DX Unified Infrastructure Management

  • 1.  CA UIM -LDAP Integration

    Posted Dec 22, 2016 11:56 AM

    Hi All,

     

       I have integrated UIM integrated with  LDAP  .I have a group with 10 users in a group ,whether it is possible to segregate role base access with that group. As of now all 10 users have admin privilege,we need to modify access for some users.  



  • 2.  Re: CA UIM -LDAP Integration

    Broadcom Employee
    Posted Dec 23, 2016 05:18 AM

    Hi Isaac,

     

    the way the integration works is that you link an ACL with a LDAP user group, and any LDAP user that is a member of that group gains the respective privileges. In order to segregate permissions you need to use different LDAP groups, that is the way the integration works at this moment.

     

    However, LDAP users can be members of several groups and then gain the highest possible privileges.

     

    Kind Regards,


    Martin Fink

    CA Tech Support



  • 3.  Re: CA UIM -LDAP Integration

    Posted Dec 23, 2016 05:36 AM

    Thanks Martin ,

     

    There is any limitation that  UIM queries only certain number of OU in Active directory.



  • 4.  Re: CA UIM -LDAP Integration

    Broadcom Employee
    Posted Dec 23, 2016 05:42 AM

    There can be indeed issues if you OU you defined in the LDAP setting on the hub contains hundreds of LDAP groups.  The issue there would be that the query to get the groups might time out and therefore fail. 

     

    The best way would be to create a sub OU and put only UIM related groups in there and define that OU in the HUB LDAP settings for the group container.

     

    Kind Regards,


    Martin Fink

    CA Tech Support



  • 5.  Re: CA UIM -LDAP Integration

    Posted Dec 23, 2016 08:30 AM

    But in the below KB i could see pre-requisites to create a Flat group under AD. Whether flat group is really needed or it is only for older versions.

     

    https://www.ca.com/us/services-support/ca-support/ca-support-online/knowledge-base-articles.tec000004894.html  



  • 6.  Re: CA UIM -LDAP Integration

    Broadcom Employee
    Posted Dec 23, 2016 08:37 AM

    Hi Isaac,

     

    the important part here is this: "Create a group in AD for your Nimsoft users (create an OU that is dedicated for NMS groups)."

     

    You need to create groups for the different ACL's you want to use, and here we mean that you cannot use nested groups (as these are currently not supported), only flat groups. There is no other workaround for this.

     

    Kind Regards,


    Martin Fink

    CA Tech Support



  • 7.  RE: Re: CA UIM -LDAP Integration

    Posted Jan 22, 2020 01:23 AM
    Hello,
    I would like to make a different question about the UIM-LDAP integration.
    I have noticed that when a new change is occurring in AD (for example I changed the group of a user and expected to see the difference in the privileges of this user in UIM), the change is not depicted simultaneously in UIM.
    Is there any mechanism which is checking AD every X minutes ?
    If yes where it is configured ?
    Kind regards

    ------------------------------
    Infrastructure Software-Systems Engineer
    ------------------------------



  • 8.  RE: Re: CA UIM -LDAP Integration

    Posted Jan 22, 2020 02:01 AM
    I just found this post which is claiming that there is a 15min refresh interval in the attachment.
    Can someone confirm please ?

    ------------------------------
    Infrastructure Software-Systems Engineer
    ------------------------------