Microsoft FIM: Working with Domino Connector v8

Posted on July 22, 2013 by Michael Pearn4 Comments

Rate This

We don’t always work with all of the ‘latest’ or ‘bleeding edge’ software here at Kloud, and occasionally us Identity Management consultants have to delve into the past and use some knowledge once thought lost from the world. Okay, so it’s not that bad, but I did find myself having to work with IBM Domino Server version 8 and FIM R2′s ECMA based Lotus Domino Management Agent (or ‘Connector’ in the new language) for a bi-directional sync between Domino and Active Directory (Exchange, Lync etc.).

The Technical Reference document supplied with the Connector from Microsoft is good (http://technet.microsoft.com/en-us/library/hh859750(v=ws.10).aspx), but not perfect and in my opinion is probably missing about 10% of the information required to get an import and export working with the connector.

There’s some key information missing from the document, at least in terms of interpreting ‘error codes’ because when you run into errors (and I’d be amazed if you didn’t!), there isn’t much guidance interpreting the errors that appear on the Microsoft FIM server side of things. Also, there’s very little in the way of guidance for those that have had to use Sync. Rules to import/export from Domino 8.

I’ll split this up into a few sections – first will be to verify the Notes side of things in terms of client installation and FIM/Domino server side requirements. The second section will be listing the errors I encountered (interpreted as a Microsoft FIM expert, not Domino remember!) and the actions I needed to follow up with the Domino expert to get the Connector working in both directions.

Installing the Notes Client

The guidance is actually very good in the MS document and be sure to follow it to the letter, particularly the guidance around which features to install (don’t forget to specify to install the ‘Client Single Logon Feature’ as it’s not default!). Also, when you’re installing the Lotus Client be sure to specify that you’re installing it for a ‘single user‘ only and ensure the ‘Data’ folder does NOT get created under the ‘Application Data’ folder:

For my customer, I installed everything under one very basic path: <Install drive>:\IBM\Lotus\Notes, and ensured my data folder was under: <Install drive>:\IBM\Lotus\Notes\Data.  Your installation should look similar to the following (click to enlarge):

I then applied ‘full control’ permissions to my FIM Synchronisation service account to the <Install drive>:\IBM\Lotus\ folder.

For any of my .ID files that I needed to use (minimum 1 for importing only, minimum 2 for importing & exporting), I then copied these to the <Install drive>:\IBM\Lotus\Notes\Datafolder. There’s guidance out there to suggest that you need to install Lotus Notes logged in as the Synchronization Service. This is not required in my experience and actually breaks Microsoft ‘best practice’ which denies allowing the Sync. service console login rights.

Check indexing and ACLs in Lotus Notes

In my career, I’ve often been told ‘yep! That’s been done’ by all sorts of people. I don’t take everything at face value and prefer to check everything myself. One of the critical requirements to get the Connector working is to ensure that ‘indexing’ has been applied to the Names.nsf.

  1. Open Lotus Notes and first create a Workspace Icon for the Address book in question and then open the Domino Directory (names.nsf).
  2. Check the existence of indexing by browsing to: File àApplication Properties and click the ‘magnifying glass’ icon to verify that database has had a recent index applied to it. Check the ‘update frequency (servers only)’ is set to ‘immediate’:

3. Check to ensure your account has the correct ACLs by browsing to: File à Access Control. Locate your account in the list and select it. On the right, you can verify the correct permissions (click to expand):

Sync Rules

The following images highlight an example of ‘export Sync. Rules’, in particular the ‘initial flow’ values that you supply when you only ‘create’ (export) a person from FIM to Domino.  Your ‘Organization value i.e.: O=Org’ will be particular to your Domino environment (click to enlarge):

Note, the key part of my guidance is using ‘comma’ separate values for the Distinguished Name (DN) requirement. Previous Visual Basic and C# .NET code made sure you used ‘forward slashes’ for the DN value (e.g. CN=Michael Pearn/O=Org,NAB=names.nsf). In my experience, this does not work and all values should be comma separated. Be very wary of using this sample code for the Domino v8 connector (I’ve tried and failed):http://msdn.microsoft.com/en-us/library/windows/desktop/ms696023(v=vs.85).aspx

Enable Domino Connector Logging

It’s vital that you enable the Synchronization Service logging created at: <program files>\Microsoft Forefront Identity Manager\2010\Synchronization Service\Extensions\LotusDominoConnector.txt.

At a minimum, set the log file value to ’3′ (in the logging.xml file in the same Extension folder) to capture all events and detail. The next few sections will refer to the error strings that were present in this log.

Troubleshooting Errors

Error #1: “Unable to retrieve schema. Error: An anchor attribute defined by the extension must not be of type Reference or Boolean. A multivalued attribute defined by the extension must not be of type Boolean”

In hindsight, this is an obvious error however if you attempt to connect to Domino without checking your ACLs or Indexing, then you will be bound to get this error at some stage.

Stop, down tools and talk to your Domino admin. There is no way to fix this issue from the FIM side of things. If you see any errors between the “Connectivity” and “Global Parameters” page then check:

  1. Your ID account you are using has the proper permissions to the Names.NSF you are connecting to as per the guidance earlier.
  2. You have a good names resolution and IP ping network connection to the Domino server. Domino relies a lot on resolving NetBIOS names to the server, so troubleshooting DNS will do no good here. Also, be wary of trying to use a ‘laptop lab’ (as I call them) whereby you’re trying to use a personal Hyper-V lab connecting to a production infrastructure. For the life of me I could not get my lab connecting to a Domino server so shifted my testing to a network connected server and this solved 90% of my connectivity problems. I’d strongly recommend using a dedicated testing FIM server for any kind of Domino import/export testing.
  3. Ensure indexing is applied as per the guidance earlier.

Verify this connection is working and potentially error free by checking the ‘Time Zone’ information on the “Global Parameters” page of the Domino Connector properties. If it is blank, then there are connectivity problems which need to be resolved before continuing.

Error #2: “Invalid-Provisioning-attribute-value”

Buried in the Microsoft guidance is the sentence ‘You should have the O/OU certifier Id and the password to register a particular user in the Organization / Organization Unit”. This is a very key point and I overlooked it when I first started working. This setting is actually (unhelpfully) located at the bottom of the ‘Global Parameters’ section of the Domino Connector properties:

Imports will work fine without specifying a value here, however your Domino server will require the ID file used to create objects for that ‘Certifier’ (and don’t ask me what that means!). If you neglect to specify the ID file and password here, then you will see an error in the Metaverse export run as ‘Invalid-Provisioning-attribute-value’, and your error will appear in the log as:

————————————————————————————————————————

2013-07-16T16:53:23 [1768:6028] Trace – DominoPerson:RegisterUser : “Domino” – certkey :

2013-07-16T16:53:23 [1768:6028] Trace – DominoPerson:RegisterUser : “Domino” -certkey is missing.

2013-07-16T16:53:23 [1768:6028] Trace – Person:Add : “Domino” – UniversalID :

2013-07-16T16:53:23 [1768:6028] Trace – LotusDominoMA:PutExportEntries : “Domino” – Call ended

————————————————————————————————————————

Error #3: “Required attribute ‘UniversalID’ is missing”

I’ve seen a few people post on the Internet their concerns that when they get an issue exporting to Domino, if they click in the Sync engine ‘Validate object against schema’, they get an error message: ‘UniversalID is missing’. While it’s true the connector uses UniversalID as an anchor variable, there is no requirement to provision a calculated value for this and this error can be safely ignored. Red herring people!

Error #4: “You are not allowed to update the Certifier log”

My last error involves an error in the Sync engine “Invalid-attribute-value” and this error appearing in the Domino log:

————————————————————————————————————————

2013-07-17T13:57:53 [1156:3512] Trace – DominoPerson:RegisterUser : “Domino” – userIdFile : pearnm.id

2013-07-17T13:57:53 [1156:3512] Trace – DominoPerson:RegisterUser : “Domino” – MailServer :

2013-07-17T13:57:54 [1156:3512] Error – Person:ExportEntry : “Domino” – Exception Occurred

——— Outer Exception Data ———

Message: Notes error: You are not allowed to update the certifier log (Pearn)

Exception root Exception type: System.Runtime.InteropServices.COMException

Source: NotesRegistration

————————————————————————————————————————

This error essentially means the export .ID file that you’re using does not have rights to create ID files.  Ask your Domino administrator to add your account to the ‘local domain admins’ group for that Domino Organisation.  After my account was added to the correct Domino permissions, the export went through perfectly.

Microsoft FIM: Working with Domino Connector v8的更多相关文章

  1. [转载]资深程序员点评当前某些对Lotus Domino 的不实评论

    实现机关办公自动化工作需要计算机技术的支持,在计算机软件范围中,有网络操作系统软件.数据库软件和开发工具等基本系统软件,在此基础上开发出适合本单位使用的应用软件.对如何选用系统软件,笔者没有发言权,但 ...

  2. 在全程Linux環境部署IBM Lotus Domino/Notes 8.5

    架設藍色巨人的協同合作訊息平台 在全程Linux環境部署IBM Lotus Domino/Notes 8.5 珊迪小姐 坊間幾乎所有探討IBM Domino/Notes的中文書籍,皆是以部署在Micr ...

  3. 超时时间已到。在操作完成之前超时时间已过或服务器未响应。 (.Net SqlClient Data Provider)

    超时时间已到.在操作完成之前超时时间已过或服务器未响应. (.Net SqlClient Data Provider) 在做一个小东西的时候出现了这个问题,就是使用VS调试几次项目后,使用SQL Se ...

  4. Moodle插件之Filters(过滤器)

    Moodle插件之Filters(过滤器) 过滤器是一种在输出之前自动转换内容的方法. 目的: 创建名为helloworld的过滤器,实现将预输出的“world”字符串替换成“hello world” ...

  5. linux服务之openldap

    http://www.openldap.org/ http://blog.csdn.net/chinalinuxzend/article/details/1870656 OpenLDAP学习笔记 ht ...

  6. Dynamics CRM 2011 报表无法显示的问题总结

    一.一般打开报表会出现:该报表无法显示.(reProcessingAborted)和由于运行Microsoft SQL Server Reporting Services 的服务器上没有安装 Micr ...

  7. Sqlserver学习研究

    关注关键词 :Sqlserver实用工具配置步骤 1)创建实用工具控制点(UCP) 2)连接到现有UCP 3)相UCP注册SQL Server实例 4)创建数据层应用程序 5)设置资源运行状况策略 6 ...

  8. Linux 上配置 AG

    SQL Server Always On Availability Group 配置步骤:配置三台 Linux 集群节点创建 Availability Group配置 Cluster Resource ...

  9. Linux 上配置 SQL Server Always On Availability Group

    SQL Server Always On Availability Group 配置步骤:配置三台 Linux 集群节点创建 Availability Group配置 Cluster Resource ...

随机推荐

  1. 2^x mod n = 1(欧拉定理,欧拉函数,快速幂乘)

    2^x mod n = 1 Time Limit: 2000/1000 MS (Java/Others)    Memory Limit: 65536/32768 K (Java/Others)Tot ...

  2. Legolas工业自动化平台入门(三)交互事件响应动作

    在上一篇Legolas工业自动化平台入门(二)数据响应动作 一文中,我们介绍了"动作"相关内容,了解到"动作"分为多种,各种动作的添加方式相同,但是应用方式各自 ...

  3. CSS布局:Float布局过程与老生常谈的三栏布局

    原文见博客主站,欢迎大家去评论. 使用CSS布局网页,那是前端的基本功了,什么两栏布局,三栏布局,那也是前端面试的基本题了.一般来说,可以使用CSSposition属性进行布局,或者使用CSSfloa ...

  4. 移动安全时代,如何保护你的app

    Android系统的安全性历来备受诟病,在强大的反编译工具下,APK中的代码逻辑一览无余:重打包技术使得各种盗版软件层出不穷,充斥着Android市场,特别是对于金融.电商.游戏等产品的盗版应用,严重 ...

  5. Tips5:通过 alt+鼠标左键 来完全展开或收缩层级

    通过 alt+点击 可以完全地展开或关闭unity中的各种层级关系,包括Hierarchy视图 或 Project视图中的. 上图中,第一次点击没有按住ALT键,可以发现子项目并没有被展开,而第二次是 ...

  6. iOS-nil,Nil,NULL的区别

    一.简述 1.nil用来给对象赋值(Objective-C中的任何对象都属于id类型) 2.NULL则给任何指针赋值,NULL和nil不能互换 3.nil用于类指针赋值(在Objective-C中类是 ...

  7. Android 学习笔记之Volley(八)实现网络图片的数据加载

    PS:最后一篇关于Volley框架的博客... 学习内容: 1.使用ImageRequest.java实现网络图片加载 2.使用ImageLoader.java实现网络图片加载 3.使用NetWork ...

  8. ASP.NET身份验证

    Asp.net的身份验证有有三种,分别是"Windows | Forms | Passport",其中又以Forms验 证用的最多,也最灵活. Forms 验证方式对基于用户的验证 ...

  9. SpringMVC核心——映射问题

    一.SpringMVC 使用 RequestMapping 来解决映射问题. 二.在学习 RequestMapping 之前,首先来看一张图. 这张图表示的是发送一次 http 请求时,所包含的请求 ...

  10. 重构第16天 封装条件(Encapsulate Conditional)

    理解:本文中的“封装条件”是指条件关系比较复杂时,代码的可读性会比较差,所以这时我们应当根据条件表达式是否需要参数将条件表达式提取成可读性更好的属性或者方法,如果条件表达式不需要参数则可以提取成属性, ...