Active Directory Accelerator Guide

Active Directory Accelerator Guide

Debug the Active Directory Accelerator Overview

Debug the Active Directory Accelerator Overview

You can debug the LDAP matcher before you use it with Dynamic Data Masking.
The LDAP debug mode does not use a security rule set. The debug mode allows you do define the LDAP_ACTUAL_USER, ATTR_NAME, ATTR_VALUES, and Groups symbols to determine whether the LDAP matcher correctly matches the Groups symbol or the ATTR_NAME and ATTR_VALUES symbols for the LDAP_ACTUAL_USER user.
When you run the accelerator standalone, you create output files that show the message outputs for LDAP group matching and attribute values matching. When you run the accelerator with the Dynamic Data Masking Server, you enable the debug log level that logs detailed information to the server.log file.
Compare the output files to verify that the Active Directory Accelerator runs with and without the Dynamic Data Masking Server.
The following text shows an example of the debug information from the server.log file:
12/05 16:03:50,829 [DDM for Oracle-2] DEBUG - Match User according to Attribute countryCode and Attribute Values 123|456|789 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute userPrincipalName: user@company.com 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute userPrincipalName has 1 values 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute description: Team Lead 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute description has 1 values 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute showInAddressBook: CN=Default Global Address List,CN=All Global Address Lists,CN=Address Lists Container,CN=Company,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=Company,DC=com, CN=All Users,CN=All Address Lists,CN=Address Lists Container,CN=Company,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=Company,DC=com 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute showInAddressBook has 2 values 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute mailNickname: user 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute mailNickname has 1 values 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute homeDirectory: \\\home\user 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute homeDirectory has 1 values 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute homeDrive: U: 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute homeDrive has 1 values 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute uSNChanged: 12345678 12/05 16:03:50,838 [DDM for Oracle-2] DEBUG - Attribute uSNChanged has 1 values ……………………………………………………………………………………………………………………………… 12/05 16:03:50,842 [DDM for Oracle-2] DEBUG - Attribute userAccountControl has 1 values 12/05 16:03:50,843 [DDM for Oracle-2] DEBUG - Attribute location: City 12/05 16:03:50,843 [DDM for Oracle-2] DEBUG - Attribute location has 1 values 12/05 16:03:50,843 [DDM for Oracle-2] DEBUG - *************************** 12/05 16:03:50,843 [DDM for Oracle-2] DEBUG - Value 123 of attribute countryCode found 12/05 16:03:50,843 [DDM for Oracle-2] DEBUG - LDAP returns TRUE

0 COMMENTS

We’d like to hear from you!