Table of Contents

Search

  1. About the Security Guide
  2. Introduction to Informatica Security
  3. User Authentication
  4. LDAP Authentication
  5. Kerberos Authentication
  6. SAML Authentication for Informatica Web Applications
  7. Domain Security
  8. Security Management in Informatica Administrator
  9. Users and Groups
  10. Privileges and Roles
  11. Permissions
  12. Audit Reports
  13. Appendix A: Command Line Privileges and Permissions
  14. Appendix B: Custom Roles

Security Guide

Security Guide

Configure the Synchronization Schedule

Configure the Synchronization Schedule

You can set up a daily schedule for the Service Manager to update the LDAP security domains with new or changed users and groups in the LDAP directory service.
When the Service Manager synchronizes the LDAP security domains with the LDAP directory service, it imports all users that match the user filter settings from the LDAP directory service into the security domain. The Service Manager then imports all groups that match the group filter settings, and associates users with their corresponding groups. The Service Manager also deletes any user or group not found in the LDAP directory service from the security domain.
By default, the Service Manager is not scheduled time to synchronize with the LDAP directory service. To ensure that the list of users and groups in the LDAP security domains is accurate, schedule when the Service Manager synchronizes the LDAP security domains with the LDAP directory service. The Service Manager synchronizes the LDAP security domains with the LDAP directory service every day at the times you set.
To ensure that synchronization succeeds, consider the following recommendations before set up the synchronization schedule:
Verify that the /etc/hosts file contains an entry for the LDAP server.
Verify that the
/etc/hosts
file on each node gateway in the domain contains an entry with the host name and IP address of the LDAP server. If the Service Manager cannot resolve the host name for the LDAP server, synchronization can fail.
Enable paging in LDAP if you are synchronizing more than 100 users or groups.
Enable paging on the LDAP directory service before you synchronize more than 100 users or groups. If you do not enable paging on the LDAP directory service, synchronization can fail.
Synchronize security domains during times when most users are not logged in to Informatica applications.
During synchronization, the Service Manager locks each user account it synchronizes. Users might not be able to log in to the Informatica application clients during synchronization. Users logged in to an application client when synchronization starts might not be able to perform certain tasks.
To set up a schedule that synchronizes LDAP security domains with the LDAP directory service, perform the following steps:
  1. In the Administrator tool, click the
    Security
    tab.
  2. Click the
    Actions
    menu and select
    LDAP Configuration
    .
  3. In the
    LDAP Configuration
    dialog box, click the
    Schedule
    tab.
  4. Click the
    Add
    button (+) to add a time.
    The synchronization schedule uses a 24-hour time format.
  5. To immediately synchronize the users and groups in the LDAP security domains with the users and groups in the LDAP directory service, click
    Synchronize Now
    .
  6. Click
    OK
    to save the synchronization schedule.
    Wait until the Service Manager synchronizes with the LDAP directory service before restarting the Informatica domain to avoid losing the synchronization times that you set in the schedule.

0 COMMENTS

We’d like to hear from you!