I don't see any loop per se, other than that the change made on the
subscriber channel come back on the publisher channel, which is normal
behavior for the AD driver. It does look like your policy "policy
allows events through only for users who are contained within the
subtree, are not disabled", is only emitting a status message rather
than vetoing the event and therefore the event goes through even though
it is out of scope.

--

Father Ramon


Bob Owen wrote:
> Hello, WOuld someone be able to look at my trace and see where I am going
> wrong! I am a novice at IDM and it is driving me ...you know...crazy.
> It is suppose to stop if not in scope but it seems to be in some loop.
> Thanks, Bob
>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Start transaction.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing events for
> transaction.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#1">
> <modify-attr attr-name="Login Disabled">
> <add-value>
> <value timestamp="1150922364#1" type="state">true</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying event
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'policy
> allows events through only for users who are contained within the
> subtree, are not disabled'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Scope Filtering (Single OU ONLY!)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn not-in-
> container "NISD\SCHOOLS\Business_Careers") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn in-
> container "NISD\SCHOOLS\Business_Careers\STU") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Veto Labs and Student OU's (Single OU ONLY!)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Query from policy
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <query class-name="User" dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson
> \e011833" dest-entry-id="68948" scope="entry">
> <read-attr attr-name="businessCategory"/>
> </query>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Pumping XDS to
> eDirectory.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Performing
> operation query for \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Query from policy
> result
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <instance class-name="User" qualified-src-dn="O=NISD\OU=SCHOOLS
> \OU=Stinson\CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833"
> src-entry-id="68948"/>
> <status level="success"></status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-attr
> 'businessCategory' equal "STUDENT") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn equal
> "student") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn equal
> "teacher") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Only synchronize users in Business Careers'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn not-in-
> container "NISD\SCHOOLS\Business_Careers") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Only
> synchronize users in Business Careers'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-status
> (level="warning","Changes Ignored: Out of scope").
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string
> ("Changes Ignored: Out of scope")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-text
> ("Changes Ignored: Out of scope")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "Changes Ignored: Out of scope".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> DirXML Log Event -------------------
> Driver: \NISD_TREE\NISD\SERVICES\ADDriver\ActiveDirectory
> Channel: Subscriber
> Status: Warning
> Message: Changes Ignored: Out of scope
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#1">
> <modify-attr attr-name="Login Disabled">
> <add-value>
> <value timestamp="1150922364#1" type="state">true</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Subscriber processing
> modify for \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: No existing association,
> converting <modify> to <add>.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Reading relevant
> attributes from \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <query class-name="User" dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson
> \e011833" dest-entry-id="68948" scope="entry">
> <read-attr attr-name="Description"/>
> <read-attr attr-name="Facsimile Telephone Number"/>
> <read-attr attr-name="Full Name"/>
> <read-attr attr-name="Given Name"/>
> <read-attr attr-name="Initials"/>
> <read-attr attr-name="Internet EMail Address"/>
> <read-attr attr-name="L"/>
> <read-attr attr-name="Login Allowed Time Map"/>
> <read-attr attr-name="Login Disabled"/>
> <read-attr attr-name="nspmDistributionPassword"/>
> <read-attr attr-name="Password Expiration Time"/>
> <read-attr attr-name="Physical Delivery Office Name"/>
> <read-attr attr-name="Postal Code"/>
> <read-attr attr-name="Postal Office Box"/>
> <read-attr attr-name="S"/>
> <read-attr attr-name="SA"/>
> <read-attr attr-name="Surname"/>
> <read-attr attr-name="Telephone Number"/>
> <read-attr attr-name="Title"/>
> <read-attr attr-name="uniqueID"/>
> </query>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Pumping XDS to
> eDirectory.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Performing operation
> query for \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Read result:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <instance class-name="User" qualified-src-dn="O=NISD\OU=SCHOOLS
> \OU=Stinson\CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833"
> src-entry-id="68948">
> <attr attr-name="Description">
> <value timestamp="1150922364#6" type="string">#506223</value>
> </attr>
> <attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </attr>
> <attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </attr>
> <attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </attr>
> <attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </attr>
> <attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </attr>
> <attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </attr>
> <attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </attr>
> <attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </attr>
> <attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </attr>
> <attr attr-name="Internet EMail Address">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </attr>
> </instance>
> DVRS: [2006/06/21 15:39:24] <status level="success"></status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Synthetic add:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#1"
> qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </add-attr>
> </add>
> </input>
> DVRS: [2006/06/21 15:39:24] </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying object matching
> policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Find
> matching object in Active Directory'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#1"
> qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </add-attr>
> </add>
> </input>
> DVRS: [2006/06/21 15:39:24] </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: No match found.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying object creation
> policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> Creation.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Create User objects (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Create
> User objects (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-veto-if-
> op-attr-not-available("Full Name").
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-set-
> dest-attr-value("DirXML-ADAliasName",token-substring(length="20",token-
> replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e
> \xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string(token-
> substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e
> \x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name
> ())))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-substring
> (length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-
> \x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e
> \x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name
> ()))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e
> \xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e
> \xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> src-name()
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token
> Value: "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg
> Value: "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token
> Value: "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-set-src-
> attr-value("DirXML-ADAliasName",token-substring(length="20",token-
> replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e
> \xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string(token-
> substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e
> \x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name
> ())))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-substring
> (length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-
> \x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e
> \x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name
> ()))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e
> \xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e
> \xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> src-name()
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token
> Value: "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg
> Value: "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token
> Value: "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Identity Vault accounts are enabled if Login Disabled
> does not exist (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-op-attr 'Login
> Disabled' not-available) = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Direct command from
> policy
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson
> \e011833" dest-entry-id="68948" event-id="ALTERNATE-DS2#20060621203924#4#
> 1">
> <modify-attr attr-name="DirXML-ADAliasName">
> <remove-all-values/>
> <add-value>
> <value type="string">e011833</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Pumping XDS to
> eDirectory.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Performing operation
> modify for \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Modifying entry
> \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing returned
> document.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing operation
> <status> for .
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> DirXML Log Event -------------------
> Driver: \NISD_TREE\NISD\SERVICES\ADDriver\ActiveDirectory
> Channel: Subscriber
> Object: \NISD_TREE\NISD\SCHOOLS\Stinson\e011833
> Status: Error
> Message: Code(-9010) An exception occurred:
> novell.jclient.JCException: modifyEntry -608 ERR_ILLEGAL_ATTRIBUTE
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Direct command from
> policy result
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status event-id="ALTERNATE-DS2#20060621203924#4#1" level="error">
> Code(-9010) An exception occurred: novell.jclient.JCException:
> modifyEntry -608 ERR_ILLEGAL_ATTRIBUTE<application>DirXML</application>
> <module>ActiveDirectory</module>
> <object-dn>\NISD_TREE\NISD\SCHOOLS\Stinson\e011833</object-dn>
> <component>Subscriber</component>
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#1"
> qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </add-attr>
> DVRS: [2006/06/21 15:39:24] <add-attr attr-name="DirXML-
> ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying object placement
> policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> Placement.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Parse User Source DN for Placement (Single OU ONLY!)
> (SUB) - 1'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Parse
> User Source DN for Placement (Single OU ONLY!) (SUB) - 1'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-set-op-
> dest-dn(arg-dn("CN="+token-src-name()
> +","+"ou=users,ou=staff,ou=BusinessCareers,ou=High ,ou=Schools,ou=NISD"+",
> "+"dc=northside,dc=isd,dc=tenet,dc=edu")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-dn
> ("CN="+token-src-name()
> +","+"ou=users,ou=staff,ou=BusinessCareers,ou=High ,ou=Schools,ou=NISD"+",
> "+"dc=northside,dc=isd,dc=tenet,dc=edu")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-text
> ("CN=")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-src-name
> ()
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "e011833".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-text(",")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-text
> ("ou=users,ou=staff,ou=BusinessCareers,ou=High,ou= Schools,ou=NISD")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-text(",")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-text
> ("dc=northside,dc=isd,dc=tenet,dc=edu")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "CN=e011833,ou=users,ou=staff,ou=BusinessCareers,o u=High,ou=Schools,ou=NI
> SD,dc=northside,dc=isd,dc=tenet,dc=edu".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> DVRS: [2006/06/21 15:39:24] <value timestamp="1131979681#17"
> type="string">e011833@nisd.net</value>
> </add-attr>
> <add-attr attr-name="DirXML-ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Submitting add to
> subscriber shim.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying command
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: Command.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> DVRS: [2006/06/21 15:39:24] <value timestamp="1131979681#17"
> type="string">e011833@nisd.net</value>
> </add-attr>
> <add-attr attr-name="DirXML-ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'A set
> of rules that are executed when any one of the user name mapping options
> are selected.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'consider user objects when name mapping is enabled
> (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name not-
> equal "User") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'FullNameMap' equal "false") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'generate full name on merge (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'FullNameMap' equal "true") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-xpath true ".
> [@from-merge='true']") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'escape source object name (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "rename") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'map rename to NT logon name (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'LogonNameMap' equal "true") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "rename") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> DVRS: [2006/06/21 15:39:24] <value timestamp="1131979681#17"
> type="string">e011833@nisd.net</value>
> </add-attr>
> <add-attr attr-name="DirXML-ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> 'Transform NMAS attribute to password elements'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Convert adds of the nspmDistributionPassword attribute
> to password elements'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-op-attr
> 'nspmDistributionPassword' available) = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block modifies for failed password publish operations
> if reset password is false'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'reset-external-password-on-failure' equal "false") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Convert modifies of a nspmDistributionPassword
> attribute to a modify password operation'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block empty modify operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> DVRS: [2006/06/21 15:39:24] <value timestamp="1131979681#17"
> type="string">e011833@nisd.net</value>
> </add-attr>
> <add-attr attr-name="DirXML-ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: Password
> (Sub)-Default Password Policy.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'On User add, provide default password of Surname if no
> password exists'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-password not-
> available) = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'On
> User add, provide default password of Surname if no password exists'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-set-
> dest-password(token-op-attr("Surname")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string(token-
> op-attr("Surname"))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-op-attr
> ("Surname")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "-- suppressed --".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value: "--
> suppressed --".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> DVRS: [2006/06/21 15:39:24] <value timestamp="1131979681#17"
> type="string">e011833@nisd.net</value>
> </add-attr>
> <add-attr attr-name="DirXML-ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> <password><!-- content suppressed --></password>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> 'Subscribe to password changes'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block subscribing to passwords when objects are
> added'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'enable-password-subscribe' equal "false") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block subscribing to password modifications'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'enable-password-subscribe' equal "false") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> DVRS: [2006/06/21 15:39:24] <value timestamp="1131979681#17"
> type="string">e011833@nisd.net</value>
> </add-attr>
> <add-attr attr-name="DirXML-ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> <password><!-- content suppressed --></password>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> 'Payloads for subscribe to password changes'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add operation-data element to password subscribe
> operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-password
> available) = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-xpath not-true
> "operation-data") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Add
> operation-data element to password subscribe operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-append-
> xml-element("operation-data",".").
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add payload data to a reset password from a failed
> password publish operation'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify-password") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add payload data to password subscribe operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-password
> available) = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Add
> payload data to password subscribe operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-append-
> xml-element("password-subscribe-status","operation-data").
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-append-
> xml-element("association","operation-data/password-subscribe-status").
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-append-
> xml-text("operation-data/password-subscribe-status/association",token-
> association()).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string(token-
> association())
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-
> association()
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value: "".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="User" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="L">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="Login Disabled">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="Password Expiration Time">
> <value timestamp="1143813930#4" type="time">1154181930</value>
> </add-attr>
> <add-attr attr-name="Surname">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="Telephone Number">
> <value timestamp="1097184664#62" type="teleNumber">397-3600
> </value>
> </add-attr>
> <add-attr attr-name="Title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="Full Name">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="Given Name">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="uniqueID">
> <value timestamp="1131979681#9" type="string">STIN124</value>
> </add-attr>
> <add-attr attr-name="Internet EMail Address">
> DVRS: [2006/06/21 15:39:24] <value timestamp="1131979681#17"
> type="string">e011833@nisd.net</value>
> </add-attr>
> <add-attr attr-name="DirXML-ADAliasName">
> <value type="string">e011833</value>
> </add-attr>
> <password><!-- content suppressed --></password>
> <operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Filtering out
> notification-only attributes.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Filtered out <add-attr
> attr-name='uniqueID'>.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Fixing up association
> references.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying schema mapping
> policies to output.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name 'L'
> to 'physicalDeliveryOfficeName'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Login Disabled' to 'dirxml-uACAccountDisable'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Password Expiration Time' to 'accountExpires'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Surname' to 'sn'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Telephone Number' to 'telephoneNumber'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Title' to 'title'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name 'Full
> Name' to 'displayName'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Given Name' to 'givenName'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Internet EMail Address' to 'mail'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'DirXML-ADAliasName' to 'sAMAccountName'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping class-name
> 'User' to 'user'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying output
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Convert
> selected attributes to a form most commonly used in Active Directory.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Street Address: Convert LF to CR-LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Street
> Address: Convert LF to CR-LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r
> \n",token-local-variable("current-value"))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'logonHours: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'logonHours: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("logonHours",token-xpath
> ("jadutil:translateTimeMap2ADLenient($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'accountExpires: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'accountExpires: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("accountExpires",token-xpath
> ("jadutil:translateEpoch2FileTime($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string(token-
> xpath("jadutil:translateEpoch2FileTime($current-value)"))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-xpath
> ("jadutil:translateEpoch2FileTime($current-value)")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "127986555300000000".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "127986555300000000".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'lockoutTime: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'lockoutTime: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("lockoutTime",token-xpath
> ("jadutil:translateEpoch2FileTime($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add: User - convert multi-valued Telephone to single
> value'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-op-attr
> 'telephoneNumber' available) = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Add:
> User - convert multi-valued Telephone to single value'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-set-
> local-variable("phone-number",token-xpath("./add-attr[@attr-
> name='telephoneNumber']/value[1]")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string(token-
> xpath("./add-attr[@attr-name='telephoneNumber']/value[1]"))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-xpath
> ("./add-attr[@attr-name='telephoneNumber']/value[1]")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "397-3600".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "397-3600".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-strip-
> op-attr("telephoneNumber").
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-set-
> dest-attr-value("telephoneNumber",token-local-variable("phone-number")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string(token-
> local-variable("phone-number"))
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-local-
> variable("phone-number")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Token Value:
> "397-3600".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "397-3600".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'update Active Directory logon name'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-xpath true
> "self::status[@level = 'success']/operation-data/windows-2000-logon-
> name") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="user" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="physicalDeliveryOfficeName">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="dirxml-uACAccountDisable">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="accountExpires">
> <value type="octet">127986555300000000</value>
> </add-attr>
> <add-attr attr-name="sn">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="displayName">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="givenName">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="mail">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </add-attr>
> <add-attr attr-name="sAMAccountName">
> <value type="string">e011833</value>
> </add-attr>
> <add-attr attr-name="telephoneNumber">
> DVRS: [2006/06/21 15:39:24] <value type="string">397-3600</value>
> </add-attr>
> <password><!-- content suppressed --></password>
> <operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Email
> notifications for failed password publications'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="user" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="physicalDeliveryOfficeName">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="dirxml-uACAccountDisable">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="accountExpires">
> <value type="octet">127986555300000000</value>
> </add-attr>
> <add-attr attr-name="sn">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="displayName">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="givenName">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="mail">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </add-attr>
> <add-attr attr-name="sAMAccountName">
> <value type="string">e011833</value>
> </add-attr>
> <add-attr attr-name="telephoneNumber">
> DVRS: [2006/06/21 15:39:24] <value type="string">397-3600</value>
> </add-attr>
> <password><!-- content suppressed --></password>
> <operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Submitting document to
> subscriber shim:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="user" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="physicalDeliveryOfficeName">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="dirxml-uACAccountDisable">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="accountExpires">
> <value type="octet">127986555300000000</value>
> </add-attr>
> <add-attr attr-name="sn">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="displayName">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="givenName">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="mail">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </add-attr>
> <add-attr attr-name="sAMAccountName">
> <value type="string">e011833</value>
> </add-attr>
> <add-attr attr-name="telephoneNumber">
> DVRS: [2006/06/21 15:39:24] <value type="string">397-3600</value>
> </add-attr>
> <password><!-- content suppressed --></password>
> <operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Stripping operation data
> from input document
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Remote Interface Driver:
> Sending...
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <add class-name="user" dest-
> dn="CN=e011833,ou=users,ou=staff,ou=BusinessCareer s,ou=High,ou=Schools,ou
> =NISD,dc=northside,dc=isd,dc=tenet,dc=edu" event-id="ALTERNATE-DS2#
> 20060621203924#4#1" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson
> \CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-
> id="68948">
> <add-attr attr-name="physicalDeliveryOfficeName">
> <value timestamp="966521476#44" type="string">Stinson Middle
> School</value>
> </add-attr>
> <add-attr attr-name="dirxml-uACAccountDisable">
> <value timestamp="1150922364#1" type="state">true</value>
> </add-attr>
> <add-attr attr-name="accountExpires">
> <value type="octet">127986555300000000</value>
> </add-attr>
> <add-attr attr-name="sn">
> <value timestamp="966521476#15" type="string">Patmon</value>
> </add-attr>
> <add-attr attr-name="title">
> <value timestamp="966521508#3" type="string">Teacher</value>
> </add-attr>
> <add-attr attr-name="displayName">
> <value timestamp="1131979681#7" type="string">Don Patmon</value>
> </add-attr>
> <add-attr attr-name="givenName">
> <value timestamp="966521508#2" type="string">Don</value>
> </add-attr>
> <add-attr attr-name="mail">
> <value timestamp="1131979681#17" type="string">e011833@nisd.net
> </value>
> </add-attr>
> <add-attr attr-name="sAMAccountName">
> <value type="string">e011833</value>
> </add-attr>
> <add-attr attr-name="telephoneNumber">
> DVRS: [2006/06/21 15:39:24] <value type="string">397-3600</value>
> </add-attr>
> <password><!-- content suppressed --></password>
> </add>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Remote Interface Driver:
> Document sent.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Received.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory :
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <add-association dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833"
> dest-entry-id="68948" event-id="ALTERNATE-DS2#20060621203924#4#1">
> 53c19661d344f84c8c9c249defd18f0d</add-association>
> <status event-id="ALTERNATE-DS2#20060621203924#4#1" level="success"/>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Received document for subscriber channel
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Waiting for receive...
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Restoring operation data
> to output document
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: SubscriptionShim.execute
> () returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <add-association dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833"
> dest-entry-id="68948" event-id="ALTERNATE-DS2#20060621203924#4#1">
> 53c19661d344f84c8c9c249defd18f0d<operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </add-association>
> <status event-id="ALTERNATE-DS2#20060621203924#4#1" level="success">
> <operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying input
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Convert
> selected attributes to a form most commonly used in the Identity Vault.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add-
> association #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-
> local-variable("current-value"))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir
> ($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'accountExpires: Convert to Identity Vault time
> format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'accountExpires: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("accountExpires",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("lockoutTime",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to status #2.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-
> local-variable("current-value"))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir
> ($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'accountExpires: Convert to Identity Vault time
> format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'accountExpires: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("accountExpires",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("lockoutTime",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <add-association dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833"
> dest-entry-id="68948" event-id="ALTERNATE-DS2#20060621203924#4#1">
> 53c19661d344f84c8c9c249defd18f0d<operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </add-association>
> <status event-id="ALTERNATE-DS2#20060621203924#4#1" level="success">
> <operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Email
> notifications for failed password subscriptions'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to add-
> association #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Send e-mail on a failure when subscribing to
> passwords'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Send e-mail on failure to reset connected system
> password using the Identity Manager data store password'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to status #2.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Send e-mail on a failure when subscribing to
> passwords'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Send e-mail on failure to reset connected system
> password using the Identity Manager data store password'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <add-association dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833"
> dest-entry-id="68948" event-id="ALTERNATE-DS2#20060621203924#4#1">
> 53c19661d344f84c8c9c249defd18f0d<operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </add-association>
> <status event-id="ALTERNATE-DS2#20060621203924#4#1" level="success">
> <operation-data>
> <password-subscribe-status>
> <association/>
> </password-subscribe-status>
> </operation-data>
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying schema mapping
> policies to input.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Resolving association
> references.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing returned
> document.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing operation
> <add-association> for \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing operation
> <status> for .
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> DirXML Log Event -------------------
> Driver: \NISD_TREE\NISD\SERVICES\ADDriver\ActiveDirectory
> Channel: Subscriber
> Object: \NISD_TREE\NISD\SCHOOLS\Stinson\e011833
> Status: Success
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: End transaction.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Start transaction.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing events for
> transaction.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying event
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'policy
> allows events through only for users who are contained within the
> subtree, are not disabled'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Scope Filtering (Single OU ONLY!)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn not-in-
> container "NISD\SCHOOLS\Business_Careers") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn in-
> container "NISD\SCHOOLS\Business_Careers\STU") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Veto Labs and Student OU's (Single OU ONLY!)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name
> equal "User") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Query from policy
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <query class-name="User" dest-dn="\NISD_TREE\NISD\SCHOOLS\Stinson
> \e011833" dest-entry-id="68948" scope="entry">
> <read-attr attr-name="businessCategory"/>
> </query>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Pumping XDS to
> eDirectory.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Performing
> operation query for \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Query from policy
> result
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <instance class-name="User" qualified-src-dn="O=NISD\OU=SCHOOLS
> \OU=Stinson\CN=e011833" src-dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833"
> src-entry-id="68948">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> </instance>
> <status level="success"></status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-attr
> 'businessCategory' equal "STUDENT") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn equal
> "student") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn equal
> "teacher") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Only synchronize users in Business Careers'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-src-dn not-in-
> container "NISD\SCHOOLS\Business_Careers") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Only
> synchronize users in Business Careers'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-status
> (level="warning","Changes Ignored: Out of scope").
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: arg-string
> ("Changes Ignored: Out of scope")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: token-text
> ("Changes Ignored: Out of scope")
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Arg Value:
> "Changes Ignored: Out of scope".
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> DirXML Log Event -------------------
> Driver: \NISD_TREE\NISD\SERVICES\ADDriver\ActiveDirectory
> Channel: Subscriber
> Status: Warning
> Message: Changes Ignored: Out of scope
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Subscriber processing
> modify for \NISD_TREE\NISD\SCHOOLS\Stinson\e011833.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying command
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: Command.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'A set
> of rules that are executed when any one of the user name mapping options
> are selected.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'consider user objects when name mapping is enabled
> (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-class-name not-
> equal "User") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'FullNameMap' equal "false") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'generate full name on merge (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'FullNameMap' equal "true") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-xpath true ".
> [@from-merge='true']") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'escape source object name (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "rename") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'map rename to NT logon name (SUB)'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'LogonNameMap' equal "true") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "rename") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> 'Transform NMAS attribute to password elements'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Convert adds of the nspmDistributionPassword attribute
> to password elements'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block modifies for failed password publish operations
> if reset password is false'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'reset-external-password-on-failure' equal "false") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-xpath true
> "modify-attr[@attr-name='nspmDistributionPassword' and @failed-
> sync='true']") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Convert modifies of a nspmDistributionPassword
> attribute to a modify password operation'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-op-attr
> 'nspmDistributionPassword' available) = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block empty modify operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify") = TRUE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-xpath not-true
> "modify-attr") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: Password
> (Sub)-Default Password Policy.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'On User add, provide default password of Surname if no
> password exists'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> 'Subscribe to password changes'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block subscribing to passwords when objects are
> added'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'enable-password-subscribe' equal "false") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Block subscribing to password modifications'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'enable-password-subscribe' equal "false") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy:
> 'Payloads for subscribe to password changes'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add operation-data element to password subscribe
> operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify-password") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add payload data to a reset password from a failed
> password publish operation'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify-password") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add payload data to password subscribe operations'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "modify-password") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="User" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="Description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Filtering out
> notification-only attributes.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Fixing up association
> references.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying schema mapping
> policies to output.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping attr-name
> 'Description' to 'description'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Mapping class-name
> 'User' to 'user'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying output
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Convert
> selected attributes to a form most commonly used in Active Directory.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Street Address: Convert LF to CR-LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule 'Street
> Address: Convert LF to CR-LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r
> \n",token-local-variable("current-value"))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'logonHours: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'logonHours: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("logonHours",token-xpath
> ("jadutil:translateTimeMap2ADLenient($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'accountExpires: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'accountExpires: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("accountExpires",token-xpath
> ("jadutil:translateEpoch2FileTime($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'lockoutTime: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'lockoutTime: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("lockoutTime",token-xpath
> ("jadutil:translateEpoch2FileTime($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Add: User - convert multi-valued Telephone to single
> value'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-operation equal
> "add") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'update Active Directory logon name'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-xpath true
> "self::status[@level = 'success']/operation-data/windows-2000-logon-
> name") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="user" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Email
> notifications for failed password publications'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to modify #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="user" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Submitting document to
> subscriber shim:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="user" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Remote Interface Driver:
> Sending...
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify class-name="user" event-id="ALTERNATE-DS2#20060621203924#4#
> 6" qualified-src-dn="O=NISD\OU=SCHOOLS\OU=Stinson\CN=e011833" src-
> dn="\NISD_TREE\NISD\SCHOOLS\Stinson\e011833" src-entry-id="68948"
> timestamp="1150922364#6">
> <association state="associated">53c19661d344f84c8c9c249defd18f0 d
> </association>
> <modify-attr attr-name="description">
> <add-value>
> <value timestamp="1150922364#6" type="string">#506223</value>
> </add-value>
> </modify-attr>
> </modify>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Remote Interface Driver:
> Document sent.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Received.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory :
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status event-id="ALTERNATE-DS2#20060621203924#4#6" level="success"/>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Received document for subscriber channel
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Waiting for receive...
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: SubscriptionShim.execute
> () returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status event-id="ALTERNATE-DS2#20060621203924#4#6" level="success"/>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying input
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Convert
> selected attributes to a form most commonly used in the Identity Vault.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to status #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-
> local-variable("current-value"))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir
> ($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'accountExpires: Convert to Identity Vault time
> format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'accountExpires: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("accountExpires",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying rule
> 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Action: do-
> reformat-op-attr("lockoutTime",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status event-id="ALTERNATE-DS2#20060621203924#4#6" level="success"/>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying policy: 'Email
> notifications for failed password subscriptions'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying to status #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Send e-mail on a failure when subscribing to
> passwords'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Evaluating selection
> criteria for rule 'Send e-mail on failure to reset connected system
> password using the Identity Manager data store password'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> <nds dtdversion="1.1" ndsversion="8.7">
> <source>
> <product asn1id="" build="20051114_120000" instance="\NISD_TREE\NISD
> \SERVICES\ADDriver\ActiveDirectory" version="3.1">AD</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status event-id="ALTERNATE-DS2#20060621203924#4#6" level="success"/>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Applying schema mapping
> policies to input.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Resolving association
> references.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing returned
> document.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: Processing operation
> <status> for .
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST:
> DirXML Log Event -------------------
> Driver: \NISD_TREE\NISD\SERVICES\ADDriver\ActiveDirectory
> Channel: Subscriber
> Object: \NISD_TREE\NISD\SCHOOLS\Stinson\e011833
> Status: Success
> DVRS: [2006/06/21 15:39:24] ActiveDirectory ST: End transaction.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Received.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory :
> <nds dtdversion="2.2">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify-password class-name="user" src-
> dn="CN=e011833,OU=Users,OU=Staff,OU=BusinessCareer s,OU=High,OU=Schools,OU
> =NISD,DC=northside,DC=isd,DC=tenet,DC=edu">
> <association>53c19661d344f84c8c9c249defd18f0d</association>
> <password><!-- content suppressed --></password>
> </modify-password>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Received document for publisher channel
> DVRS: [2006/06/21 15:39:24] ActiveDirectory : Remote Interface Driver:
> Waiting for receive...
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Receiving DOM document
> from application.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="2.2">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify-password class-name="user" src-
> dn="CN=e011833,OU=Users,OU=Staff,OU=BusinessCareer s,OU=High,OU=Schools,OU
> =NISD,DC=northside,DC=isd,DC=tenet,DC=edu">
> <association>53c19661d344f84c8c9c249defd18f0d</association>
> <password><!-- content suppressed --></password>
> </modify-password>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying input
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying policy: 'Convert
> selected attributes to a form most commonly used in the Identity Vault.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying to modify-
> password #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule
> 'streetAddress: Convert CR-LF to LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-
> local-variable("current-value"))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule
> 'logonHours: Convert to Login Allowed Time Map form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir
> ($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'accountExpires: Convert to Identity Vault time
> format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule
> 'accountExpires: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("accountExpires",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule
> 'lockoutTime: Convert to Identity Vault time format'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("lockoutTime",token-xpath
> ("jadutil:translateFileTime2Epoch($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="2.2">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify-password class-name="user" src-
> dn="CN=e011833,OU=Users,OU=Staff,OU=BusinessCareer s,OU=High,OU=Schools,OU
> =NISD,DC=northside,DC=isd,DC=tenet,DC=edu">
> <association>53c19661d344f84c8c9c249defd18f0d</association>
> <password><!-- content suppressed --></password>
> </modify-password>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying policy: 'Email
> notifications for failed password subscriptions'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying to modify-
> password #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'Send e-mail on a failure when subscribing to
> passwords'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'Send e-mail on failure to reset connected system
> password using the Identity Manager data store password'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-global-variable
> 'notify-user-on-password-dist-failure' equal "true") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="2.2">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify-password class-name="user" src-
> dn="CN=e011833,OU=Users,OU=Staff,OU=BusinessCareer s,OU=High,OU=Schools,OU
> =NISD,DC=northside,DC=isd,DC=tenet,DC=edu">
> <association>53c19661d344f84c8c9c249defd18f0d</association>
> <password><!-- content suppressed --></password>
> </modify-password>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying schema mapping
> policies to input.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Mapping class-name
> 'user' to 'User'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Resolving association
> references.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying event
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying policy: Event
> Transform.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying to modify-
> password #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'setup for move validation'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-operation equal
> "move") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'setup for rename validation'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-operation equal
> "move") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'move or rename validation'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-local-variable
> 'cached-object-value' match ".*") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'move or rename cached context update'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-local-variable
> 'cached-object-value' match ".*") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="2.2">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <input>
> <modify-password class-name="User" src-
> dn="CN=e011833,OU=Users,OU=Staff,OU=BusinessCareer s,OU=High,OU=Schools,OU
> =NISD,DC=northside,DC=isd,DC=tenet,DC=edu">
> <association>53c19661d344f84c8c9c249defd18f0d</association>
> <password><!-- content suppressed --></password>
> </modify-password>
> </input>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying publisher
> filter.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Filtered out <modify-
> password class-name='User'>.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Fixing up association
> references.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying schema mapping
> policies to output.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying output
> transformation policies.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying policy: 'Convert
> selected attributes to a form most commonly used in Active Directory.'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying to status #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'Street Address: Convert LF to CR-LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule 'Street
> Address: Convert LF to CR-LF'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r
> \n",token-local-variable("current-value"))).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'logonHours: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule
> 'logonHours: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("logonHours",token-xpath
> ("jadutil:translateTimeMap2ADLenient($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'accountExpires: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule
> 'accountExpires: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("accountExpires",token-xpath
> ("jadutil:translateEpoch2FileTime($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'lockoutTime: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule selected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying rule
> 'lockoutTime: Convert to Active Directory form'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Action: do-
> reformat-op-attr("lockoutTime",token-xpath
> ("jadutil:translateEpoch2FileTime($current-value)")).
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'Add: User - convert multi-valued Telephone to single
> value'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-operation equal
> "add") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Evaluating selection
> criteria for rule 'update Active Directory logon name'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: (if-xpath true
> "self::status[@level = 'success']/operation-data/windows-2000-logon-
> name") = FALSE.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Rule rejected.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status level="warning">Code(-8015) Operation vetoed by filter.
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying policy: 'Email
> notifications for failed password publications'.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Applying to status #1.
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Policy returned:
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status level="warning">Code(-8015) Operation vetoed by filter.
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status level="warning">Code(-8015) Operation vetoed by filter.
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Remote Interface Driver:
> Sending...
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT:
> <nds dtdversion="3.0" ndsversion="8.x">
> <source>
> <product version="3.0.0.20051118 ">DirXML</product>
> <contact>Novell, Inc.</contact>
> </source>
> <output>
> <status level="warning">Code(-8015) Operation vetoed by filter.
> </status>
> </output>
> </nds>
> DVRS: [2006/06/21 15:39:24] ActiveDirectory PT: Remote Interface Driver:
> Document sent.