I'm having some strange problems, when I add a user to a new created group
in AD or eDir, everything goes OK (it syncs in both directions), also for
adding users to groups that already existed in NDS(and now also exist in
AD) before implementing IDM3. But here comes the strange problem: When I
add a user to a group that already existed in AD (like Domain Admins), the
membership in NDS doesn't change and the other direction does not work
either?????????? Here is a DSTrace when adding user "wtest1" to group
"Enterprise Admins" in AD(if you want the DSTrace when adding a user to a
group in NDS, just tell me)

13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Received.
13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory :
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<modify-attr attr-name="member">
<remove-all-values/>
<add-value>
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="false"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="false"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="false"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="false"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="false"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Received document for publisher channel
13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Waiting for receive...
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Receiving DOM document from application.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<modify-attr attr-name="member">
<remove-all-values/>
<add-value>
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="false"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="false"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="false"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="false"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="false"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
input transformation policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Convert selected attributes to a form most commonly used in the
Identity Vault.'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to modify #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'streetAddress: Convert CR-LF to LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'logonHours: Convert to Login
Allowed Time Map form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'logonHours: Convert to Login Allowed Time Map form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'accountExpires: Convert to Identity
Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'accountExpires: Convert to Identity Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'lockoutTime: Convert to Identity
Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'lockoutTime: Convert to Identity Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<modify-attr attr-name="member">
<remove-all-values/>
<add-value>
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="false"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="false"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="false"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="false"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="false"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Email notifications for failed password subscriptions'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to modify #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Send e-mail on a failure when
subscribing to passwords'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "status") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Send e-mail on failure to reset
connected system password using the Identity Manager data store password'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "status") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<modify-attr attr-name="member">
<remove-all-values/>
<add-value>
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="false"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="false"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="false"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="false"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="false"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
schema mapping policies to input.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
class-name 'group' to 'Group'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'member' to 'Member'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Resolving association references.
Thursday, Mar 23, 2006
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
event transformation policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: Event Transform.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to modify #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'setup for move validation'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "move") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'setup for rename validation'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "move") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'move or rename validation'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-local-variable 'cached-object-value' match ".*") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'move or rename cached context update'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-local-variable 'cached-object-value' match ".*") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="Group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<modify-attr attr-name="Member">
<remove-all-values/>
<add-value>
<value naming="false" type="dn">\perk\perk\su01</value>
<value naming="false" type="dn">\perk\perk\wtest1</value>
<value naming="false" type="dn">\perk\perk\su08</value>
<value naming="false" type="dn">\perk\perk\su07</value>
<value naming="false" type="dn">\perk\perk\administrator</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: No
associated objects.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
publisher filter.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Publisher processing modify for CN=Enterprise Admins,CN=Users,dc=perk,DC=nl.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Converting <modify> to <add>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Reading
relevant attributes from af08dbce79f0f3468e02eb593efdc9d9.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="Group" scope="entry">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<read-attr attr-name="CN"/>
<read-attr attr-name="Description"/>
<read-attr attr-name="Full Name"/>
<read-attr attr-name="L"/>
<read-attr attr-name="Member"/>
<read-attr attr-name="Owner"/>
</query>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Fixing
up association references.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
schema mapping policies to output.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'CN' to 'cn'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'Description' to 'description'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'Full Name' to 'displayName'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'L' to 'physicalDeliveryOfficeName'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'Member' to 'member'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'Owner' to 'managedBy'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
class-name 'Group' to 'group'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
output transformation policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Convert selected attributes to a form most commonly used in Active
Directory.'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to query #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'Street Address: Convert LF to CR-LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'logonHours: Convert to Active
Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'logonHours: Convert to Active Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'accountExpires: Convert to Active
Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'accountExpires: Convert to Active Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'lockoutTime: Convert to Active
Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'lockoutTime: Convert to Active Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Add: User - convert multi-valued
Telephone to single value'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'update Active Directory logon name'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-xpath true "self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="group" event-id="0" scope="entry">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<read-attr attr-name="cn"/>
<read-attr attr-name="description"/>
<read-attr attr-name="displayName"/>
<read-attr attr-name="physicalDeliveryOfficeName"/>
<read-attr attr-name="member"/>
<read-attr attr-name="managedBy"/>
</query>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Email notifications for failed password publications'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to query #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Send e-mail for a failed publish
password operation'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "status") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="group" event-id="0" scope="entry">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<read-attr attr-name="cn"/>
<read-attr attr-name="description"/>
<read-attr attr-name="displayName"/>
<read-attr attr-name="physicalDeliveryOfficeName"/>
<read-attr attr-name="member"/>
<read-attr attr-name="managedBy"/>
</query>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Querying
publisher shim.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="group" event-id="0" scope="entry">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<read-attr attr-name="cn"/>
<read-attr attr-name="description"/>
<read-attr attr-name="displayName"/>
<read-attr attr-name="physicalDeliveryOfficeName"/>
<read-attr attr-name="member"/>
<read-attr attr-name="managedBy"/>
</query>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Remote
Interface Publisher: Querying remote Publisher...
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Remote
Interface Driver: Sending...
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="group" event-id="0" scope="entry">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<read-attr attr-name="cn"/>
<read-attr attr-name="description"/>
<read-attr attr-name="displayName"/>
<read-attr attr-name="physicalDeliveryOfficeName"/>
<read-attr attr-name="member"/>
<read-attr attr-name="managedBy"/>
</query>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Remote
Interface Driver: Document sent.
13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Received.
13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\perk\perk\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<attr attr-name="cn">
<value naming="true" type="string">Enterprise Admins</value>
</attr>
<attr attr-name="description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</attr>
<attr attr-name="member">
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="true"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="true"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="true"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="true"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="true"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</attr>
</instance>
</output>
</nds>
13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Received document for publisher channel
13:38:58 77528440 00000000 FFFFFFFF -1 Drvrs: Active Directory : Remote
Interface Driver: Waiting for receive...
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Publisher shim returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\perk\perk\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<attr attr-name="cn">
<value naming="true" type="string">Enterprise Admins</value>
</attr>
<attr attr-name="description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</attr>
<attr attr-name="member">
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="true"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="true"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="true"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="true"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="true"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</attr>
</instance>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
input transformation policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Convert selected attributes to a form most commonly used in the
Identity Vault.'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to instance #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'streetAddress: Convert CR-LF to LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'logonHours: Convert to Login
Allowed Time Map form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'logonHours: Convert to Login Allowed Time Map form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'accountExpires: Convert to Identity
Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'accountExpires: Convert to Identity Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'lockoutTime: Convert to Identity
Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'lockoutTime: Convert to Identity Vault time format'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\perk\perk\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<attr attr-name="cn">
<value naming="true" type="string">Enterprise Admins</value>
</attr>
<attr attr-name="description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</attr>
<attr attr-name="member">
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="true"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="true"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="true"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="true"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="true"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</attr>
</instance>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Email notifications for failed password subscriptions'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to instance #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Send e-mail on a failure when
subscribing to passwords'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "status") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Send e-mail on failure to reset
connected system password using the Identity Manager data store password'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "status") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\perk\perk\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<attr attr-name="cn">
<value naming="true" type="string">Enterprise Admins</value>
</attr>
<attr attr-name="description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</attr>
<attr attr-name="member">
<value association-ref="9e4fef1461ef09428b9726dad2c02089" naming="true"
type="dn">CN=su01,CN=Users,dc=perk,DC=nl</value>
<value association-ref="c1a9b0b6b2f9f742afeb9e69f9ea7df5" naming="true"
type="dn">CN=winuser1 test1,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f7e93db10637964ba69247b42c89857c" naming="true"
type="dn">CN=su08,CN=Users,dc=perk,DC=nl</value>
<value association-ref="f34fb43938481c4e9ca74da51b71db60" naming="true"
type="dn">CN=su07,CN=Users,dc=perk,DC=nl</value>
<value association-ref="8e0540f74529594999963e4b5ae7b7ed" naming="true"
type="dn">CN=administrator,CN=Users,dc=perk,DC=nl</value>
</attr>
</instance>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
schema mapping policies to input.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
class-name 'group' to 'Group'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'cn' to 'CN'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'description' to 'Description'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Mapping
attr-name 'member' to 'Member'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Resolving association references.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Read result:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20051114_120000"
instance="\perk\perk\ADNDSDriverSet\Active Directory"
version="3.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="Group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</attr>
<attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</attr>
<attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</attr>
</instance>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Synthetic add:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
object matching policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Find a matching unassociated object in the Identity Vault.'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'remember relative position in
hierarchy'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-src-dn in-subtree "cn=users,dc=perk,dc=nl") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'remember relative position in hierarchy'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-set-op-property("unmatched-src-dn",token-unmatched-src-dn(convert="true")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
arg-string(token-unmatched-src-dn(convert="true"))
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-unmatched-src-dn(convert="true")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Token
Value: "Enterprise Admins".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Arg
Value: "Enterprise Admins".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'veto out-of-scope events'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-op-property 'unmatched-src-dn' not-available) = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'match users based on NT logon name'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "User") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'match users based on full name'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "User") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'match everything else'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name not-equal "User") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'match everything else'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-find-matching-object(scope="entry",arg-dn("perk"+"\"+token-unmatched-src-dn(convert="true"))).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
arg-dn("perk"+"\"+token-unmatched-src-dn(convert="true"))
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-text("perk")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-text("\")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-unmatched-src-dn(convert="true")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Token
Value: "nl\perk\Users\Enterprise Admins".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Arg
Value: "perk\nl\perk\Users\Enterprise Admins".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Query
from policy
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="Group" dest-dn="perk\nl\perk\Users\Enterprise Admins"
scope="entry">
<search-class class-name="Group"/>
<read-attr/>
</query>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Pumping
XDS to eDirectory.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Performing operation query for perk\nl\perk\Users\Enterprise Admins.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Query
from policy result
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"></status>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: No
matches found.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<operation-data unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: No match
found.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
object creation policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: Creation.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'add attributes for all objects'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'add attributes for all objects'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-add-dest-attr-value("Object Class","DirXML-ApplicationAttrs").
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
arg-string("DirXML-ApplicationAttrs")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-text("DirXML-ApplicationAttrs")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Arg
Value: "DirXML-ApplicationAttrs".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-set-dest-attr-value("DirXML-ADContext",token-src-dn()).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
arg-string(token-src-dn())
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-src-dn()
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Token
Value: "CN=Enterprise Admins,CN=Users,dc=perk,DC=nl".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Arg
Value: "CN=Enterprise Admins,CN=Users,dc=perk,DC=nl".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'add attributes for user objects'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "User") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'set user default password'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "User") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'update Active Directory logon name'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'UpnMap' equal "ad-mail-auth") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" event-id="0" src-dn="CN=Enterprise
Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<operation-data unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
object placement policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: Placement.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'placement for all objects'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'placement for all objects'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-set-op-dest-dn(arg-dn("perk"+"\"+token-op-property("unmatched-src-dn"))).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
arg-dn("perk"+"\"+token-op-property("unmatched-src-dn"))
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-text("perk")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-text("\")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
token-op-property("unmatched-src-dn")
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Token
Value: "Enterprise Admins".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Arg
Value: "perk\Enterprise Admins".
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'optional logon name mapping'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "User") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<operation-data unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Found
non-class attribute DirXML-ADContext.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
command transformation policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'A set of rules that implement the user name mapping options'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'consider user objects when name
mapping is enabled'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name not-equal "User") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'consider user objects when name mapping is enabled'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-break().
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<operation-data unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: Command Transform.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'set cached context value on merge'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "modify") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Set Equivalent To Me when adding
object to a group'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "Group") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-op-attr 'Member' available) = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'Set Equivalent To Me when adding object to a group'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-clone-op-attr("Member","Equivalent To Me").
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Remove Equivalent To Me when
removing object from a group'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "Group") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-op-attr 'Member' changing-from ".+") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'remove managed attributes when
object disassociated'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "remove-association") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<add-attr attr-name="Equivalent To Me">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: <operation-data
unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
XSLT policy.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<add-attr attr-name="Equivalent To Me">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: <operation-data
unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: Password(Pub)-Default Password Policy.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'On User add, provide default
password of @Dirxml1 if no password exists'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-class-name equal "User") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
Thursday, Mar 23, 2006
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<add-attr attr-name="Equivalent To Me">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: <operation-data
unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Publish Passwords'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Block publishing passwords to
Identity Manager data store when adding a object'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'enable-password-publish' equal "false") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Block sending modify-password
changes to the Identity Manager data store'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'enable-password-publish' equal "false") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<add-attr attr-name="Equivalent To Me">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: <operation-data
unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Publish passwords to NMAS distribution password'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Add nspmDistributionAttribute
attribute to add operation'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'publish-password-to-dp' equal "true") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-password available) = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Change modify-password operations
to a modify'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'publish-password-to-dp' equal "true") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "modify-password") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<add-attr attr-name="Equivalent To Me">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: <operation-data
unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Publish passwords to NDS password.'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Block publishing passwords to NDS
password'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'publish-password-to-nds' equal "false") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'Block publishing passwords to NDS password'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-strip-xpath("password").
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Block sending modify-password
changes to the NDS password'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'publish-password-to-nds' equal "false") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "modify-password") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<add-attr attr-name="Equivalent To Me">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: <operation-data
unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Publish password payloads'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to add #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Add operation-data element to
password operations'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-password available) = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-xpath true "add-attr[@attr-name='nspmDistributionPassword']") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "modify-password") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "modify") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Add payload data to password
operations'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-password available) = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-xpath true "add-attr[@attr-name='nspmDistributionPassword']") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "modify-password") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "modify") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="2.2">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="Group" dest-dn="perk\Enterprise Admins" event-id="0"
src-dn="CN=Enterprise Admins,CN=Users,dc=perk,DC=nl">
<association>af08dbce79f0f3468e02eb593efdc9d9</association>
<add-attr attr-name="CN">
<value naming="true" type="string">Enterprise Admins</value>
</add-attr>
<add-attr attr-name="Description">
<value naming="true" type="string">Designated administrators of the
enterprise</value>
</add-attr>
<add-attr attr-name="Member">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
<add-attr attr-name="Object Class">
<value type="string">DirXML-ApplicationAttrs</value>
</add-attr>
<add-attr attr-name="DirXML-ADContext">
<value type="string">CN=Enterprise Admins,CN=Users,dc=perk,DC=nl</value>
</add-attr>
<add-attr attr-name="Equivalent To Me">
<value naming="true" type="dn">\perk\perk\su01</value>
<value naming="true" type="dn">\perk\perk\wtest1</value>
<value naming="true" type="dn">\perk\perk\su08</value>
<value naming="true" type="dn">\perk\perk\su07</value>
<value naming="true" type="dn">\perk\perk\administrator</value>
</add-attr>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: <operation-data
unmatched-src-dn="Enterprise Admins"/>
</add>
</input>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Filtering out notification-only attributes.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Pumping
XDS to eDirectory.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Performing operation add for perk\Enterprise Admins.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Adding
entry perk\Enterprise Admins.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Creating
RDN Enterprise Admins in context perk.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
DirXML Log Event -------------------
Driver: \perk\perk\ADNDSDriverSet\Active Directory
Channel: Publisher
Object: CN=Enterprise Admins,CN=Users,dc=perk,DC=nl (perk\Enterprise Admins)
Status: Error
Message: Code(-9010) An exception occurred: novell.jclient.JCException:
createEntry -606 ERR_ENTRY_ALREADY_EXISTS
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Fixing
up association references.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
schema mapping policies to output.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
output transformation policies.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Convert selected attributes to a form most commonly used in Active
Directory.'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to status #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'Street Address: Convert LF to CR-LF'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'logonHours: Convert to Active
Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'logonHours: Convert to Active Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'accountExpires: Convert to Active
Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'accountExpires: Convert to Active Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'lockoutTime: Convert to Active
Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
selected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
rule 'lockoutTime: Convert to Active Directory form'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Add: User - convert multi-valued
Telephone to single value'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "add") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'update Active Directory logon name'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-xpath true "self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="error">Code(-9010) An exception occurred:
novell.jclient.JCException: createEntry -606
ERR_ENTRY_ALREADY_EXISTS<operation-data unmatched-src-dn="Enterprise Admins"/>
<application>DirXML</application>
<module>Active Directory</module>
<object-dn>CN=Enterprise Admins,CN=Users,dc=perk,DC=nl (perk\Enterprise
Admins)</object-dn>
<component>Publisher</component>
</status>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
policy: 'Email notifications for failed password publications'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Applying
to status #1.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
Evaluating selection criteria for rule 'Send e-mail for a failed publish
password operation'.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-global-variable 'notify-user-on-password-dist-failure' equal "true") =
TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-operation equal "status") = TRUE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
(if-xpath true "self::status[@level !=
'success']/operation-data/password-publish-status") = FALSE.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Rule
rejected.
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Policy
returned:
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="error">Code(-9010) An exception occurred:
novell.jclient.JCException: createEntry -606
ERR_ENTRY_ALREADY_EXISTS<operation-data unmatched-src-dn="Enterprise Admins"/>
<application>DirXML</application>
<module>Active Directory</module>
<object-dn>CN=Enterprise Admins,CN=Users,dc=perk,DC=nl (perk\Enterprise
Admins)</object-dn>
<component>Publisher</component>
</status>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="error">Code(-9010) An exception occurred:
novell.jclient.JCException: createEntry -606
ERR_ENTRY_ALREADY_EXISTS<operation-data unmatched-src-dn="Enterprise Admins"/>
<application>DirXML</application>
<module>Active Directory</module>
<object-dn>CN=Enterprise Admins,CN=Users,dc=perk,DC=nl (perk\Enterprise
Admins)</object-dn>
<component>Publisher</component>
</status>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Remote
Interface Driver: Sending...
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT:
<nds dtdversion="3.0" ndsversion="8.x">
<source>
<product version="3.0.0.20051118 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="error">Code(-9010) An exception occurred:
novell.jclient.JCException: createEntry -606
ERR_ENTRY_ALREADY_EXISTS<operation-data unmatched-src-dn="Enterprise Admins"/>
<application>DirXML</application>
<module>Active Directory</module>
<object-dn>CN=Enterprise Admins,CN=Users,dc=perk,DC=nl (perk\Enterprise
Admins)</object-dn>
<component>Publisher</component>
</status>
</output>
</nds>
13:38:58 76537060 00000000 FFFFFFFF -1 Drvrs: Active Directory PT: Remote
Interface Driver: Document sent.