You can set up a daily schedule for the Service Manager to update the LDAP security domains with new or changed users and groups in the LDAP directory service.
When the Service Manager synchronizes the LDAP security domains with the LDAP directory service, it imports all users that match the user filter settings from the LDAP directory service into the security domain. The Service Manager then imports all groups that match the group filter settings, and associates users with their corresponding groups. The Service Manager also deletes any user or group not found in the LDAP directory service from the security domain.
By default, the Service Manager is not scheduled time to synchronize with the LDAP directory service. To ensure that the list of users and groups in the LDAP security domains is accurate, schedule when the Service Manager synchronizes the LDAP security domains with the LDAP directory service. The Service Manager synchronizes the LDAP security domains with the LDAP directory service every day at the times you set.
To ensure that synchronization succeeds, consider the following recommendations before set up the synchronization schedule:
Verify that the /etc/hosts file contains an entry for the LDAP server.
Verify that the
/etc/hosts
file on each node gateway in the domain contains an entry with the host name and IP address of the LDAP server. If the Service Manager cannot resolve the host name for the LDAP server, synchronization can fail.
Enable paging in LDAP if you are synchronizing more than 100 users or groups.
Enable paging on the LDAP directory service before you synchronize more than 100 users or groups. If you do not enable paging on the LDAP directory service, synchronization can fail.
Synchronize security domains during times when most users are not logged in to Informatica applications.
During synchronization, the Service Manager locks each user account it synchronizes. Users might not be able to log in to the Informatica application clients during synchronization. Users logged in to an application client when synchronization starts might not be able to perform certain tasks.
To set up a schedule that synchronizes LDAP security domains with the LDAP directory service, perform the following steps:
In the Administrator tool, click the
Security
tab.
Click the
Actions
menu and select
LDAP Configuration
.
In the
LDAP Configuration
dialog box, click the
Schedule
tab.
Click the
Add
button (+) to add a time.
The synchronization schedule uses a 24-hour time format.
To immediately synchronize the users and groups in the LDAP security domains with the users and groups in the LDAP directory service, click
Synchronize Now
.
Click
OK
to save the synchronization schedule.
Wait until the Service Manager synchronizes with the LDAP directory service before restarting the Informatica domain to avoid losing the synchronization times that you set in the schedule.