanagement.relation">

  <attribute name="PRINCIPAL_RELATION_PARENT_ATTRIBUTE">

  <physicalAttribute name="*null*"/>

  </attribute>

  </nameSpace>

  <nameSpace name="$usermapping$">

  <attribute name="REFERENCE_SYSTEM_USER">

  <physicalAttribute name="sapusername"/>

  </attribute>

  </nameSpace>

  </principal>

  <principal type="group">

  <nameSpace name="com.sap.security.core.usermanagement">

  <attribute name="displayname">

  <physicalAttribute name="displayname"/>

  </attribute>

  <attribute name="description">

  <physicalAttribute name="description"/>

  </attribute>

  <attribute name="uniquename" populateInitially="true">

  <physicalAttribute name="ou"/>

  </attribute>

  </nameSpace>

  <nameSpace name="com.sap.security.core.usermanagement.relation">

  <attribute name="PRINCIPAL_RELATION_MEMBER_ATTRIBUTE">

  <physicalAttribute name="*null*"/>

  </attribute>

  <attribute name="PRINCIPAL_RELATION_PARENT_ATTRIBUTE">

  <physicalAttribute name="*null*"/>

  </attribute>

  </nameSpace>

  <nameSpace name="com.sap.security.core.bridge">

  <attribute name="dn">

  <physicalAttribute name="*null*"/>

  </attribute>

  </nameSpace>

  </principal>

  </attributeMapping>

  <privateSection>

  <ume.ldap.access.server_type>MSADS</ume.ldap.access.server_type>

  <ume.ldap.access.context_factory>com.sun.jndi.ldap.LdapCtxFactory</ume.ldap.access.context_factory>

  <ume.ldap.access.authentication>simple</ume.ldap.access.authentication>

  <ume.ldap.access.flat_group_hierachy>false</ume.ldap.access.flat_group_hierachy>

  <ume.ldap.access.user_as_account>true</ume.ldap.access.user_as_account>

  <ume.ldap.access.dynamic_groups>false</ume.ldap.access.dynamic_groups>

  <ume.ldap.access.ssl_socket_factory>com.sap.security.core.server.https.SecureConnectionFactory</ume.ldap.access.ssl_socket_factory>

  <ume.ldap.access.objectclass.user>User</ume.ldap.access.objectclass.user>

  <ume.ldap.access.objectclass.uacc>User</ume.ldap.access.objectclass.uacc>

  <ume.ldap.access.objectclass.grup>organizationalUnit</ume.ldap.access.objectclass.grup>

  <ume.ldap.access.naming_attribute.user>cn</ume.ldap.access.naming_attribute.user>

  <ume.ldap.access.auxiliary_naming_attribute.user>samaccountname</ume.ldap.access.auxiliary_naming_attribute.user>

  <ume.ldap.access.naming_attribute.uacc>cn</ume.ldap.access.naming_attribute.uacc>

  <ume.ldap.access.auxiliary_naming_attribute.uacc>samaccountname</ume.ldap.access.auxiliary_naming_attribute.uacc>

  <ume.ldap.access.naming_attribute.grup>ou</ume.ldap.access.naming_attribute.grup>

  </privateSection>

  </dataSource>

</dataSources>

 

 

Need your advise for the same.

 

Regards,

Krunal Patel


Viewing all articles
Browse latest Browse all 3876

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>