We have a few admin accounts named su#1, su#2 etc... All other accounts get
sync perfectly, but these su#1,su#2... gives a problem. Here is a level 3
DSTrace.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: Creation.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Create User objects'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name equal "User") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'Create User objects'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-veto-if-op-attr-not-available("Full Name").
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-dest-attr-value("DirXML-ADAliasName",token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-src-name()
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su\#8".
Thursday, Mar 9, 2006
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-src-attr-value("DirXML-ADAliasName",token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-src-name()
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-dest-password(token-op-attr("Surname")+"-- suppressed --").
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-op-attr("Surname")+"-- suppressed --")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-op-attr("Surname")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "-- suppressed --".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-text("-- suppressed --")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "-- suppressed --".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'map user name to Windows logon name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'UpnMap' equal "edir-name-auth") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name equal "User") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'map user name to Windows logon name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-dest-attr-value("userPrincipalName",class-name="User",token-src-name()+"@"+"comp.nl").
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-src-name()+"@"+"comp.nl")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-src-name()
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-text("@")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-text("comp.nl")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su\#8@comp.nl".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Create Group objects'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name equal "Group") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Identity Vault accounts are enabled
if Login Disabled does not exist'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name equal "User") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-op-attr 'Login Disabled' not-available) = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'default Exchange assignment'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'ExchMailboxPolicy' equal "policy") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Direct
command from policy
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="User" dest-dn="\comp\comp\su#8" dest-entry-id="35353"
event-id="HEAD#20060309143022#2#77">
<modify-attr attr-name="DirXML-ADAliasName">
<remove-all-values/>
<add-value>
<value type="string">su\#8</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Pumping
XDS to eDirectory.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Performing operation modify for \comp\comp\su#8.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Modifying entry \comp\comp\su#8.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Processing returned document.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Processing operation <status> for .
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
DirXML Log Event -------------------
Driver: \comp\comp\ADNDSDriverSet\Active Directory
Channel: Subscriber
Object: \comp\comp\su#8
Status: Error
Message: Code(-9010) An exception occurred: novell.jclient.JCException:
modifyEntry -608 ERR_ILLEGAL_ATTRIBUTE
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Direct
command from policy result
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="HEAD#20060309143022#2#77" level="error">Code(-9010) An
exception occurred: novell.jclient.JCException: modifyEntry -608
ERR_ILLEGAL_ATTRIBUTE<application>DirXML</application>
<module>Active Directory</module>
<object-dn>\comp\comp\su#8</object-dn>
<component>Subscriber</component>
</status>
</output>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" event-id="HEAD#20060309143022#2#77"
qualified-src-dn="O=comp\CN=su#8" src-dn="\comp\comp\su#8"
src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">3784 rg<value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">AM</value>
</add-attr>
<add-attr attr-name="SA">
<value timestamp="1141914622#68" type="string">amstreet</value>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: </add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8"/>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
object placement policies.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: Placement.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'placement for all objects'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'placement for all objects'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-op-dest-dn(arg-dn(token-op-property("unmatched-src-dn")+","+"cn=users,dc=comp,dc=nl")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-dn(token-op-property("unmatched-src-dn")+","+"cn=users,dc=comp,dc=nl")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-op-property("unmatched-src-dn")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "CN=su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-text(",")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-text("cn=users,dc=comp,dc=nl")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "CN=su\#8,cn=users,dc=comp,dc=nl".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Use Full Name for naming user objects'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name equal "User") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'FullNameMap' equal "true") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'Use Full Name for naming user objects'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-op-dest-dn(arg-dn("CN="+token-escape-for-dest-dn(token-attr("CN"))+","+token-dest-dn(length="-2"))).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-dn("CN="+token-escape-for-dest-dn(token-attr("CN"))+","+token-dest-dn(length="-2"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-text("CN=")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-escape-for-dest-dn(token-attr("CN"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-escape-for-dest-dn(token-attr("CN"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-attr("CN")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "su#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "su\#8".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-text(",")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-dest-dn(length="-2")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "cn=users,dc=comp,dc=nl".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "CN=su\#8,cn=users,dc=comp,dc=nl".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="SA">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914622#68" type="string">Amstreet</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8"/>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Submitting add to subscriber shim.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
command transformation policies.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: Command.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'default Exchange assignment'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'ExchMailboxPolicy' equal "policy") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="SA">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914622#68" type="string">Amstreet</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8"/>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'A set of rules that are executed when any one of the user name
mapping options are selected.'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'consider user objects when name
mapping is enabled'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name not-equal "User") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'FullNameMap' equal "false") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'generate full name on merge'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'FullNameMap' equal "true") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-xpath true ".[@from-merge='true']") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'map full name to destination object
name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'FullNameMap' equal "true") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "modify") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'escape source object name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "rename") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'map rename to NT logon name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'LogonNameMap' equal "true") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "rename") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'map rename to Active Directory
logon name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'UpnMap' equal "edir-name-auth") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "rename") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'map e-mail address to Active
Directory logon name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'unmap e-mail address from Active
Directory logon name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'map e-mail address to Active
Directory logon name on merge'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'unmap e-mail address from Active
Directory logon name on merge'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'discard unwanted renames'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'FullNameMap' equal "true") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "rename") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="SA">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914622#68" type="string">Amstreet</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8"/>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'Transform NMAS attribute to password elements'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Convert adds of the
nspmDistributionPassword attribute to password elements'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "add") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-op-attr 'nspmDistributionPassword' available) = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Block modifies for failed password
publish operations if reset password is false'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'reset-external-password-on-failure' equal "false") =
FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Convert modifies of a
nspmDistributionPassword attribute to a modify password operation'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "modify") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Block empty modify operations'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "modify") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="SA">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914622#68" type="string">Amstreet</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8"/>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: Password(Sub)-Default Password Policy.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'On User add, provide default
password of Surname if no password exists'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "add") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name equal "User") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-password not-available) = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="SA">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914622#68" type="string">Amstreet</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8"/>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'Subscribe to password changes'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Block subscribing to passwords when
objects are added'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'enable-password-subscribe' equal "false") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Block subscribing to password
modifications'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'enable-password-subscribe' equal "false") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="SA">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914622#68" type="string">Amstreet</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8"/>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'Payloads for subscribe to password changes'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Add operation-data element to
password subscribe operations'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "add") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-password available) = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-xpath not-true "operation-data") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "modify-password") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Add payload data to a reset
password from a failed password publish operation'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "modify-password") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Add payload data to password
subscribe operations'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "add") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-password available) = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'Add payload data to password subscribe operations'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-append-xml-element("password-subscribe-status","operation-data").
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-append-xml-element("association","operation-data/password-subscribe-status").
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-append-xml-text("operation-data/password-subscribe-status/association",token-association()).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-association())
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-association()
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="CN">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="Facsimile Telephone Number">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="L">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Login Allowed Time Map">
<value timestamp="1141914622#42"
type="octet">////////////////////////////////////////////////////////</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="Physical Delivery Office Name">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="Postal Code">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="S">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="SA">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914622#68" type="string">Amstreet</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Telephone Number">
<value timestamp="1141914622#70" type="teleNumber">123456</value>
</add-attr>
<add-attr attr-name="Full Name">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Filtering out notification-only attributes.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Fixing
up association references.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
schema mapping policies to output.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'CN' to 'cn'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Facsimile Telephone Number' to 'facsimileTelephoneNumber'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'L' to 'physicalDeliveryOfficeName'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Login Allowed Time Map' to 'logonHours'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Login Disabled' to 'dirxml-uACAccountDisable'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Physical Delivery Office Name' to 'l'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Postal Code' to 'postalCode'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'S' to 'st'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'SA' to 'streetAddress'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Surname' to 'sn'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Telephone Number' to 'telephoneNumber'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Full Name' to 'displayName'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'Given Name' to 'givenName'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
attr-name 'DirXML-ADAliasName' to 'sAMAccountName'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Mapping
class-name 'User' to 'user'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
output transformation policies.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'Convert selected attributes to a form most commonly used in Active
Directory.'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'Street Address: Convert LF to CR-LF'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value")))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-local-variable("current-value")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "Amstreet".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "Amstreet".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "Amstreet".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "Amstreet".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'logonHours: Convert to Active
Directory form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'logonHours: Convert to Active Directory form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-xpath("jadutil:translateTimeMap2ADLenient($current-value)"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")
Thursday, Mar 9, 2006
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "////////////////////////////".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "////////////////////////////".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'accountExpires: Convert to Active
Directory form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'accountExpires: Convert to Active Directory form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'lockoutTime: Convert to Active
Directory form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'lockoutTime: Convert to Active Directory form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Add: User - convert multi-valued
Telephone to single value'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "add") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-class-name equal "User") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-op-attr 'telephoneNumber' available) = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'Add: User - convert multi-valued Telephone to single value'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-local-variable("phone-number",token-xpath("./add-attr[@attr-name='telephoneNumber']/value[1]")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-xpath("./add-attr[@attr-name='telephoneNumber']/value[1]"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-xpath("./add-attr[@attr-name='telephoneNumber']/value[1]")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "123456".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "123456".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-strip-op-attr("telephoneNumber").
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-set-dest-attr-value("telephoneNumber",token-local-variable("phone-number")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
arg-string(token-local-variable("phone-number"))
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
token-local-variable("phone-number")
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Token
Value: "123456".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Arg
Value: "123456".
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'update Active Directory logon name'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-xpath true "self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="cn">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="facsimileTelephoneNumber">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="physicalDeliveryOfficeName">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="logonHours">
<value type="octet">////////////////////////////</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="l">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="postalCode">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="st">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="streetAddress">
<value>Amstreet</value>
</add-attr>
<add-attr attr-name="sn">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="displayName">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<add-attr attr-name="telephoneNumber">
<value type="string">123456</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'Email notifications for failed password publications'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to add #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Send e-mail for a failed publish
password operation'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "status") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="cn">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="facsimileTelephoneNumber">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="physicalDeliveryOfficeName">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="logonHours">
<value type="octet">////////////////////////////</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="l">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="postalCode">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="st">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="streetAddress">
<value>Amstreet</value>
</add-attr>
<add-attr attr-name="sn">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="displayName">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<add-attr attr-name="telephoneNumber">
<value type="string">123456</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Submitting document to subscriber shim:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="cn">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="facsimileTelephoneNumber">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="physicalDeliveryOfficeName">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="logonHours">
<value type="octet">////////////////////////////</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="l">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="postalCode">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="st">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="streetAddress">
<value>Amstreet</value>
</add-attr>
<add-attr attr-name="sn">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="displayName">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<add-attr attr-name="telephoneNumber">
<value type="string">123456</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=su\#8">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Stripping operation data from input document
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Remote
Interface Driver: Sending...
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=su\#8,cn=users,dc=comp,dc=nl"
event-id="HEAD#20060309143022#2#77" qualified-src-dn="O=comp\CN=su#8"
src-dn="\comp\comp\su#8" src-entry-id="35353">
<add-attr attr-name="cn">
<value naming="true" timestamp="1141914622#21" type="string">su#8</value>
</add-attr>
<add-attr attr-name="facsimileTelephoneNumber">
<value timestamp="1141914622#37" type="structured">
<component name="faxNumber">123456</component>
<component name="faxBitCount">0</component>
<component name="faxParameters"/>
</value>
</add-attr>
<add-attr attr-name="physicalDeliveryOfficeName">
<value timestamp="1141914622#41" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="logonHours">
<value type="octet">////////////////////////////</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value timestamp="1141914622#43" type="state">false</value>
</add-attr>
<add-attr attr-name="l">
<value timestamp="1141914622#60" type="string">Amsterdam</value>
</add-attr>
<add-attr attr-name="postalCode">
<value timestamp="1141914622#61" type="string">1234 AM</value>
</add-attr>
<add-attr attr-name="st">
<value timestamp="1141914622#67" type="string">nh</value>
</add-attr>
<add-attr attr-name="streetAddress">
<value>Amstreet</value>
</add-attr>
<add-attr attr-name="sn">
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: <value
timestamp="1141914989#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="displayName">
<value timestamp="1141914989#8" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1141916009#2" type="string">wba su account</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">su\#8</value>
</add-attr>
<add-attr attr-name="userPrincipalName">
<value type="string">su\#8@comp.nl</value>
</add-attr>
<add-attr attr-name="telephoneNumber">
<value type="string">123456</value>
</add-attr>
<password><!-- content suppressed --></password>
</add>
</input>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Remote
Interface Driver: Document sent.
15:53:29 67CE84C0 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Received.
15:53:29 67CE84C0 00000000 FFFFFFFF -1 Drvrs: Active Directory :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\comp\comp\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="HEAD#20060309143022#2#77" level="error"
type="driver-general">
<ldap-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">
<client-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">Other</client-err>
<server-err>00000523: SysErr: DSID-031A0FB6, problem 22 (Invalid argument),
data 0
</server-err>
<server-err-ex win32-rc="1315"/>
</ldap-err>
</status>
</output>
</nds>
15:53:29 67CE84C0 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Received document for subscriber channel
15:53:29 67CE84C0 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Waiting for receive...
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Restoring operation data to output document
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
SubscriptionShim.execute() returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\comp\comp\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="HEAD#20060309143022#2#77" level="error"
type="driver-general">
<ldap-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">
<client-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">Other</client-err>
<server-err>00000523: SysErr: DSID-031A0FB6, problem 22 (Invalid argument),
data 0
</server-err>
<server-err-ex win32-rc="1315"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=su\#8">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
input transformation policies.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'Convert selected attributes to a form most commonly used in the
Identity Vault.'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to status #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'streetAddress: Convert CR-LF to LF'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'logonHours: Convert to Login
Allowed Time Map form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'logonHours: Convert to Login Allowed Time Map form'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'accountExpires: Convert to Identity
Vault time format'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'accountExpires: Convert to Identity Vault time format'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'lockoutTime: Convert to Identity
Vault time format'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
selected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
rule 'lockoutTime: Convert to Identity Vault time format'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\comp\comp\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="HEAD#20060309143022#2#77" level="error"
type="driver-general">
<ldap-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">
<client-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">Other</client-err>
<server-err>00000523: SysErr: DSID-031A0FB6, problem 22 (Invalid argument),
data 0
</server-err>
<server-err-ex win32-rc="1315"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=su\#8">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
policy: 'Email notifications for failed password subscriptions'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Applying
to status #1.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Send e-mail on a failure when
subscribing to passwords'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "status") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-xpath true "self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']") =
FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
Evaluating selection criteria for rule 'Send e-mail on failure to reset
connected system password using the Identity Manager data store password'.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-operation equal "status") = TRUE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
(if-xpath true "self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Rule
rejected.
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST: Policy
returned:
15:53:29 61084040 00000000 FFFFFFFF -1 Drvrs: Active Directory ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\comp\comp\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="HEAD#20060309143022#2#77" level="error"
type="driver-general">
<ldap-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">
<client-err ldap-rc="80" ldap-rc-name="LDAP_OTHER">Other</client-err>
<server-err>00000523: SysErr: DSID-031A0FB6, problem 22 (Invalid argument),
data 0
</server-err>
<server-err-ex win32-rc="1315"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=su\#8">
<password-subscribe-status>
<association/>
</password-subscribe-status>