Hello,

I have a problem with migrating users to MAD. In our testenviroment it
works very well. I cant see where it goes wrong. Below is the level 3
logfile from the VAULT.

Thanks for the help,

Frank







[05/26/08 13:56:06.553]:ADTRACE :Reading named passwords list.
[05/26/08 13:56:06.553]:ADTRACE :Named passwords:
[05/26/08 13:56:06.554]:ADTRACE :Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-EngineControlValues.
[05/26/08 13:56:06.555]:ADTRACE :Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers#DirXML-ConfigValues.
[05/26/08 13:56:06.555]:ADTRACE :Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-ConfigValues.
[05/26/08 13:56:06.556]:ADTRACE :Global Configuration Values:
[05/26/08 13:56:06.556]:ADTRACE : Name: ConnectedSystemName Value:
Active Directory
[05/26/08 13:56:06.556]:ADTRACE : Name: ExchMailboxPolicy Value: none
[05/26/08 13:56:06.556]:ADTRACE : Name: exch-default-mdb Value:
[05/26/08 13:56:06.557]:ADTRACE : Name: pwd-mgt-display Value: show
[05/26/08 13:56:06.557]:ADTRACE : Name: enable-password-subscribe
Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name: enable-password-publish Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name: publish-password-to-nds Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name: publish-password-to-dp Value: false
[05/26/08 13:56:06.557]:ADTRACE : Name: enforce-password-policy Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name:
reset-external-password-on-failure Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name:
notify-user-on-password-dist-failure Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name: name-map-display Value: show
[05/26/08 13:56:06.557]:ADTRACE : Name: FullNameMap Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name: LogonNameMap Value: true
[05/26/08 13:56:06.557]:ADTRACE : Name: UpnMap Value: none
[05/26/08 13:56:06.557]:ADTRACE : Name: dirxml.auto.treename Value: IDMEDIR
[05/26/08 13:56:06.557]:ADTRACE : Name: dirxml.auto.driverdn Value:
\IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active Directory
[05/26/08 13:56:06.557]:ADTRACE : Name: dirxml.auto.driverguid Value:
{5BC49B00-2B12-11dd-9657-001CC4D8B2F8}
[05/26/08 13:56:06.560]:ADTRACE :Found subscriber IDM Driver
Set\Identity Manager Drivers\Active Directory\Subscriber.
[05/26/08 13:56:06.563]:ADTRACE :Found publisher IDM Driver Set\Identity
Manager Drivers\Active Directory\Publisher.
[05/26/08 13:56:06.563]:ADTRACE :Creating subscriber thread.
[05/26/08 13:56:06.613]:ADTRACE ST:Subscriber thread starting.
[05/26/08 13:56:06.627]:ADTRACE ST:Initializing driver shim.
[05/26/08 13:56:06.627]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-ApplicationSchema.
[05/26/08 13:56:06.629]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-ConfigManifest.
[05/26/08 13:56:06.629]:ADTRACE ST:Reading driver information from the
\IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active Directory object.
[05/26/08 13:56:06.629]:ADTRACE ST:Loading Java shim
com.novell.nds.dirxml.remote.driver.DriverShimImpl .
[05/26/08 13:56:06.646]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-ShimConfigInfo.
[05/26/08 13:56:06.648]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverStorage.
[05/26/08 13:56:06.649]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<init-params src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory">
<authentication-info>
<server>REMOTE(hostname=172.31.1.24 port=8090)172.31.1.24</server>
<user>.tse.local/IDMUser</user>
<password><!-- content suppressed --></password>
</authentication-info>
<driver-options>
<auth-options display-name="Show authentication
options">show</auth-options>
<auth-method display-name="Authentication
Method">Negotiate</auth-method>
<signing display-name="Digitally sign communications">no</signing>
<sealing display-name="Digitally sign and seal
communications">no</sealing>
<use-ssl display-name="Use SSL for encryption">no</use-ssl>
<impersonation display-name="Logon and
impersonate">yes</impersonation>
<xchg-options display-name="Show Microsoft Exchange
options">show</xchg-options>
<exch-api-type display-name="Exchange Management interface type
(use-cdoexm/use-post-cdoexm)">default</exch-api-type>
<exch-move display-name="Allow Exchange mailbox move
(yes/no)">no</exch-move>
<exch-delete display-name="Allow Exchange mailbox delete
(yes/no)">no</exch-delete>
<access-options display-name="Show access
options">show</access-options>
<pollingInterval display-name="Driver Polling
Interval">1</pollingInterval>
<pub-heartbeat-interval display-name="Publisher heartbeat
interval">0</pub-heartbeat-interval>
<pub-password-expire-time display-name="Password Sync Timeout
(minutes)">5</pub-password-expire-time>
<search-domain-scope display-name="Search domain
scope">no</search-domain-scope>
<retry-ldap-auth-unknown display-name="Retry LDAP Auth unknown
error">no</retry-ldap-auth-unknown>
<enable-incremental-values display-name="Enable DirSync
Incremental Values">no</enable-incremental-values>
</driver-options>
</init-params>
</input>
</nds>
[05/26/08 13:56:06.650]:ADTRACE STriverShim.init() returned:
[05/26/08 13:56:06.650]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success">
<provides-secure-channel>false</provides-secure-channel>
</status>
</output>
</nds>
[05/26/08 13:56:06.760]:ADTRACE ST:Initializing ECMAScript extensions.
[05/26/08 13:56:06.761]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverFilter.
[05/26/08 13:56:06.762]:ADTRACE ST:Loaded filter.
[05/26/08 13:56:06.762]:ADTRACE ST:
<filter>
<filter-class class-name="Group" publisher="sync" subscriber="sync">
<filter-attr attr-name="CN" publisher="ignore" subscriber="ignore"/>
<filter-attr attr-name="Description" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Full Name" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="L" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Member" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Owner" publisher="sync" subscriber="sync"/>
</filter-class>
<filter-class class-name="Organizational Unit" publisher="sync"
subscriber="sync">
<filter-attr attr-name="Description" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="OU" publisher="ignore" subscriber="ignore"/>
</filter-class>
<filter-class class-name="User" publisher="sync" subscriber="sync">
<filter-attr attr-name="CN" publisher="ignore" subscriber="ignore"/>
<filter-attr attr-name="Description" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="DirXML-ADAliasName" publisher="sync"
subscriber="ignore"/>
<!--filter-attr attr-name="DirXML-ADContext" publisher="notify"
subscriber="sync"/-->
<filter-attr attr-name="Facsimile Telephone Number" publisher="sync"
subscriber="sync"/>
<filter-attr attr-name="Full Name" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Given Name" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Initials" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Internet EMail Address" publisher="sync"
subscriber="sync"/>
<filter-attr attr-name="L" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Login Allowed Time Map" publisher="sync"
subscriber="sync"/>
<!-- login disabled is not synchronized if account is controlled by
entitlements-->
<filter-attr attr-name="Login Disabled" merge-authority="default"
publisher="sync" publisher-optimize-modify="true" subscriber="sync"/>
<filter-attr attr-name="Physical Delivery Office Name"
publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Postal Code" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Postal Office Box" publisher="sync"
subscriber="sync"/>
<filter-attr attr-name="S" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="SA" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Surname" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="Telephone Number" publisher="sync"
subscriber="sync"/>
<filter-attr attr-name="Title" publisher="sync" subscriber="sync"/>
<filter-attr attr-name="nspmDistributionPassword"
merge-authority="none" publisher="ignore"
publisher-optimize-modify="false" subscriber="notify"/>
<!-- turn on entitlement notifications when entitlements are enabled.
if the user enables entitlements after import this will need to be
updated manually in the driver filter config via iManager or
Designer. -->
</filter-class>
</filter>
[05/26/08 13:56:06.764]:ADTRACE ST:Initializing subscriber IDM Driver
Set\Identity Manager Drivers\Active Directory\Subscriber for
\IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active Directory.
[05/26/08 13:56:06.764]:ADTRACE ST:Loading Subscriber input
transformation policies.
[05/26/08 13:56:06.764]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/InputTransform#XmlData.
[05/26/08 13:56:06.765]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.768]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Password%28Pub%29-Sub+Email+Notifications#XmlData.
[05/26/08 13:56:06.769]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.771]:ADTRACE ST:Loading Subscriber output
transformation policies.
[05/26/08 13:56:06.771]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/OutputTransform#XmlData.
[05/26/08 13:56:06.772]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.774]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Password%28Sub%29-Pub+Email+Notifications#XmlData.
[05/26/08 13:56:06.774]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.775]:ADTRACE ST:Loading Subscriber schema mapping
policies.
[05/26/08 13:56:06.776]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/SchemaMapping#XmlData.
[05/26/08 13:56:06.777]:ADTRACE ST:Found schema map.
[05/26/08 13:56:06.778]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/SchemaMapping#XmlData.
[05/26/08 13:56:06.779]:ADTRACE ST:Found schema map.
[05/26/08 13:56:06.779]:ADTRACE ST:Loading policies.
[05/26/08 13:56:06.779]:ADTRACE ST:Loading Subscriber event
transformation policies.
[05/26/08 13:56:06.780]:ADTRACE ST:Policy not found.
[05/26/08 13:56:06.780]:ADTRACE ST:Loading Subscriber object matching
policies.
[05/26/08 13:56:06.780]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Matching#XmlData.
[05/26/08 13:56:06.781]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.782]:ADTRACE ST:Loading Subscriber object creation
policies.
[05/26/08 13:56:06.783]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Creation#XmlData.
[05/26/08 13:56:06.784]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.785]:ADTRACE ST:Loading Subscriber object placement
policies.
[05/26/08 13:56:06.786]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Placement#XmlData.
[05/26/08 13:56:06.786]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.787]:ADTRACE ST:Loading Subscriber command
transformation policies.
[05/26/08 13:56:06.787]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Command#XmlData.
[05/26/08 13:56:06.787]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.789]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/UserNameMap#XmlData.
[05/26/08 13:56:06.790]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.792]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Password%28Sub%29-Transform+Distribution+Password#XmlData.
[05/26/08 13:56:06.793]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.797]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Password%28Sub%29-Default+Password+Policy#XmlData.
[05/26/08 13:56:06.797]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.798]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Password%28Sub%29-Check+Password+GCV#XmlData.
[05/26/08 13:56:06.799]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.799]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/Password%28Sub%29-Add+Password+Payload#XmlData.
[05/26/08 13:56:06.800]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.802]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Subscriber/%28Sub%29-Group+Member+Resolution#XmlData.
[05/26/08 13:56:06.802]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:06.803]:ADTRACE ST:Mapping sensitive attribute names to
application space
[05/26/08 13:56:06.820]:ADTRACE ST:Initializing subscriber shim.
[05/26/08 13:56:07.020]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-ShimConfigInfo.
[05/26/08 13:56:07.022]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverStorage.
[05/26/08 13:56:07.022]:ADTRACE ST:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Description' to
'description'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Full Name' to
'displayName'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Member' to 'member'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Owner' to
'managedBy'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Description' to
'description'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Description' to
'description'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Facsimile
Telephone Number' to 'facsimileTelephoneNumber'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Full Name' to
'displayName'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Given Name' to
'givenName'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Initials' to
'initials'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Internet EMail
Address' to 'mail'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'L' to
'physicalDeliveryOfficeName'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Login Allowed
Time Map' to 'logonHours'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Login Disabled'
to 'dirxml-uACAccountDisable'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Physical
Delivery Office Name' to 'l'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Postal Code' to
'postalCode'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'Postal Office
Box' to 'postOfficeBox'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'S' to 'st'.
[05/26/08 13:56:07.023]:ADTRACE ST: Mapping attr-name 'SA' to
'streetAddress'.
[05/26/08 13:56:07.024]:ADTRACE ST: Mapping attr-name 'Surname' to 'sn'.
[05/26/08 13:56:07.024]:ADTRACE ST: Mapping attr-name 'Telephone
Number' to 'telephoneNumber'.
[05/26/08 13:56:07.024]:ADTRACE ST: Mapping attr-name 'Title' to 'title'.
[05/26/08 13:56:07.024]:ADTRACE ST: Mapping class-name 'Group' to 'group'.
[05/26/08 13:56:07.024]:ADTRACE ST: Mapping class-name 'Organizational
Unit' to 'organizationalUnit'.
[05/26/08 13:56:07.024]:ADTRACE ST: Mapping class-name 'User' to 'user'.
[05/26/08 13:56:07.024]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<init-params src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory\Subscriber">
<authentication-info>
<server>REMOTE(hostname=172.31.1.24 port=8090)172.31.1.24</server>
<user>.tse.local/IDMUser</user>
<password><!-- content suppressed --></password>
</authentication-info>
<driver-filter>
<allow-class class-name="group">
<allow-attr attr-name="description"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="L"/>
<allow-attr attr-name="member"/>
<allow-attr attr-name="managedBy"/>
</allow-class>
<allow-class class-name="organizationalUnit">
<allow-attr attr-name="description"/>
</allow-class>
<allow-class class-name="user">
<allow-attr attr-name="description"/>
<allow-attr attr-name="facsimileTelephoneNumber"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="givenName"/>
<allow-attr attr-name="initials"/>
<allow-attr attr-name="mail"/>
<allow-attr attr-name="physicalDeliveryOfficeName"/>
<allow-attr attr-name="logonHours"/>
<allow-attr attr-name="dirxml-uACAccountDisable"/>
<allow-attr attr-name="l"/>
<allow-attr attr-name="postalCode"/>
<allow-attr attr-name="postOfficeBox"/>
<allow-attr attr-name="st"/>
<allow-attr attr-name="streetAddress"/>
<allow-attr attr-name="sn"/>
<allow-attr attr-name="telephoneNumber"/>
<allow-attr attr-name="title"/>
</allow-class>
</driver-filter>
</init-params>
</input>
</nds>
[05/26/08 13:56:07.025]:ADTRACE ST:SubscriptionShim.init() returned:
[05/26/08 13:56:07.025]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:56:07.025]:ADTRACE ST:Applying input transformation policies.
[05/26/08 13:56:07.025]:ADTRACE ST:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:07.025]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:07.025]:ADTRACE ST: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:07.025]:ADTRACE ST: Rule selected.
[05/26/08 13:56:07.025]:ADTRACE ST: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:07.025]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:07.026]:ADTRACE ST: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.026]:ADTRACE ST: Rule selected.
[05/26/08 13:56:07.026]:ADTRACE ST: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.026]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:07.026]:ADTRACE ST: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:07.026]:ADTRACE ST: Rule selected.
[05/26/08 13:56:07.026]:ADTRACE ST: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.026]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.026]:ADTRACE ST: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:07.026]:ADTRACE ST: Rule selected.
[05/26/08 13:56:07.026]:ADTRACE ST: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.026]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.026]:ADTRACE ST:Policy returned:
[05/26/08 13:56:07.026]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:56:07.026]:ADTRACE ST:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:07.026]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:07.026]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:07.027]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.027]:ADTRACE ST: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:07.027]:ADTRACE ST: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:07.027]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:07.027]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:07.027]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.027]:ADTRACE ST: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:07.027]:ADTRACE ST: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:07.027]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:07.027]:ADTRACE ST:Policy returned:
[05/26/08 13:56:07.027]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:56:07.027]:ADTRACE ST:Applying schema mapping policies to
input.
[05/26/08 13:56:07.027]:ADTRACE ST:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.027]:ADTRACE ST:Resolving association references.
[05/26/08 13:56:07.027]:ADTRACE ST:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping class-name 'user' to 'User'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'accountExpires'
to 'Login Expiration Time'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'description' to
'Description'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'displayName' to
'Full Name'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name
'facsimileTelephoneNumber' to 'Facsimile Telephone Number'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'givenName' to
'Given Name'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'initials' to
'Initials'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'l' to 'Physical
Delivery Office Name'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'lockoutTime' to
'Login Intruder Reset Time'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'logonHours' to
'Login Allowed Time Map'.
[05/26/08 13:56:07.028]:ADTRACE ST: Mapping attr-name 'mail' to
'Internet EMail Address'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'memberOf' to
'Group Membership'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'ou' to 'OU'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name
'physicalDeliveryOfficeName' to 'L'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'postalCode' to
'Postal Code'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'postOfficeBox'
to 'Postal Office Box'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'seeAlso' to 'See
Also'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'sn' to 'Surname'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'st' to 'S'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'streetAddress'
to 'SA'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'telephoneNumber'
to 'Telephone Number'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'title' to 'Title'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'cn' to 'CN'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'sAMAccountName'
to 'DirXML-ADAliasName'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name 'cn' to 'CN'.
[05/26/08 13:56:07.029]:ADTRACE ST: Mapping attr-name
'dirxml-uACAccountDisable' to 'Login Disabled'.
[05/26/08 13:56:07.030]:ADTRACE ST:Application DN form: ldap.
[05/26/08 13:56:07.030]:ADTRACE ST:Creating publisher.
[05/26/08 13:56:07.030]:ADTRACE ST:Loading Publisher input
transformation policies.
[05/26/08 13:56:07.031]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/InputTransform#XmlData.
[05/26/08 13:56:07.031]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.032]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Password%28Pub%29-Sub+Email+Notifications#XmlData.
[05/26/08 13:56:07.033]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.039]:ADTRACE ST:Loading Publisher output
transformation policies.
[05/26/08 13:56:07.039]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/OutputTransform#XmlData.
[05/26/08 13:56:07.040]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.041]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Password%28Sub%29-Pub+Email+Notifications#XmlData.
[05/26/08 13:56:07.042]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.043]:ADTRACE ST:Loading Publisher schema mapping
policies.
[05/26/08 13:56:07.043]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/SchemaMapping#XmlData.
[05/26/08 13:56:07.044]:ADTRACE ST:Found schema map.
[05/26/08 13:56:07.045]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/SchemaMapping#XmlData.
[05/26/08 13:56:07.046]:ADTRACE ST:Found schema map.
[05/26/08 13:56:07.047]:ADTRACE ST:Loading Publisher event
transformation policies.
[05/26/08 13:56:07.047]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Event+Transform#XmlData.
[05/26/08 13:56:07.049]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.050]:ADTRACE ST:Loading Publisher object matching
policies.
[05/26/08 13:56:07.050]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Matching#XmlData.
[05/26/08 13:56:07.051]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.052]:ADTRACE ST:Loading Publisher object creation
policies.
[05/26/08 13:56:07.052]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Creation#XmlData.
[05/26/08 13:56:07.053]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.053]:ADTRACE ST:Loading Publisher object placement
policies.
[05/26/08 13:56:07.054]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Placement#XmlData.
[05/26/08 13:56:07.054]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.055]:ADTRACE ST:Loading Publisher command
transformation policies.
[05/26/08 13:56:07.055]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/UserNameMap#XmlData.
[05/26/08 13:56:07.056]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.057]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Command+Transform#XmlData.
[05/26/08 13:56:07.057]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.059]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Command+Transform+SS#XmlData.
[05/26/08 13:56:07.060]:ADTRACE ST:Found XSLT policy.
[05/26/08 13:56:07.061]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Password%28Pub%29-Default+Password+Policy#XmlData.
[05/26/08 13:56:07.061]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.064]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Password%28Pub%29-Check+Password+GCV#XmlData.
[05/26/08 13:56:07.065]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.065]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Password%28Pub%29-Publish+Distribution+Password#XmlData.
[05/26/08 13:56:07.066]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.067]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Password%28Pub%29-Publish+NDS+Password#XmlData.
[05/26/08 13:56:07.067]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.068]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory/Publisher/Password%28Pub%29-Add+Password+Payload#XmlData.
[05/26/08 13:56:07.069]:ADTRACE ST:Found DirXMLScript policy.
[05/26/08 13:56:07.070]:ADTRACE ST:Creating publisher thread.
[05/26/08 13:56:07.463]:ADTRACE PT:In publisher thread.
[05/26/08 13:56:07.464]:ADTRACE PT:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-ShimConfigInfo.
[05/26/08 13:56:07.466]:ADTRACE PT:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverStorage.
[05/26/08 13:56:07.466]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.466]:ADTRACE PT: Mapping attr-name 'Description' to
'description'.
[05/26/08 13:56:07.466]:ADTRACE PT: Mapping attr-name 'Full Name' to
'displayName'.
[05/26/08 13:56:07.466]:ADTRACE PT: Mapping attr-name 'Member' to 'member'.
[05/26/08 13:56:07.466]:ADTRACE PT: Mapping attr-name 'Owner' to
'managedBy'.
[05/26/08 13:56:07.466]:ADTRACE PT: Mapping attr-name 'Description' to
'description'.
[05/26/08 13:56:07.466]:ADTRACE PT: Mapping attr-name 'Description' to
'description'.
[05/26/08 13:56:07.466]:ADTRACE PT: Mapping attr-name
'DirXML-ADAliasName' to 'sAMAccountName'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Facsimile
Telephone Number' to 'facsimileTelephoneNumber'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Full Name' to
'displayName'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Given Name' to
'givenName'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Initials' to
'initials'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Internet EMail
Address' to 'mail'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'L' to
'physicalDeliveryOfficeName'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Login Allowed
Time Map' to 'logonHours'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Login Disabled'
to 'dirxml-uACAccountDisable'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Physical
Delivery Office Name' to 'l'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Postal Code' to
'postalCode'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Postal Office
Box' to 'postOfficeBox'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'S' to 'st'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'SA' to
'streetAddress'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Surname' to 'sn'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Telephone
Number' to 'telephoneNumber'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping attr-name 'Title' to 'title'.
[05/26/08 13:56:07.467]:ADTRACE PT: Mapping class-name 'Group' to 'group'.
[05/26/08 13:56:07.468]:ADTRACE PT: Mapping class-name 'Organizational
Unit' to 'organizationalUnit'.
[05/26/08 13:56:07.468]:ADTRACE PT: Mapping class-name 'User' to 'user'.
[05/26/08 13:56:07.468]:ADTRACE PT:Initializing publisher shim.
[05/26/08 13:56:07.468]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<init-params src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory\Publisher">
<authentication-info>
<server>REMOTE(hostname=172.31.1.24 port=8090)172.31.1.24</server>
<user>.tse.local/IDMUser</user>
<password><!-- content suppressed --></password>
</authentication-info>
<driver-filter>
<allow-class class-name="group">
<allow-attr attr-name="description"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="L"/>
<allow-attr attr-name="member"/>
<allow-attr attr-name="managedBy"/>
</allow-class>
<allow-class class-name="organizationalUnit">
<allow-attr attr-name="description"/>
</allow-class>
<allow-class class-name="user">
<allow-attr attr-name="description"/>
<allow-attr attr-name="sAMAccountName"/>
<allow-attr attr-name="facsimileTelephoneNumber"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="givenName"/>
<allow-attr attr-name="initials"/>
<allow-attr attr-name="mail"/>
<allow-attr attr-name="physicalDeliveryOfficeName"/>
<allow-attr attr-name="logonHours"/>
<allow-attr attr-name="dirxml-uACAccountDisable"/>
<allow-attr attr-name="l"/>
<allow-attr attr-name="postalCode"/>
<allow-attr attr-name="postOfficeBox"/>
<allow-attr attr-name="st"/>
<allow-attr attr-name="streetAddress"/>
<allow-attr attr-name="sn"/>
<allow-attr attr-name="telephoneNumber"/>
<allow-attr attr-name="title"/>
</allow-class>
</driver-filter>
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:07.469]:ADTRACE PT:PublicationShim.init() returned:
[05/26/08 13:56:07.469]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:56:07.469]:ADTRACE PT:Applying input transformation policies.
[05/26/08 13:56:07.469]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:07.469]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:07.469]:ADTRACE PT: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:07.469]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.469]:ADTRACE PT: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:07.469]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:07.469]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.469]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.469]:ADTRACE PT: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.470]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:07.470]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:07.470]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.470]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.470]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.470]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:07.470]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.470]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.470]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.470]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.470]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:56:07.470]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:07.470]:ADTRACE ST:Publisher thread created.
[05/26/08 13:56:07.471]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:07.471]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:07.471]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.471]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:07.471]:ADTRACE PT: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:07.471]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.471]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:07.472]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.472]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:07.472]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:07.472]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.472]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.472]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:56:07.472]:ADTRACE PT:Applying schema mapping policies to
input.
[05/26/08 13:56:07.472]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.472]:ADTRACE PT:Resolving association references.
[05/26/08 13:56:07.472]:ADTRACE PT:Receiving DOM document from application.
[05/26/08 13:56:07.472]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.472]:ADTRACE PT:Applying input transformation policies.
[05/26/08 13:56:07.472]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:07.473]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.473]:ADTRACE PT: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:07.473]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.473]:ADTRACE PT: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:07.473]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:07.473]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.473]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.473]:ADTRACE PT: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.473]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:07.473]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:07.473]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.473]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.473]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.473]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:07.473]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.473]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.473]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.474]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.474]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.474]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:07.474]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.474]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:07.474]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.474]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:07.474]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.474]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:07.474]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.474]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:07.474]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.474]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.474]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.474]:ADTRACE PT:Applying schema mapping policies to
input.
[05/26/08 13:56:07.475]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.475]:ADTRACE PT: No mapping for attr-name 'Public Key'.
[05/26/08 13:56:07.475]:ADTRACE PT:Resolving association references.
[05/26/08 13:56:07.475]:ADTRACE PT:Applying event transformation policies.
[05/26/08 13:56:07.475]:ADTRACE PT:Applying policy: %+C%14CEvent
Transform%-C.
[05/26/08 13:56:07.475]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.475]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for move validation'.
[05/26/08 13:56:07.475]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:07.475]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.475]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for rename validation'.
[05/26/08 13:56:07.475]:ADTRACE PT: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:07.475]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.475]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename validation'.
[05/26/08 13:56:07.475]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:07.475]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.475]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename cached context update'.
[05/26/08 13:56:07.475]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:07.476]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.476]:ADTRACE PT: Evaluating selection criteria for
rule 'veto move'.
[05/26/08 13:56:07.476]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:07.476]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.476]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.476]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.476]:ADTRACE PT:Skipping publisher filter on
operation query.
[05/26/08 13:56:07.476]:ADTRACE PT:Publisher processing query for .
[05/26/08 13:56:07.476]:ADTRACE PT:Applying command transformation policies.
[05/26/08 13:56:07.476]:ADTRACE PT:Applying policy: %+C%14C'A set of
rules that implement the user name mapping options'%-C.
[05/26/08 13:56:07.476]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.476]:ADTRACE PT: Evaluating selection criteria for
rule 'consider user objects when name mapping is enabled'.
[05/26/08 13:56:07.476]:ADTRACE PT: (if-class-name not-equal
"User") = TRUE.
[05/26/08 13:56:07.476]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.476]:ADTRACE PT: Applying rule 'consider user
objects when name mapping is enabled'.
[05/26/08 13:56:07.476]:ADTRACE PT: Action: do-break().
[05/26/08 13:56:07.476]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.477]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.477]:ADTRACE PT:Applying policy: %+C%14CCommand
Transform%-C.
[05/26/08 13:56:07.477]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.477]:ADTRACE PT: Evaluating selection criteria for
rule 'set cached context value on merge'.
[05/26/08 13:56:07.477]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.477]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.477]:ADTRACE PT: Evaluating selection criteria for
rule 'Set Equivalent To Me when adding object to a group'.
[05/26/08 13:56:07.477]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:07.477]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.477]:ADTRACE PT: Evaluating selection criteria for
rule 'Remove Equivalent To Me when removing object from a group'.
[05/26/08 13:56:07.477]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:07.477]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.477]:ADTRACE PT: Evaluating selection criteria for
rule 'remove managed attributes when object disassociated'.
[05/26/08 13:56:07.477]:ADTRACE PT: (if-operation equal
"remove-association") = FALSE.
[05/26/08 13:56:07.477]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.477]:ADTRACE PT: Evaluating selection criteria for
rule 'Prevent unassociated users from being removed from groups'.
[05/26/08 13:56:07.477]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.478]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.478]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.478]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.478]:ADTRACE ST:Starting event loop.
[05/26/08 13:56:07.478]:ADTRACE PT:Applying XSLT policy:
%+C%14CCommand+Transform+SS%-C.
[05/26/08 13:56:07.478]:ADTRACE ST:Received state change event.
[05/26/08 13:56:07.478]:ADTRACE ST:Transitioned from state
'%+C%14CStopped%-C' to state '%+C%14CStarting%-C'.
[05/26/08 13:56:07.478]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.478]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.478]:ADTRACE PT:Applying policy:
%+C%14CPassword(Pub)-Default Password Policy%-C.
[05/26/08 13:56:07.478]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.478]:ADTRACE PT: Evaluating selection criteria for
rule 'On User add, provide default password of @Dirxml1 if no password
exists'.
[05/26/08 13:56:07.479]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.479]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.479]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.479]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.479]:ADTRACE PT:Applying policy: %+C%14C'Publish
Passwords'%-C.
[05/26/08 13:56:07.479]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.479]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to Identity Manager data store when
adding a object'.
[05/26/08 13:56:07.479]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:07.479]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.479]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the Identity Manager data
store'.
[05/26/08 13:56:07.479]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:07.479]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.479]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.479]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.479]:ADTRACE ST:Successfully processed state change
event.
[05/26/08 13:56:07.479]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NMAS distribution password'%-C.
[05/26/08 13:56:07.480]:ADTRACE ST:Submitting identification query to
subscriber shim:
[05/26/08 13:56:07.480]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.480]:ADTRACE PT: Evaluating selection criteria for
rule 'Add nspmDistributionAttribute attribute to add operation'.
[05/26/08 13:56:07.480]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query event-id="query-driver-ident" scope="entry">
<search-class class-name="__driver_identification_class__"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:07.480]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:07.480]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.480]:ADTRACE PT: Evaluating selection criteria for
rule 'Change modify-password operations to a modify'.
[05/26/08 13:56:07.480]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:07.480]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.480]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.480]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.480]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NDS password.'%-C.
[05/26/08 13:56:07.480]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.480]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to NDS password'.
[05/26/08 13:56:07.480]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.481]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the NDS password'.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.481]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.481]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.481]:ADTRACE PT:Applying policy: %+C%14C'Publish
password payloads'%-C.
[05/26/08 13:56:07.481]:ADTRACE PT: Applying to query #1.
[05/26/08 13:56:07.481]:ADTRACE PT: Evaluating selection criteria for
rule 'Add operation-data element to password operations'.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.481]:ADTRACE PT: Evaluating selection criteria for
rule 'Add payload data to password operations'.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-operation equal
"addPayloadToPassword") = FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.481]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:07.482]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.482]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.482]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.482]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<query dest-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" scope="entry">
<read-attr attr-name="Public Key"/>
</query>
</input>
</nds>
[05/26/08 13:56:07.482]:ADTRACE PT:Filtering out notification-only
attributes.
[05/26/08 13:56:07.482]:ADTRACE PT:Pumping XDS to eDirectory.
[05/26/08 13:56:07.482]:ADTRACE PT:Performing operation query for
\IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active Directory.
[05/26/08 13:56:07.483]:ADTRACE PT:Fixing up association references.
[05/26/08 13:56:07.483]:ADTRACE PT:Applying schema mapping policies to
output.
[05/26/08 13:56:07.483]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.483]:ADTRACE PT: No mapping for class-name
'DirXML-Driver'.
[05/26/08 13:56:07.483]:ADTRACE PT:Applying output transformation policies.
[05/26/08 13:56:07.483]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in Active Directory.'%-C.
[05/26/08 13:56:07.484]:ADTRACE PT: Applying to instance #1.
[05/26/08 13:56:07.484]:ADTRACE PT: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:07.484]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.484]:ADTRACE PT: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:07.484]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:07.484]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:07.484]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.484]:ADTRACE PT: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:07.484]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:07.484]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:07.484]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.484]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:07.484]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:07.484]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:07.484]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.484]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:07.484]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:07.485]:ADTRACE PT: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:07.485]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.485]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.485]:ADTRACE PT: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:07.485]:ADTRACE PT: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:07.485]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.485]:ADTRACE PT: Applying to status #2.
[05/26/08 13:56:07.485]:ADTRACE PT: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:07.485]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.485]:ADTRACE PT: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:07.485]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:07.485]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:07.485]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.485]:ADTRACE PT: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:07.485]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:07.485]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:07.485]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.485]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:07.486]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:07.486]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:07.486]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.486]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:07.486]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:07.486]:ADTRACE PT: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:07.486]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.486]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.486]:ADTRACE PT: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:07.486]:ADTRACE PT: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:07.486]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.486]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.486]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="DirXML-Driver" event-id="0"
qualified-src-dn="O=IDM Driver Set\CN=Identity Manager Drivers\CN=Active
Directory" src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" src-entry-id="35529">
<attr attr-name="Public Key">
<value timestamp="1211799374#1337"
type="octet">AQAAAAQAAABaANwAAABSAVoAggB2AAAAAABDA E4APQBJAGQAZQBuAHQAaQB0AHkAIABNAGEAbgBhAGcAZQByACA ARAByAGkAdgBlAHIAcwAuAE8APQBJAEQATQAgAEQAcgBpAHYAZ QByACAAUwBlAHQAAABDAE4APQBBAGMAdABpAHYAZQAgAEQAaQB yAGUAYwB0AG8AcgB5AC4AQwBOAD0ASQBkAGUAbgB0AGkAdAB5A CAATQBhAG4AYQBnAGUAcgAgAEQAcgBpAHYAZQByAHMALgBPAD0 ASQBEAE0AIABEAHIAaQB2AGUAcgAgAFMAZQB0AAAAAQAAAAMAA QBsAEJWBAAxLjAAQkMBAANCQQEAMEJMAgCkAU5ONQDzV0SGyFB 1Tj7HlThtnbjHWjlYBtBLhyI+jiXVRUlqbVAGsKAb4/CrlPizJgl25cTD1ziFCkVOAwABAAFNQQgA+XjIHpo/FXdkAFBVUlNBRg==</value>
</attr>
</instance>
<status event-id="0" level="success"></status>
</output>
</nds>
[05/26/08 13:56:07.487]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password publications'%-C.
[05/26/08 13:56:07.487]:ADTRACE PT: Applying to instance #1.
[05/26/08 13:56:07.487]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:07.487]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.487]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:07.487]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.487]:ADTRACE PT: Applying to status #2.
[05/26/08 13:56:07.487]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:07.487]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.487]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:07.487]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-publish-status") = FALSE.
[05/26/08 13:56:07.487]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.487]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.488]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="DirXML-Driver" event-id="0"
qualified-src-dn="O=IDM Driver Set\CN=Identity Manager Drivers\CN=Active
Directory" src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" src-entry-id="35529">
<attr attr-name="Public Key">
<value timestamp="1211799374#1337"
type="octet">AQAAAAQAAABaANwAAABSAVoAggB2AAAAAABDA E4APQBJAGQAZQBuAHQAaQB0AHkAIABNAGEAbgBhAGcAZQByACA ARAByAGkAdgBlAHIAcwAuAE8APQBJAEQATQAgAEQAcgBpAHYAZ QByACAAUwBlAHQAAABDAE4APQBBAGMAdABpAHYAZQAgAEQAaQB yAGUAYwB0AG8AcgB5AC4AQwBOAD0ASQBkAGUAbgB0AGkAdAB5A CAATQBhAG4AYQBnAGUAcgAgAEQAcgBpAHYAZQByAHMALgBPAD0 ASQBEAE0AIABEAHIAaQB2AGUAcgAgAFMAZQB0AAAAAQAAAAMAA QBsAEJWBAAxLjAAQkMBAANCQQEAMEJMAgCkAU5ONQDzV0SGyFB 1Tj7HlThtnbjHWjlYBtBLhyI+jiXVRUlqbVAGsKAb4/CrlPizJgl25cTD1ziFCkVOAwABAAFNQQgA+XjIHpo/FXdkAFBVUlNBRg==</value>
</attr>
</instance>
<status event-id="0" level="success"></status>
</output>
</nds>
[05/26/08 13:56:07.488]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="DirXML-Driver" event-id="0"
qualified-src-dn="O=IDM Driver Set\CN=Identity Manager Drivers\CN=Active
Directory" src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory" src-entry-id="35529">
<attr attr-name="Public Key">
<value timestamp="1211799374#1337"
type="octet">AQAAAAQAAABaANwAAABSAVoAggB2AAAAAABDA E4APQBJAGQAZQBuAHQAaQB0AHkAIABNAGEAbgBhAGcAZQByACA ARAByAGkAdgBlAHIAcwAuAE8APQBJAEQATQAgAEQAcgBpAHYAZ QByACAAUwBlAHQAAABDAE4APQBBAGMAdABpAHYAZQAgAEQAaQB yAGUAYwB0AG8AcgB5AC4AQwBOAD0ASQBkAGUAbgB0AGkAdAB5A CAATQBhAG4AYQBnAGUAcgAgAEQAcgBpAHYAZQByAHMALgBPAD0 ASQBEAE0AIABEAHIAaQB2AGUAcgAgAFMAZQB0AAAAAQAAAAMAA QBsAEJWBAAxLjAAQkMBAANCQQEAMEJMAgCkAU5ONQDzV0SGyFB 1Tj7HlThtnbjHWjlYBtBLhyI+jiXVRUlqbVAGsKAb4/CrlPizJgl25cTD1ziFCkVOAwABAAFNQQgA+XjIHpo/FXdkAFBVUlNBRg==</value>
</attr>
</instance>
<status event-id="0" level="success"></status>
</output>
</nds>
[05/26/08 13:56:07.489]:ADTRACE PT:Receiving DOM document from application.
[05/26/08 13:56:07.489]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.489]:ADTRACE PT:Applying input transformation policies.
[05/26/08 13:56:07.489]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:07.489]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.489]:ADTRACE PT: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:07.489]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.489]:ADTRACE PT: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:07.489]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:07.490]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.490]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.490]:ADTRACE PT: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:07.490]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:07.490]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:07.490]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.490]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.490]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.490]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:07.490]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.490]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:07.490]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:07.490]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.490]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.490]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:07.490]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.491]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:07.491]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.491]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:07.491]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.491]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:07.491]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:07.491]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:07.491]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.491]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.491]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.491]:ADTRACE PT:Applying schema mapping policies to
input.
[05/26/08 13:56:07.491]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:07.491]:ADTRACE PT:Resolving association references.
[05/26/08 13:56:07.491]:ADTRACE PT:Applying event transformation policies.
[05/26/08 13:56:07.491]:ADTRACE PT:Applying policy: %+C%14CEvent
Transform%-C.
[05/26/08 13:56:07.492]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.492]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for move validation'.
[05/26/08 13:56:07.492]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:07.492]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.492]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for rename validation'.
[05/26/08 13:56:07.492]:ADTRACE PT: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:07.492]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.492]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename validation'.
[05/26/08 13:56:07.492]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:07.492]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.492]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename cached context update'.
[05/26/08 13:56:07.492]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:07.492]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.492]:ADTRACE PT: Evaluating selection criteria for
rule 'veto move'.
[05/26/08 13:56:07.492]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:07.492]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.492]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.492]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.493]:ADTRACE PT:Applying publisher filter.
[05/26/08 13:56:07.493]:ADTRACE PT:Publisher processing check-password for .
[05/26/08 13:56:07.493]:ADTRACE PT:Applying command transformation policies.
[05/26/08 13:56:07.493]:ADTRACE PT:Applying policy: %+C%14C'A set of
rules that implement the user name mapping options'%-C.
[05/26/08 13:56:07.493]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.493]:ADTRACE PT: Evaluating selection criteria for
rule 'consider user objects when name mapping is enabled'.
[05/26/08 13:56:07.493]:ADTRACE PT: (if-class-name not-equal
"User") = TRUE.
[05/26/08 13:56:07.493]:ADTRACE PT: Rule selected.
[05/26/08 13:56:07.493]:ADTRACE PT: Applying rule 'consider user
objects when name mapping is enabled'.
[05/26/08 13:56:07.493]:ADTRACE PT: Action: do-break().
[05/26/08 13:56:07.493]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.493]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.493]:ADTRACE PT:Applying policy: %+C%14CCommand
Transform%-C.
[05/26/08 13:56:07.493]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.493]:ADTRACE PT: Evaluating selection criteria for
rule 'set cached context value on merge'.
[05/26/08 13:56:07.494]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.494]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.494]:ADTRACE PT: Evaluating selection criteria for
rule 'Set Equivalent To Me when adding object to a group'.
[05/26/08 13:56:07.494]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:07.494]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.494]:ADTRACE PT: Evaluating selection criteria for
rule 'Remove Equivalent To Me when removing object from a group'.
[05/26/08 13:56:07.494]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:07.494]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.494]:ADTRACE PT: Evaluating selection criteria for
rule 'remove managed attributes when object disassociated'.
[05/26/08 13:56:07.494]:ADTRACE PT: (if-operation equal
"remove-association") = FALSE.
[05/26/08 13:56:07.494]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.494]:ADTRACE PT: Evaluating selection criteria for
rule 'Prevent unassociated users from being removed from groups'.
[05/26/08 13:56:07.494]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.494]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.494]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.494]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.494]:ADTRACE PT:Applying XSLT policy:
%+C%14CCommand+Transform+SS%-C.
[05/26/08 13:56:07.495]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.495]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.495]:ADTRACE PT:Applying policy:
%+C%14CPassword(Pub)-Default Password Policy%-C.
[05/26/08 13:56:07.495]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.495]:ADTRACE PT: Evaluating selection criteria for
rule 'On User add, provide default password of @Dirxml1 if no password
exists'.
[05/26/08 13:56:07.495]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.495]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.495]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.495]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.495]:ADTRACE PT:Applying policy: %+C%14C'Publish
Passwords'%-C.
[05/26/08 13:56:07.495]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.495]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to Identity Manager data store when
adding a object'.
[05/26/08 13:56:07.496]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:07.496]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.496]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the Identity Manager data
store'.
[05/26/08 13:56:07.496]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:07.496]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.496]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.496]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.496]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NMAS distribution password'%-C.
[05/26/08 13:56:07.496]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.496]:ADTRACE PT: Evaluating selection criteria for
rule 'Add nspmDistributionAttribute attribute to add operation'.
[05/26/08 13:56:07.496]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:07.496]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.496]:ADTRACE PT: Evaluating selection criteria for
rule 'Change modify-password operations to a modify'.
[05/26/08 13:56:07.496]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:07.496]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.496]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.497]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.497]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NDS password.'%-C.
[05/26/08 13:56:07.497]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.497]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to NDS password'.
[05/26/08 13:56:07.497]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:07.497]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.497]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the NDS password'.
[05/26/08 13:56:07.497]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:07.497]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.497]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.497]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.497]:ADTRACE PT:Applying policy: %+C%14C'Publish
password payloads'%-C.
[05/26/08 13:56:07.498]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:07.498]:ADTRACE PT: Evaluating selection criteria for
rule 'Add operation-data element to password operations'.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.498]:ADTRACE PT: Evaluating selection criteria for
rule 'Add payload data to password operations'.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal
"addPayloadToPassword") = FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:07.498]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:07.498]:ADTRACE PT:Policy returned:
[05/26/08 13:56:07.499]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password event-id="This check-password result is expected.
It is the result of the shim verifying that the driver object password
is non-empty."><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:07.499]:ADTRACE PT:Filtering out notification-only
attributes.
[05/26/08 13:56:07.499]:ADTRACE PT:Pumping XDS to eDirectory.
[05/26/08 13:56:07.499]:ADTRACE PT:Performing operation check-password for .
[05/26/08 13:56:08.475]:ADTRACE ST:SubscriptionShim.execute() returned:
[05/26/08 13:56:08.475]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="retry" type="remoteloader">No connection to remote
loader</status>
</output>
</nds>
[05/26/08 13:56:08.475]:ADTRACE ST:Requesting 30 second retry delay.
[05/26/08 13:56:08.475]:ADTRACE ST:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Subscriber
Status: Retry
Message: Code(-9006) The driver returned a "retry" status
indicating that the operation should be retried later. Detail from
driver: No connection to remote loader
[05/26/08 13:56:08.477]:ADTRACE ST:Received state change event.
[05/26/08 13:56:08.477]:ADTRACE ST:Transitioned from state
'%+C%14CStarting%-C' to state '%+C%14CRunning%-C'.
[05/26/08 13:56:08.478]:ADTRACE ST:Successfully processed state change
event.
[05/26/08 13:56:08.478]:ADTRACE ST:Submitting identification query to
subscriber shim:
[05/26/08 13:56:08.478]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query event-id="query-driver-ident" scope="entry">
<search-class class-name="__driver_identification_class__"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:09.109]:ADTRACE PT:Fixing up association references.
[05/26/08 13:56:09.109]:ADTRACE PT:Applying schema mapping policies to
output.
[05/26/08 13:56:09.109]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:09.109]:ADTRACE PT:Applying output transformation policies.
[05/26/08 13:56:09.109]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in Active Directory.'%-C.
[05/26/08 13:56:09.110]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:09.110]:ADTRACE PT: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:09.110]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.110]:ADTRACE PT: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:09.110]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:09.110]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:09.110]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.110]:ADTRACE PT: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:09.110]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:09.110]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:09.110]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.110]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:09.110]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:09.110]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:09.110]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.110]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:09.110]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:09.110]:ADTRACE PT: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:09.110]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:09.111]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.111]:ADTRACE PT: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:09.111]:ADTRACE PT: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:09.111]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.111]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.111]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="This check-password result is expected. It is the
result of the shim verifying that the driver object password is
non-empty." level="error">Code(-9046) Invalid password specified for
&lt;check-password>.</status>
</output>
</nds>
[05/26/08 13:56:09.111]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password publications'%-C.
[05/26/08 13:56:09.111]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:09.111]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:09.111]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:09.111]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:09.111]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-publish-status") = FALSE.
[05/26/08 13:56:09.111]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.111]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.112]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="This check-password result is expected. It is the
result of the shim verifying that the driver object password is
non-empty." level="error">Code(-9046) Invalid password specified for
&lt;check-password>.</status>
</output>
</nds>
[05/26/08 13:56:09.112]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="This check-password result is expected. It is the
result of the shim verifying that the driver object password is
non-empty." level="error">Code(-9046) Invalid password specified for
&lt;check-password>.</status>
</output>
</nds>
[05/26/08 13:56:09.264]:ADTRACE PT:Remote Interface Driver: Opening
connection...
[05/26/08 13:56:09.266]:ADTRACE PT:Remote Interface Driver: Connection
established...
[05/26/08 13:56:09.269]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:09.269]:ADTRACE PT:Remote Interface Driver: Sending...
[05/26/08 13:56:09.269]:ADTRACE PT:
<handshake version="1.0">
<password><!-- content suppressed --></password>
</handshake>
[05/26/08 13:56:09.269]:ADTRACE PT:Remote Interface Driver: Document sent.
[05/26/08 13:56:09.282]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:09.282]:ADTRACE :
<handshake version="1.0">
<password><!-- content suppressed --></password>
</handshake>
[05/26/08 13:56:09.282]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:09.282]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:09.282]:ADTRACE PT:Receiving DOM document from application.
[05/26/08 13:56:09.282]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.282]:ADTRACE PT:Applying input transformation policies.
[05/26/08 13:56:09.282]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:09.282]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.282]:ADTRACE PT: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:09.282]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.283]:ADTRACE PT: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:09.283]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:09.283]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:09.283]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.283]:ADTRACE PT: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:09.283]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:09.283]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:09.283]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.283]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:09.283]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:09.283]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:09.283]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.283]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:09.283]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:09.283]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.283]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.283]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:09.284]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.284]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:09.284]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:09.284]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:09.284]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.284]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:09.284]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:09.284]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:09.284]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.284]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.284]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.284]:ADTRACE PT:Applying schema mapping policies to
input.
[05/26/08 13:56:09.284]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:09.284]:ADTRACE PT:Resolving association references.
[05/26/08 13:56:09.284]:ADTRACE PT:Applying event transformation policies.
[05/26/08 13:56:09.284]:ADTRACE PT:Applying policy: %+C%14CEvent
Transform%-C.
[05/26/08 13:56:09.285]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.285]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for move validation'.
[05/26/08 13:56:09.285]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:09.285]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.285]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for rename validation'.
[05/26/08 13:56:09.285]:ADTRACE PT: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:09.285]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.285]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename validation'.
[05/26/08 13:56:09.285]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:09.285]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.285]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename cached context update'.
[05/26/08 13:56:09.285]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:09.285]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.285]:ADTRACE PT: Evaluating selection criteria for
rule 'veto move'.
[05/26/08 13:56:09.285]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:09.285]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.285]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.285]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.285]:ADTRACE PT:Applying publisher filter.
[05/26/08 13:56:09.286]:ADTRACE PT:Publisher processing check-password for .
[05/26/08 13:56:09.286]:ADTRACE PT:Applying command transformation policies.
[05/26/08 13:56:09.286]:ADTRACE PT:Applying policy: %+C%14C'A set of
rules that implement the user name mapping options'%-C.
[05/26/08 13:56:09.286]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.286]:ADTRACE PT: Evaluating selection criteria for
rule 'consider user objects when name mapping is enabled'.
[05/26/08 13:56:09.286]:ADTRACE PT: (if-class-name not-equal
"User") = TRUE.
[05/26/08 13:56:09.286]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.286]:ADTRACE PT: Applying rule 'consider user
objects when name mapping is enabled'.
[05/26/08 13:56:09.286]:ADTRACE PT: Action: do-break().
[05/26/08 13:56:09.286]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.286]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.286]:ADTRACE PT:Applying policy: %+C%14CCommand
Transform%-C.
[05/26/08 13:56:09.286]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.286]:ADTRACE PT: Evaluating selection criteria for
rule 'set cached context value on merge'.
[05/26/08 13:56:09.286]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:09.286]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.286]:ADTRACE PT: Evaluating selection criteria for
rule 'Set Equivalent To Me when adding object to a group'.
[05/26/08 13:56:09.287]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:09.287]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.287]:ADTRACE PT: Evaluating selection criteria for
rule 'Remove Equivalent To Me when removing object from a group'.
[05/26/08 13:56:09.287]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:09.287]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.287]:ADTRACE PT: Evaluating selection criteria for
rule 'remove managed attributes when object disassociated'.
[05/26/08 13:56:09.287]:ADTRACE PT: (if-operation equal
"remove-association") = FALSE.
[05/26/08 13:56:09.287]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.287]:ADTRACE PT: Evaluating selection criteria for
rule 'Prevent unassociated users from being removed from groups'.
[05/26/08 13:56:09.287]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:09.287]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.287]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.287]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.287]:ADTRACE PT:Applying XSLT policy:
%+C%14CCommand+Transform+SS%-C.
[05/26/08 13:56:09.287]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.288]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.288]:ADTRACE PT:Applying policy:
%+C%14CPassword(Pub)-Default Password Policy%-C.
[05/26/08 13:56:09.288]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.288]:ADTRACE PT: Evaluating selection criteria for
rule 'On User add, provide default password of @Dirxml1 if no password
exists'.
[05/26/08 13:56:09.288]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:09.288]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.288]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.288]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.288]:ADTRACE PT:Applying policy: %+C%14C'Publish
Passwords'%-C.
[05/26/08 13:56:09.288]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.288]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to Identity Manager data store when
adding a object'.
[05/26/08 13:56:09.288]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:09.288]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.288]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the Identity Manager data
store'.
[05/26/08 13:56:09.288]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:09.288]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.288]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.289]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.289]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NMAS distribution password'%-C.
[05/26/08 13:56:09.289]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.289]:ADTRACE PT: Evaluating selection criteria for
rule 'Add nspmDistributionAttribute attribute to add operation'.
[05/26/08 13:56:09.289]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:09.289]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.289]:ADTRACE PT: Evaluating selection criteria for
rule 'Change modify-password operations to a modify'.
[05/26/08 13:56:09.289]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:09.289]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.289]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.289]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.289]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NDS password.'%-C.
[05/26/08 13:56:09.289]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.289]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to NDS password'.
[05/26/08 13:56:09.289]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:09.289]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.290]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the NDS password'.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.290]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.290]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.290]:ADTRACE PT:Applying policy: %+C%14C'Publish
password payloads'%-C.
[05/26/08 13:56:09.290]:ADTRACE PT: Applying to check-password #1.
[05/26/08 13:56:09.290]:ADTRACE PT: Evaluating selection criteria for
rule 'Add operation-data element to password operations'.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.290]:ADTRACE PT: Evaluating selection criteria for
rule 'Add payload data to password operations'.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal
"addPayloadToPassword") = FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:09.290]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.290]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.291]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<input>
<check-password><!-- content suppressed --></check-password>
</input>
</nds>
[05/26/08 13:56:09.291]:ADTRACE PT:Filtering out notification-only
attributes.
[05/26/08 13:56:09.291]:ADTRACE PT:Pumping XDS to eDirectory.
[05/26/08 13:56:09.291]:ADTRACE PT:Performing operation check-password for .
[05/26/08 13:56:09.470]:ADTRACE ST:SubscriptionShim.execute() returned:
[05/26/08 13:56:09.470]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="retry" type="remoteloader">No connection to remote
loader</status>
</output>
</nds>
[05/26/08 13:56:09.471]:ADTRACE ST:Requesting 30 second retry delay.
[05/26/08 13:56:09.471]:ADTRACE ST:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Subscriber
Status: Retry
Message: Code(-9006) The driver returned a "retry" status
indicating that the operation should be retried later. Detail from
driver: No connection to remote loader
[05/26/08 13:56:09.762]:ADTRACE PT:Fixing up association references.
[05/26/08 13:56:09.762]:ADTRACE PT:Applying schema mapping policies to
output.
[05/26/08 13:56:09.762]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:09.762]:ADTRACE PT:Applying output transformation policies.
[05/26/08 13:56:09.762]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in Active Directory.'%-C.
[05/26/08 13:56:09.762]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:09.762]:ADTRACE PT: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:09.762]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.762]:ADTRACE PT: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:09.762]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:09.762]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:09.762]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.762]:ADTRACE PT: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:09.763]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:09.763]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:09.763]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.763]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:09.763]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:09.763]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:09.763]:ADTRACE PT: Rule selected.
[05/26/08 13:56:09.763]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:09.763]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:09.763]:ADTRACE PT: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:09.763]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:09.763]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.763]:ADTRACE PT: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:09.763]:ADTRACE PT: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:09.763]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.763]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.764]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"></status>
</output>
</nds>
[05/26/08 13:56:09.764]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password publications'%-C.
[05/26/08 13:56:09.764]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:09.764]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:09.764]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:09.764]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:09.764]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-publish-status") = FALSE.
[05/26/08 13:56:09.764]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:09.764]:ADTRACE PT:Policy returned:
[05/26/08 13:56:09.764]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"></status>
</output>
</nds>
[05/26/08 13:56:09.764]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"></status>
</output>
</nds>
[05/26/08 13:56:09.764]:ADTRACE PT:Remote Interface Driver: Sending...
[05/26/08 13:56:09.765]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:56:09.765]:ADTRACE PT:Remote Interface Driver: Document sent.
[05/26/08 13:56:09.765]:ADTRACE PT:Remote Interface Driver: Sending...
[05/26/08 13:56:09.766]:ADTRACE PT:
<top>
<driver-init>
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<init-params src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory">
<authentication-info>
<server>172.31.1.24</server>
<user>.tse.local/IDMUser</user>
<password><!-- content suppressed --></password>
</authentication-info>
<driver-options>
<auth-options display-name="Show authentication
options">show</auth-options>
<auth-method display-name="Authentication
Method">Negotiate</auth-method>
<signing display-name="Digitally sign
communications">no</signing>
<sealing display-name="Digitally sign and seal
communications">no</sealing>
<use-ssl display-name="Use SSL for encryption">no</use-ssl>
<impersonation display-name="Logon and
impersonate">yes</impersonation>
<xchg-options display-name="Show Microsoft Exchange
options">show</xchg-options>
<exch-api-type display-name="Exchange Management interface
type (use-cdoexm/use-post-cdoexm)">default</exch-api-type>
<exch-move display-name="Allow Exchange mailbox move
(yes/no)">no</exch-move>
<exch-delete display-name="Allow Exchange mailbox delete
(yes/no)">no</exch-delete>
<access-options display-name="Show access
options">show</access-options>
<pollingInterval display-name="Driver Polling
Interval">1</pollingInterval>
<pub-heartbeat-interval display-name="Publisher heartbeat
interval">0</pub-heartbeat-interval>
<pub-password-expire-time display-name="Password Sync
Timeout (minutes)">5</pub-password-expire-time>
<search-domain-scope display-name="Search domain
scope">no</search-domain-scope>
<retry-ldap-auth-unknown display-name="Retry LDAP Auth
unknown error">no</retry-ldap-auth-unknown>
<enable-incremental-values display-name="Enable DirSync
Incremental Values">no</enable-incremental-values>
</driver-options>
</init-params>
</input>
</nds>
</driver-init>
<subscriber-init>
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<init-params src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory\Subscriber">
<authentication-info>
<server>172.31.1.24</server>
<user>.tse.local/IDMUser</user>
<password><!-- content suppressed --></password>
</authentication-info>
<driver-filter>
<allow-class class-name="group">
<allow-attr attr-name="description"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="L"/>
<allow-attr attr-name="member"/>
<allow-attr attr-name="managedBy"/>
</allow-class>
<allow-class class-name="organizationalUnit">
<allow-attr attr-name="description"/>
</allow-class>
<allow-class class-name="user">
<allow-attr attr-name="description"/>
<allow-attr attr-name="facsimileTelephoneNumber"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="givenName"/>
<allow-attr attr-name="initials"/>
<allow-attr attr-name="mail"/>
<allow-attr attr-name="physicalDeliveryOfficeName"/>
<allow-attr attr-name="logonHours"/>
<allow-attr attr-name="dirxml-uACAccountDisable"/>
<allow-attr attr-name="l"/>
<allow-attr attr-name="postalCode"/>
<allow-attr attr-name="postOfficeBox"/>
<allow-attr attr-name="st"/>
<allow-attr attr-name="streetAddress"/>
<allow-attr attr-name="sn"/>
<allow-attr attr-name="telephoneNumber"/>
<allow-attr attr-name="title"/>
</allow-class>
</driver-filter>
</init-params>
</input>
</nds>
</subscriber-init>
<publisher-init>
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<init-params src-dn="\IDMEDIR\IDM Driver Set\Identity Manager
Drivers\Active Directory\Publisher">
<authentication-info>
<server>172.31.1.24</server>
<user>.tse.local/IDMUser</user>
<password><!-- content suppressed --></password>
</authentication-info>
<driver-filter>
<allow-class class-name="group">
<allow-attr attr-name="description"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="L"/>
<allow-attr attr-name="member"/>
<allow-attr attr-name="managedBy"/>
</allow-class>
<allow-class class-name="organizationalUnit">
<allow-attr attr-name="description"/>
</allow-class>
<allow-class class-name="user">
<allow-attr attr-name="description"/>
<allow-attr attr-name="sAMAccountName"/>
<allow-attr attr-name="facsimileTelephoneNumber"/>
<allow-attr attr-name="displayName"/>
<allow-attr attr-name="givenName"/>
<allow-attr attr-name="initials"/>
<allow-attr attr-name="mail"/>
<allow-attr attr-name="physicalDeliveryOfficeName"/>
<allow-attr attr-name="logonHours"/>
<allow-attr attr-name="dirxml-uACAccountDisable"/>
<allow-attr attr-name="l"/>
<allow-attr attr-name="postalCode"/>
<allow-attr attr-name="postOfficeBox"/>
<allow-attr attr-name="st"/>
<allow-attr attr-name="streetAddress"/>
<allow-attr attr-name="sn"/>
<allow-attr attr-name="telephoneNumber"/>
<allow-attr attr-name="title"/>
</allow-class>
</driver-filter>
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
</publisher-init>
</top>
[05/26/08 13:56:10.194]:ADTRACE PT:Remote Interface Driver: Document sent.
[05/26/08 13:56:10.202]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:10.203]:ADTRACE :
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</output>
</nds>
[05/26/08 13:56:10.203]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:10.203]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:10.203]:ADTRACE PT:Receiving DOM document from application.
[05/26/08 13:56:10.203]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.203]:ADTRACE PT:Applying input transformation policies.
[05/26/08 13:56:10.203]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:10.204]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.204]:ADTRACE PT: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:10.204]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.204]:ADTRACE PT: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:10.204]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:10.204]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:10.204]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.206]:ADTRACE PT: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:10.206]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:10.207]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:10.207]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.207]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:10.207]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:10.207]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:10.207]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.207]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:10.207]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:10.207]:ADTRACE PT: Applying to init-params #2.
[05/26/08 13:56:10.207]:ADTRACE PT: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:10.207]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.207]:ADTRACE PT: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:10.207]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:10.207]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:10.207]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.207]:ADTRACE PT: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:10.207]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:10.207]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:10.208]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.208]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:10.208]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:10.208]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:10.208]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.208]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:10.208]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:10.208]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.208]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.208]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:10.208]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.208]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:10.208]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:10.208]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:10.209]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.209]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:10.209]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.209]:ADTRACE PT: Applying to init-params #2.
[05/26/08 13:56:10.209]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:10.209]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.209]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:10.209]:ADTRACE PT: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:10.209]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.210]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.210]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.210]:ADTRACE PT:Applying schema mapping policies to
input.
[05/26/08 13:56:10.210]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:10.210]:ADTRACE PT:Resolving association references.
[05/26/08 13:56:10.210]:ADTRACE PT:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverStorage.
[05/26/08 13:56:10.211]:ADTRACE PT:Writing driver state.
[05/26/08 13:56:10.211]:ADTRACE PT:Writing XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverStorage.
[05/26/08 13:56:10.213]:ADTRACE PT:Applying event transformation policies.
[05/26/08 13:56:10.213]:ADTRACE PT:Applying policy: %+C%14CEvent
Transform%-C.
[05/26/08 13:56:10.213]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.213]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for move validation'.
[05/26/08 13:56:10.213]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:10.213]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.213]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for rename validation'.
[05/26/08 13:56:10.213]:ADTRACE PT: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:10.213]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.213]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename validation'.
[05/26/08 13:56:10.213]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:10.213]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.214]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename cached context update'.
[05/26/08 13:56:10.214]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:10.214]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.214]:ADTRACE PT: Evaluating selection criteria for
rule 'veto move'.
[05/26/08 13:56:10.214]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:10.214]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.214]:ADTRACE PT: Applying to init-params #2.
[05/26/08 13:56:10.214]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for move validation'.
[05/26/08 13:56:10.214]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:10.214]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.214]:ADTRACE PT: Evaluating selection criteria for
rule 'setup for rename validation'.
[05/26/08 13:56:10.214]:ADTRACE PT: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:10.214]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.214]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename validation'.
[05/26/08 13:56:10.214]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:10.214]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.214]:ADTRACE PT: Evaluating selection criteria for
rule 'move or rename cached context update'.
[05/26/08 13:56:10.214]:ADTRACE PT: (if-local-variable
'cached-object-value' match ".*") = FALSE.
[05/26/08 13:56:10.214]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.214]:ADTRACE PT: Evaluating selection criteria for
rule 'veto move'.
[05/26/08 13:56:10.215]:ADTRACE PT: (if-operation equal "move") =
FALSE.
[05/26/08 13:56:10.215]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.215]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.215]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.215]:ADTRACE PT:Applying publisher filter.
[05/26/08 13:56:10.215]:ADTRACE PT:Publisher processing status for .
[05/26/08 13:56:10.215]:ADTRACE PT:Applying command transformation policies.
[05/26/08 13:56:10.215]:ADTRACE PT:Applying policy: %+C%14C'A set of
rules that implement the user name mapping options'%-C.
[05/26/08 13:56:10.215]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.215]:ADTRACE PT: Evaluating selection criteria for
rule 'consider user objects when name mapping is enabled'.
[05/26/08 13:56:10.215]:ADTRACE PT: (if-class-name not-equal
"User") = TRUE.
[05/26/08 13:56:10.215]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.216]:ADTRACE PT: Applying rule 'consider user
objects when name mapping is enabled'.
[05/26/08 13:56:10.216]:ADTRACE PT: Action: do-break().
[05/26/08 13:56:10.216]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.216]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.216]:ADTRACE PT:Applying policy: %+C%14CCommand
Transform%-C.
[05/26/08 13:56:10.216]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.216]:ADTRACE PT: Evaluating selection criteria for
rule 'set cached context value on merge'.
[05/26/08 13:56:10.216]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.216]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.216]:ADTRACE PT: Evaluating selection criteria for
rule 'Set Equivalent To Me when adding object to a group'.
[05/26/08 13:56:10.216]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:10.216]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.216]:ADTRACE PT: Evaluating selection criteria for
rule 'Remove Equivalent To Me when removing object from a group'.
[05/26/08 13:56:10.216]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:10.216]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.216]:ADTRACE PT: Evaluating selection criteria for
rule 'remove managed attributes when object disassociated'.
[05/26/08 13:56:10.216]:ADTRACE PT: (if-operation equal
"remove-association") = FALSE.
[05/26/08 13:56:10.216]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.216]:ADTRACE PT: Evaluating selection criteria for
rule 'Prevent unassociated users from being removed from groups'.
[05/26/08 13:56:10.217]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.217]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.217]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.217]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.217]:ADTRACE PT:Applying XSLT policy:
%+C%14CCommand+Transform+SS%-C.
[05/26/08 13:56:10.217]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.217]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.217]:ADTRACE PT:Applying policy:
%+C%14CPassword(Pub)-Default Password Policy%-C.
[05/26/08 13:56:10.217]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.217]:ADTRACE PT: Evaluating selection criteria for
rule 'On User add, provide default password of @Dirxml1 if no password
exists'.
[05/26/08 13:56:10.217]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.217]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.218]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.218]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.218]:ADTRACE PT:Applying policy: %+C%14C'Publish
Passwords'%-C.
[05/26/08 13:56:10.218]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.218]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to Identity Manager data store when
adding a object'.
[05/26/08 13:56:10.218]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:10.218]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.218]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the Identity Manager data
store'.
[05/26/08 13:56:10.218]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:10.218]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.218]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.218]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.218]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NMAS distribution password'%-C.
[05/26/08 13:56:10.218]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.218]:ADTRACE PT: Evaluating selection criteria for
rule 'Add nspmDistributionAttribute attribute to add operation'.
[05/26/08 13:56:10.218]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:10.218]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.219]:ADTRACE PT: Evaluating selection criteria for
rule 'Change modify-password operations to a modify'.
[05/26/08 13:56:10.219]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:10.219]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.219]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.219]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.219]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NDS password.'%-C.
[05/26/08 13:56:10.219]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.219]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to NDS password'.
[05/26/08 13:56:10.219]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:10.219]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.219]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the NDS password'.
[05/26/08 13:56:10.219]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:10.219]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.219]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.219]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.219]:ADTRACE PT:Applying policy: %+C%14C'Publish
password payloads'%-C.
[05/26/08 13:56:10.220]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.220]:ADTRACE PT: Evaluating selection criteria for
rule 'Add operation-data element to password operations'.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.220]:ADTRACE PT: Evaluating selection criteria for
rule 'Add payload data to password operations'.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal
"addPayloadToPassword") = FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.220]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.220]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.220]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<status event-id="report status" level="success">Remote driver
successfully started.</status>
</input>
</nds>
[05/26/08 13:56:10.220]:ADTRACE PT:Filtering out notification-only
attributes.
[05/26/08 13:56:10.220]:ADTRACE PT:Pumping XDS to eDirectory.
[05/26/08 13:56:10.220]:ADTRACE PT:Performing operation status for .
[05/26/08 13:56:10.221]:ADTRACE PT:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Publisher
Status: Success
Message: Remote driver successfully started.
[05/26/08 13:56:10.221]:ADTRACE PT:Applying publisher filter.
[05/26/08 13:56:10.221]:ADTRACE PT:Publisher processing init-params for .
[05/26/08 13:56:10.221]:ADTRACE PT:Applying command transformation policies.
[05/26/08 13:56:10.221]:ADTRACE PT:Applying policy: %+C%14C'A set of
rules that implement the user name mapping options'%-C.
[05/26/08 13:56:10.221]:ADTRACE PT: Applying to init-params #1.
[05/26/08 13:56:10.221]:ADTRACE PT: Evaluating selection criteria for
rule 'consider user objects when name mapping is enabled'.
[05/26/08 13:56:10.221]:ADTRACE PT: (if-class-name not-equal
"User") = TRUE.
[05/26/08 13:56:10.221]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.221]:ADTRACE PT: Applying rule 'consider user
objects when name mapping is enabled'.
[05/26/08 13:56:10.221]:ADTRACE PT: Action: do-break().
[05/26/08 13:56:10.221]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.221]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.222]:ADTRACE PT:Applying policy: %+C%14CCommand
Transform%-C.
[05/26/08 13:56:10.222]:ADTRACE PT: Applying to init-params #1.
[05/26/08 13:56:10.222]:ADTRACE PT: Evaluating selection criteria for
rule 'set cached context value on merge'.
[05/26/08 13:56:10.222]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.222]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.222]:ADTRACE PT: Evaluating selection criteria for
rule 'Set Equivalent To Me when adding object to a group'.
[05/26/08 13:56:10.222]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:10.222]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.222]:ADTRACE PT: Evaluating selection criteria for
rule 'Remove Equivalent To Me when removing object from a group'.
[05/26/08 13:56:10.222]:ADTRACE PT: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:10.222]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.222]:ADTRACE PT: Evaluating selection criteria for
rule 'remove managed attributes when object disassociated'.
[05/26/08 13:56:10.222]:ADTRACE PT: (if-operation equal
"remove-association") = FALSE.
[05/26/08 13:56:10.222]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.222]:ADTRACE PT: Evaluating selection criteria for
rule 'Prevent unassociated users from being removed from groups'.
[05/26/08 13:56:10.222]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.222]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.222]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.223]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.223]:ADTRACE PT:Applying XSLT policy:
%+C%14CCommand+Transform+SS%-C.
[05/26/08 13:56:10.223]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.223]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.223]:ADTRACE PT:Applying policy:
%+C%14CPassword(Pub)-Default Password Policy%-C.
[05/26/08 13:56:10.223]:ADTRACE PT: Applying to init-params #1.
[05/26/08 13:56:10.223]:ADTRACE PT: Evaluating selection criteria for
rule 'On User add, provide default password of @Dirxml1 if no password
exists'.
[05/26/08 13:56:10.223]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.224]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.224]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.224]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.224]:ADTRACE PT:Applying policy: %+C%14C'Publish
Passwords'%-C.
[05/26/08 13:56:10.224]:ADTRACE PT: Applying to init-params #1.
[05/26/08 13:56:10.224]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to Identity Manager data store when
adding a object'.
[05/26/08 13:56:10.224]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:10.224]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.224]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the Identity Manager data
store'.
[05/26/08 13:56:10.224]:ADTRACE PT: (if-global-variable
'enable-password-publish' equal "false") = FALSE.
[05/26/08 13:56:10.224]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.224]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.224]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.225]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NMAS distribution password'%-C.
[05/26/08 13:56:10.225]:ADTRACE PT: Applying to init-params #1.
[05/26/08 13:56:10.225]:ADTRACE PT: Evaluating selection criteria for
rule 'Add nspmDistributionAttribute attribute to add operation'.
[05/26/08 13:56:10.225]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:10.225]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.225]:ADTRACE PT: Evaluating selection criteria for
rule 'Change modify-password operations to a modify'.
[05/26/08 13:56:10.225]:ADTRACE PT: (if-global-variable
'publish-password-to-dp' equal "true") = FALSE.
[05/26/08 13:56:10.225]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.225]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.225]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.225]:ADTRACE PT:Applying policy: %+C%14C'Publish
passwords to NDS password.'%-C.
[05/26/08 13:56:10.225]:ADTRACE PT: Applying to init-params #1.
[05/26/08 13:56:10.225]:ADTRACE PT: Evaluating selection criteria for
rule 'Block publishing passwords to NDS password'.
[05/26/08 13:56:10.225]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:10.225]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.225]:ADTRACE PT: Evaluating selection criteria for
rule 'Block sending modify-password changes to the NDS password'.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-global-variable
'publish-password-to-nds' equal "false") = FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.226]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.226]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.226]:ADTRACE PT:Applying policy: %+C%14C'Publish
password payloads'%-C.
[05/26/08 13:56:10.226]:ADTRACE PT: Applying to init-params #1.
[05/26/08 13:56:10.226]:ADTRACE PT: Evaluating selection criteria for
rule 'Add operation-data element to password operations'.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.226]:ADTRACE PT: Evaluating selection criteria for
rule 'Add payload data to password operations'.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal
"addPayloadToPassword") = FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:10.226]:ADTRACE PT: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:10.227]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.227]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.227]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x" remote-interface="yes">
<input>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</input>
</nds>
[05/26/08 13:56:10.227]:ADTRACE PT:Filtering out notification-only
attributes.
[05/26/08 13:56:10.227]:ADTRACE PT:Pumping XDS to eDirectory.
[05/26/08 13:56:10.227]:ADTRACE PT:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Publisher
Status: Success
[05/26/08 13:56:10.227]:ADTRACE PT:Fixing up association references.
[05/26/08 13:56:10.227]:ADTRACE PT:Applying schema mapping policies to
output.
[05/26/08 13:56:10.227]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:10.228]:ADTRACE PT:Applying output transformation policies.
[05/26/08 13:56:10.228]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in Active Directory.'%-C.
[05/26/08 13:56:10.228]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.228]:ADTRACE PT: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:10.228]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.228]:ADTRACE PT: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:10.228]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:10.228]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:10.228]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.228]:ADTRACE PT: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:10.228]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:10.228]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:10.228]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.228]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:10.228]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:10.228]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:10.228]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.228]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:10.229]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:10.229]:ADTRACE PT: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:10.229]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.229]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.229]:ADTRACE PT: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:10.229]:ADTRACE PT: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:10.229]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.229]:ADTRACE PT: Applying to status #2.
[05/26/08 13:56:10.229]:ADTRACE PT: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:10.229]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.229]:ADTRACE PT: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:10.229]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:10.229]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:10.229]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.229]:ADTRACE PT: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:10.229]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:10.229]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:10.230]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.230]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:10.230]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:10.230]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:10.230]:ADTRACE PT: Rule selected.
[05/26/08 13:56:10.230]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:10.230]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:10.230]:ADTRACE PT: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:10.230]:ADTRACE PT: (if-operation equal "add") = FALSE.
[05/26/08 13:56:10.230]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.230]:ADTRACE PT: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:10.230]:ADTRACE PT: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:10.230]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.230]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.230]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="report status" level="success"></status>
<status event-id="write state"
level="success"><application>DirXML</application>
<module>Active Directory</module>
<object-dn></object-dn>
<component>Publisher</component>
</status>
</output>
</nds>
[05/26/08 13:56:10.231]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password publications'%-C.
[05/26/08 13:56:10.231]:ADTRACE PT: Applying to status #1.
[05/26/08 13:56:10.231]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:10.231]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:10.231]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:10.231]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-publish-status") = FALSE.
[05/26/08 13:56:10.231]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.231]:ADTRACE PT: Applying to status #2.
[05/26/08 13:56:10.231]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:10.231]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:10.231]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:10.231]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-publish-status") = FALSE.
[05/26/08 13:56:10.231]:ADTRACE PT: Rule rejected.
[05/26/08 13:56:10.231]:ADTRACE PT:Policy returned:
[05/26/08 13:56:10.232]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="report status" level="success"></status>
<status event-id="write state"
level="success"><application>DirXML</application>
<module>Active Directory</module>
<object-dn></object-dn>
<component>Publisher</component>
</status>
</output>
</nds>
[05/26/08 13:56:10.232]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="report status" level="success"></status>
<status event-id="write state"
level="success"><application>DirXML</application>
<module>Active Directory</module>
<object-dn></object-dn>
<component>Publisher</component>
</status>
</output>
</nds>
[05/26/08 13:56:39.552]:ADTRACE ST:Submitting identification query to
subscriber shim:
[05/26/08 13:56:39.552]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query event-id="query-driver-ident" scope="entry">
<search-class class-name="__driver_identification_class__"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:39.552]:ADTRACE ST:Remote Interface Driver: Sending...
[05/26/08 13:56:39.552]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query event-id="query-driver-ident" scope="entry">
<search-class class-name="__driver_identification_class__"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:39.552]:ADTRACE ST:Remote Interface Driver: Document sent.
[05/26/08 13:56:39.602]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:39.602]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="__driver_identification_class__">
<attr attr-name="driver-id">
<value type="string">AD</value>
</attr>
<attr attr-name="driver-version">
<value type="string">3.5.1</value>
</attr>
<attr attr-name="min-activation-version">
<value type="string">5</value>
</attr>
<attr attr-name="query-ex-supported">
<value type="state">true</value>
</attr>
</instance>
<status event-id="query-driver-ident" level="success"/>
</output>
</nds>
[05/26/08 13:56:39.603]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:39.603]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:39.603]:ADTRACE ST:SubscriptionShim.execute() returned:
[05/26/08 13:56:39.603]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="__driver_identification_class__">
<attr attr-name="driver-id">
<value type="string">AD</value>
</attr>
<attr attr-name="driver-version">
<value type="string">3.5.1</value>
</attr>
<attr attr-name="min-activation-version">
<value type="string">5</value>
</attr>
<attr attr-name="query-ex-supported">
<value type="state">true</value>
</attr>
</instance>
<status event-id="query-driver-ident" level="success"/>
</output>
</nds>
[05/26/08 13:56:39.697]:ADTRACE ST:Start transaction.
[05/26/08 13:56:39.697]:ADTRACE ST:Processing events for transaction.
[05/26/08 13:56:39.698]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<sync cached-time="20080526115506.472Z" class-name="User"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238"
timestamp="0#0">
<association state="manual"></association>
</sync>
</input>
</nds>
[05/26/08 13:56:39.698]:ADTRACE ST:No event transformation policies.
[05/26/08 13:56:39.698]:ADTRACE ST:Subscriber processing sync for
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:39.698]:ADTRACE ST:Reading relevant attributes from
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:39.699]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User"
dest-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" dest-entry-id="35238"
scope="entry">
<read-attr attr-name="Description"/>
<read-attr attr-name="Facsimile Telephone Number"/>
<read-attr attr-name="Full Name"/>
<read-attr attr-name="Given Name"/>
<read-attr attr-name="Initials"/>
<read-attr attr-name="Internet EMail Address"/>
<read-attr attr-name="L"/>
<read-attr attr-name="Login Allowed Time Map"/>
<read-attr attr-name="Login Disabled"/>
<read-attr attr-name="nspmDistributionPassword"/>
<read-attr attr-name="Physical Delivery Office Name"/>
<read-attr attr-name="Postal Code"/>
<read-attr attr-name="Postal Office Box"/>
<read-attr attr-name="S"/>
<read-attr attr-name="SA"/>
<read-attr attr-name="Surname"/>
<read-attr attr-name="Telephone Number"/>
<read-attr attr-name="Title"/>
</query>
</input>
</nds>
[05/26/08 13:56:39.699]:ADTRACE ST:Pumping XDS to eDirectory.
[05/26/08 13:56:39.699]:ADTRACE ST:Performing operation query for
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:39.703]:ADTRACE ST:Read result:
[05/26/08 13:56:39.703]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="User"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<association state="manual"></association>
<attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</attr>
<attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</attr>
<attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</attr>
<attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</attr>
<attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</attr>
</instance>
<status level="success"></status>
</output>
</nds>
[05/26/08 13:56:39.703]:ADTRACE ST:Synthetic add:
[05/26/08 13:56:39.704]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<add class-name="User" event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<association state="manual"></association>
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
</add>
<status level="success"></status>
</output>
</nds>
[05/26/08 13:56:39.704]:ADTRACE ST:Applying object matching policies.
[05/26/08 13:56:39.704]:ADTRACE ST:Applying policy: %+C%14C'Find
matching object in Active Directory'%-C.
[05/26/08 13:56:39.704]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:39.704]:ADTRACE ST: Evaluating selection criteria for
rule 'remember relative position in hierarchy'.
[05/26/08 13:56:39.704]:ADTRACE ST: (if-src-dn in-subtree "Users")
= TRUE.
[05/26/08 13:56:39.704]:ADTRACE ST: Rule selected.
[05/26/08 13:56:39.705]:ADTRACE ST: Applying rule 'remember relative
position in hierarchy'.
[05/26/08 13:56:39.705]:ADTRACE ST: Action:
do-set-op-property("unmatched-src-dn",token-unmatched-src-dn(convert="true")).
[05/26/08 13:56:39.705]:ADTRACE ST:
arg-string(token-unmatched-src-dn(convert="true"))
[05/26/08 13:56:39.705]:ADTRACE ST:
token-unmatched-src-dn(convert="true")
[05/26/08 13:56:39.705]:ADTRACE ST: Token Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:39.705]:ADTRACE ST: Arg Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:39.705]:ADTRACE ST: Evaluating selection criteria for
rule 'veto out-of-scope events'.
[05/26/08 13:56:39.705]:ADTRACE ST: (if-op-property
'unmatched-src-dn' not-available) = FALSE.
[05/26/08 13:56:39.705]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:39.705]:ADTRACE ST: Evaluating selection criteria for
rule 'generate full name if not in Identity Vault'.
[05/26/08 13:56:39.705]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:39.705]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:39.705]:ADTRACE ST: (if-attr 'Full Name'
not-available) = FALSE.
[05/26/08 13:56:39.705]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:39.705]:ADTRACE ST: Evaluating selection criteria for
rule 'match users based on NT logon name'.
[05/26/08 13:56:39.705]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:39.705]:ADTRACE ST: (if-global-variable
'LogonNameMap' equal "true") = TRUE.
[05/26/08 13:56:39.705]:ADTRACE ST: Rule selected.
[05/26/08 13:56:39.705]:ADTRACE ST: Applying rule 'match users based
on NT logon name'.
[05/26/08 13:56:39.705]:ADTRACE ST: Action:
do-find-matching-object(scope="subtree",arg-dn("OU=SynchronizedUsers,DC=tse,DC=local"),arg-match-attr("DirXML-ADAliasName",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
[05/26/08 13:56:39.706]:ADTRACE ST:
arg-dn("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:39.706]:ADTRACE ST:
token-text("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:39.706]:ADTRACE ST: Arg Value:
"OU=SynchronizedUsers,DC=tse,DC=local".
[05/26/08 13:56:39.706]:ADTRACE ST:
arg-match-attr("DirXML-ADAliasName",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:39.706]:ADTRACE ST:
arg-string(token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:39.706]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:39.706]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:39.706]:ADTRACE ST: token-src-name()
[05/26/08 13:56:39.706]:ADTRACE ST: Token Value:
"teststud1".
[05/26/08 13:56:39.706]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:39.706]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:39.706]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:39.706]:ADTRACE ST: Query from policy
[05/26/08 13:56:39.707]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" scope="subtree">
<search-class class-name="User"/>
<search-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:39.707]:ADTRACE ST: Fixing up association references.
[05/26/08 13:56:39.707]:ADTRACE ST: Applying schema mapping
policies to output.
[05/26/08 13:56:39.707]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:39.707]:ADTRACE ST: Mapping attr-name
'DirXML-ADAliasName' to 'sAMAccountName'.
[05/26/08 13:56:39.707]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:39.707]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:39.707]:ADTRACE ST: Applying output
transformation policies.
[05/26/08 13:56:39.707]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in
Active Directory.'%-C.
[05/26/08 13:56:39.707]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:39.707]:ADTRACE ST: Evaluating selection
criteria for rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:39.707]:ADTRACE ST: Rule selected.
[05/26/08 13:56:39.708]:ADTRACE ST: Applying rule 'Street
Address: Convert LF to CR-LF'.
[05/26/08 13:56:39.708]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:39.708]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:39.708]:ADTRACE ST: Rule selected.
[05/26/08 13:56:39.708]:ADTRACE ST: Applying rule
'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:39.708]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:39.708]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:39.708]:ADTRACE ST: Rule selected.
[05/26/08 13:56:39.708]:ADTRACE ST: Applying rule
'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:39.708]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:39.708]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:39.708]:ADTRACE ST: Rule selected.
[05/26/08 13:56:39.708]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:39.708]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:39.708]:ADTRACE ST: Evaluating selection
criteria for rule 'Add: User - convert multi-valued Telephone to single
value'.
[05/26/08 13:56:39.708]:ADTRACE ST: (if-operation equal
"add") = FALSE.
[05/26/08 13:56:39.708]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:39.709]:ADTRACE ST: Evaluating selection
criteria for rule 'update Active Directory logon name'.
[05/26/08 13:56:39.709]:ADTRACE ST: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:39.709]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:39.709]:ADTRACE ST: Policy returned:
[05/26/08 13:56:39.709]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:39.709]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password publications'%-C.
[05/26/08 13:56:39.709]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:39.709]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:39.709]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:39.709]:ADTRACE ST: (if-operation equal
"status") = FALSE.
[05/26/08 13:56:39.709]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:39.709]:ADTRACE ST: Policy returned:
[05/26/08 13:56:39.710]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:39.710]:ADTRACE ST: Submitting document to
subscriber shim:
[05/26/08 13:56:39.710]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:39.711]:ADTRACE ST: Remote Interface Driver:
Sending...
[05/26/08 13:56:39.711]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:39.711]:ADTRACE ST: Remote Interface Driver:
Document sent.
[05/26/08 13:56:40.252]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:40.252]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.252]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:40.252]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:40.252]:ADTRACE ST: SubscriptionShim.execute()
returned:
[05/26/08 13:56:40.252]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.252]:ADTRACE ST: Applying input transformation
policies.
[05/26/08 13:56:40.252]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in the
Identity Vault.'%-C.
[05/26/08 13:56:40.253]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:40.253]:ADTRACE ST: Evaluating selection
criteria for rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:40.253]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.253]:ADTRACE ST: Applying rule
'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:40.253]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:40.253]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:40.253]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.253]:ADTRACE ST: Applying rule
'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:40.253]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:40.253]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:40.253]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.253]:ADTRACE ST: Applying rule
'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:40.253]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:40.253]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:40.253]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.253]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:40.254]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:40.254]:ADTRACE ST: Policy returned:
[05/26/08 13:56:40.254]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.254]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password subscriptions'%-C.
[05/26/08 13:56:40.254]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:40.254]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:40.254]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:40.254]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:40.254]:ADTRACE ST: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:40.254]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.254]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on failure to reset connected system
password using the Identity Manager data store password'.
[05/26/08 13:56:40.254]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:40.255]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:40.255]:ADTRACE ST: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:40.255]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.255]:ADTRACE ST: Policy returned:
[05/26/08 13:56:40.255]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.255]:ADTRACE ST: Applying schema mapping
policies to input.
[05/26/08 13:56:40.255]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:40.255]:ADTRACE ST: Resolving association references.
[05/26/08 13:56:40.255]:ADTRACE ST: Query from policy result
[05/26/08 13:56:40.255]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.256]:ADTRACE ST: No matches found.
[05/26/08 13:56:40.256]:ADTRACE ST: Evaluating selection criteria for
rule 'match users based on full name'.
[05/26/08 13:56:40.256]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.256]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:40.256]:ADTRACE ST: (if-op-attr 'Full Name'
available) = TRUE.
[05/26/08 13:56:40.256]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.256]:ADTRACE ST: Applying rule 'match users based
on full name'.
[05/26/08 13:56:40.256]:ADTRACE ST: Action:
do-find-matching-object(scope="entry",arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))+"OU=SynchronizedUsers,DC=tse,DC=local")).
[05/26/08 13:56:40.256]:ADTRACE ST:
arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))+"OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:40.256]:ADTRACE ST: token-text("CN=")
[05/26/08 13:56:40.256]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:40.256]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:40.256]:ADTRACE ST: token-attr("Full Name")
[05/26/08 13:56:40.256]:ADTRACE ST: Token Value: "test
tester".
[05/26/08 13:56:40.256]:ADTRACE ST: Arg Value: "test tester".
[05/26/08 13:56:40.256]:ADTRACE ST: Token Value: "test tester".
[05/26/08 13:56:40.257]:ADTRACE ST: token-text(",")
[05/26/08 13:56:40.257]:ADTRACE ST:
token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))
[05/26/08 13:56:40.257]:ADTRACE ST:
token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))
[05/26/08 13:56:40.257]:ADTRACE ST:
token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn"))
[05/26/08 13:56:40.257]:ADTRACE ST:
token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn"))
[05/26/08 13:56:40.257]:ADTRACE ST:
token-op-property("unmatched-src-dn")
[05/26/08 13:56:40.257]:ADTRACE ST: Token Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:40.257]:ADTRACE ST: Arg Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:40.257]:ADTRACE ST: Token Value:
"OU=Testbak,OU=HESOCT".
[05/26/08 13:56:40.257]:ADTRACE ST: Arg Value:
"OU=Testbak,OU=HESOCT".
[05/26/08 13:56:40.257]:ADTRACE ST: Token Value:
"OU=Testbak,OU=HESOCT,".
[05/26/08 13:56:40.257]:ADTRACE ST:
token-text("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:40.257]:ADTRACE ST: Arg Value: "CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local".
[05/26/08 13:56:40.257]:ADTRACE ST: Query from policy
[05/26/08 13:56:40.257]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
scope="entry">
<search-class class-name="User"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:40.258]:ADTRACE ST: Fixing up association references.
[05/26/08 13:56:40.258]:ADTRACE ST: Applying schema mapping
policies to output.
[05/26/08 13:56:40.258]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:40.258]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:40.258]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:40.258]:ADTRACE ST: Applying output
transformation policies.
[05/26/08 13:56:40.258]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in
Active Directory.'%-C.
[05/26/08 13:56:40.258]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:40.258]:ADTRACE ST: Evaluating selection
criteria for rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:40.258]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.258]:ADTRACE ST: Applying rule 'Street
Address: Convert LF to CR-LF'.
[05/26/08 13:56:40.258]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:40.258]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:40.258]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.259]:ADTRACE ST: Applying rule
'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:40.259]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:40.259]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:40.259]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.259]:ADTRACE ST: Applying rule
'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:40.259]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:40.259]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:40.259]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.259]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:40.259]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:40.259]:ADTRACE ST: Evaluating selection
criteria for rule 'Add: User - convert multi-valued Telephone to single
value'.
[05/26/08 13:56:40.259]:ADTRACE ST: (if-operation equal
"add") = FALSE.
[05/26/08 13:56:40.259]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.259]:ADTRACE ST: Evaluating selection
criteria for rule 'update Active Directory logon name'.
[05/26/08 13:56:40.259]:ADTRACE ST: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:40.259]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.259]:ADTRACE ST: Policy returned:
[05/26/08 13:56:40.260]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:40.260]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password publications'%-C.
[05/26/08 13:56:40.260]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:40.260]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:40.260]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:40.260]:ADTRACE ST: (if-operation equal
"status") = FALSE.
[05/26/08 13:56:40.260]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.260]:ADTRACE ST: Policy returned:
[05/26/08 13:56:40.260]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:40.261]:ADTRACE ST: Submitting document to
subscriber shim:
[05/26/08 13:56:40.261]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:40.261]:ADTRACE ST: Remote Interface Driver:
Sending...
[05/26/08 13:56:40.261]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:40.261]:ADTRACE ST: Remote Interface Driver:
Document sent.
[05/26/08 13:56:40.749]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:40.749]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.749]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:40.749]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:40.749]:ADTRACE ST: SubscriptionShim.execute()
returned:
[05/26/08 13:56:40.749]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.750]:ADTRACE ST: Applying input transformation
policies.
[05/26/08 13:56:40.750]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in the
Identity Vault.'%-C.
[05/26/08 13:56:40.750]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:40.750]:ADTRACE ST: Evaluating selection
criteria for rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:40.750]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.750]:ADTRACE ST: Applying rule
'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:40.750]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:40.750]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:40.750]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.750]:ADTRACE ST: Applying rule
'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:40.750]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:40.750]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:40.750]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.750]:ADTRACE ST: Applying rule
'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:40.750]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:40.751]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:40.751]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.751]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:40.751]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:40.751]:ADTRACE ST: Policy returned:
[05/26/08 13:56:40.751]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.751]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password subscriptions'%-C.
[05/26/08 13:56:40.751]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:40.751]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:40.751]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:40.751]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:40.751]:ADTRACE ST: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:40.751]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.752]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on failure to reset connected system
password using the Identity Manager data store password'.
[05/26/08 13:56:40.752]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:40.752]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:40.752]:ADTRACE ST: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:40.752]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.752]:ADTRACE ST: Policy returned:
[05/26/08 13:56:40.752]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.752]:ADTRACE ST: Applying schema mapping
policies to input.
[05/26/08 13:56:40.752]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:40.752]:ADTRACE ST: Resolving association references.
[05/26/08 13:56:40.752]:ADTRACE ST: Query from policy result
[05/26/08 13:56:40.753]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:40.753]:ADTRACE ST: No matches found.
[05/26/08 13:56:40.753]:ADTRACE ST: Evaluating selection criteria for
rule 'match everything else'.
[05/26/08 13:56:40.753]:ADTRACE ST: (if-class-name not-equal
"User") = FALSE.
[05/26/08 13:56:40.753]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.753]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.753]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.754]:ADTRACE ST:No match found.
[05/26/08 13:56:40.754]:ADTRACE ST:Applying object creation policies.
[05/26/08 13:56:40.754]:ADTRACE ST:Applying policy: %+C%14CCreation%-C.
[05/26/08 13:56:40.755]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.755]:ADTRACE ST: Evaluating selection criteria for
rule 'Veto if nspmDistributionPassword is not available'.
[05/26/08 13:56:40.755]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.756]:ADTRACE ST: (if-global-variable
'enable-password-subscribe' equal "true") = TRUE.
[05/26/08 13:56:40.756]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.756]:ADTRACE ST: Applying rule 'Veto if
nspmDistributionPassword is not available'.
[05/26/08 13:56:40.756]:ADTRACE ST: Action:
do-veto-if-op-attr-not-available("nspmDistributionPassword").
[05/26/08 13:56:40.756]:ADTRACE ST: Evaluating selection criteria for
rule 'Create User objects'.
[05/26/08 13:56:40.756]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.756]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.756]:ADTRACE ST: Applying rule 'Create User objects'.
[05/26/08 13:56:40.756]:ADTRACE ST: Action:
do-veto-if-op-attr-not-available("Full Name").
[05/26/08 13:56:40.756]:ADTRACE ST: Action:
do-set-dest-attr-value("DirXML-ADAliasName",token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
[05/26/08 13:56:40.756]:ADTRACE ST:
arg-string(token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())))
[05/26/08 13:56:40.756]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:40.756]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:40.756]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:40.756]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:40.757]:ADTRACE ST: token-src-name()
[05/26/08 13:56:40.757]:ADTRACE ST: Token Value:
"teststud1".
[05/26/08 13:56:40.757]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:40.757]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:40.757]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:40.757]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:40.757]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:40.757]:ADTRACE ST: Action:
do-add-src-attr-value("Object
Class",class-name="User","DirXML-ApplicationAttrs").
[05/26/08 13:56:40.757]:ADTRACE ST:
arg-string("DirXML-ApplicationAttrs")
[05/26/08 13:56:40.757]:ADTRACE ST:
token-text("DirXML-ApplicationAttrs")
[05/26/08 13:56:40.757]:ADTRACE ST: Arg Value:
"DirXML-ApplicationAttrs".
[05/26/08 13:56:40.757]:ADTRACE ST: Action:
do-set-src-attr-value("DirXML-ADAliasName",token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
[05/26/08 13:56:40.757]:ADTRACE ST:
arg-string(token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())))
[05/26/08 13:56:40.757]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:40.757]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:40.758]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:40.758]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:40.758]:ADTRACE ST: token-src-name()
[05/26/08 13:56:40.758]:ADTRACE ST: Token Value:
"teststud1".
[05/26/08 13:56:40.758]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:40.758]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:40.758]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:40.758]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:40.758]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:40.758]:ADTRACE ST: Action:
do-set-dest-password(token-op-attr("Surname")+"-- suppressed --").
[05/26/08 13:56:40.758]:ADTRACE ST:
arg-string(token-op-attr("Surname")+"-- suppressed --")
[05/26/08 13:56:40.758]:ADTRACE ST: token-op-attr("Surname")
[05/26/08 13:56:40.758]:ADTRACE ST: Token Value: "--
suppressed --".
[05/26/08 13:56:40.758]:ADTRACE ST: token-text("-- suppressed --")
[05/26/08 13:56:40.758]:ADTRACE ST: Arg Value: "-- suppressed --".
[05/26/08 13:56:40.758]:ADTRACE ST: Evaluating selection criteria for
rule 'map user name to Windows logon name'.
[05/26/08 13:56:40.758]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-name-auth") = FALSE.
[05/26/08 13:56:40.758]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.758]:ADTRACE ST: Evaluating selection criteria for
rule 'Create Group objects'.
[05/26/08 13:56:40.759]:ADTRACE ST: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:40.759]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.759]:ADTRACE ST: Evaluating selection criteria for
rule 'Identity Vault accounts are enabled if Login Disabled does not exist'.
[05/26/08 13:56:40.759]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.759]:ADTRACE ST: (if-op-attr 'Login Disabled'
not-available) = TRUE.
[05/26/08 13:56:40.759]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.759]:ADTRACE ST: Applying rule 'Identity Vault
accounts are enabled if Login Disabled does not exist'.
[05/26/08 13:56:40.759]:ADTRACE ST: Action:
do-set-dest-attr-value("Login Disabled","false").
[05/26/08 13:56:40.759]:ADTRACE ST: arg-string("false")
[05/26/08 13:56:40.759]:ADTRACE ST: token-text("false")
[05/26/08 13:56:40.759]:ADTRACE ST: Arg Value: "false".
[05/26/08 13:56:40.759]:ADTRACE ST: Evaluating selection criteria for
rule 'default Exchange assignment'.
[05/26/08 13:56:40.759]:ADTRACE ST: (if-global-variable
'ExchMailboxPolicy' equal "policy") = FALSE.
[05/26/08 13:56:40.759]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.759]:ADTRACE ST: Direct command from policy
[05/26/08 13:56:40.759]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="User"
dest-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" dest-entry-id="35238"
event-id="IDMVAULT#20080526115506#1#1">
<modify-attr attr-name="Object Class">
<add-value>
<value>DirXML-ApplicationAttrs</value>
</add-value>
</modify-attr>
<modify-attr attr-name="DirXML-ADAliasName">
<remove-all-values/>
<add-value>
<value type="string">teststud1</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
[05/26/08 13:56:40.760]:ADTRACE ST: Pumping XDS to eDirectory.
[05/26/08 13:56:40.760]:ADTRACE ST: Performing operation modify for
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:40.760]:ADTRACE ST: Modifying entry
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:40.762]:ADTRACE ST: Processing returned document.
[05/26/08 13:56:40.762]:ADTRACE ST: Processing operation <status> for .
[05/26/08 13:56:40.762]:ADTRACE ST:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Subscriber
Object: \IDMEDIR\Users\HESOCT\Testbak\teststud1
Status: Success
[05/26/08 13:56:40.762]:ADTRACE ST: Direct command from policy result
[05/26/08 13:56:40.762]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115506#1#1"
level="success"><application>DirXML</application>
<module>Active Directory</module>
<object-dn>\IDMEDIR\Users\HESOCT\Testbak\teststud1</object-dn>
<component>Subscriber</component>
</status>
</output>
</nds>
[05/26/08 13:56:40.763]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.763]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.764]:ADTRACE ST:Applying object placement policies.
[05/26/08 13:56:40.764]:ADTRACE ST:Applying policy: %+C%14CPlacement%-C.
[05/26/08 13:56:40.764]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.764]:ADTRACE ST: Evaluating selection criteria for
rule 'placement for all objects'.
[05/26/08 13:56:40.764]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.764]:ADTRACE ST: Applying rule 'placement for all
objects'.
[05/26/08 13:56:40.764]:ADTRACE ST: Action:
do-set-op-dest-dn(arg-dn(token-op-property("unmatched-src-dn")+","+"OU=SynchronizedUsers,DC=tse,DC=local") ).
[05/26/08 13:56:40.764]:ADTRACE ST:
arg-dn(token-op-property("unmatched-src-dn")+","+"OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:40.764]:ADTRACE ST:
token-op-property("unmatched-src-dn")
[05/26/08 13:56:40.764]:ADTRACE ST: Token Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:40.764]:ADTRACE ST: token-text(",")
[05/26/08 13:56:40.764]:ADTRACE ST:
token-text("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:40.764]:ADTRACE ST: Arg Value:
"CN=teststud1,OU=Testbak,OU=HESOCT,OU=Synchronized Users,DC=tse,DC=local".
[05/26/08 13:56:40.764]:ADTRACE ST: Evaluating selection criteria for
rule 'Use Full Name for naming user objects'.
[05/26/08 13:56:40.765]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.765]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:40.765]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.765]:ADTRACE ST: Applying rule 'Use Full Name for
naming user objects'.
[05/26/08 13:56:40.765]:ADTRACE ST: Action:
do-set-op-dest-dn(arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-dest-dn(length="-2"))).
[05/26/08 13:56:40.765]:ADTRACE ST:
arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-dest-dn(length="-2"))
[05/26/08 13:56:40.765]:ADTRACE ST: token-text("CN=")
[05/26/08 13:56:40.765]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:40.765]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:40.765]:ADTRACE ST: token-attr("Full Name")
[05/26/08 13:56:40.765]:ADTRACE ST: Token Value: "test
tester".
[05/26/08 13:56:40.765]:ADTRACE ST: Arg Value: "test tester".
[05/26/08 13:56:40.765]:ADTRACE ST: Token Value: "test tester".
[05/26/08 13:56:40.765]:ADTRACE ST: token-text(",")
[05/26/08 13:56:40.765]:ADTRACE ST: token-dest-dn(length="-2")
[05/26/08 13:56:40.765]:ADTRACE ST: Token Value:
"OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,DC=tse, DC=local".
[05/26/08 13:56:40.766]:ADTRACE ST: Arg Value: "CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local".
[05/26/08 13:56:40.766]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.766]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.767]:ADTRACE ST:Submitting add to subscriber shim.
[05/26/08 13:56:40.767]:ADTRACE ST:Applying command transformation policies.
[05/26/08 13:56:40.767]:ADTRACE ST:Applying policy: %+C%14CCommand%-C.
[05/26/08 13:56:40.767]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.767]:ADTRACE ST: Evaluating selection criteria for
rule 'default Exchange assignment'.
[05/26/08 13:56:40.767]:ADTRACE ST: (if-global-variable
'ExchMailboxPolicy' equal "policy") = FALSE.
[05/26/08 13:56:40.767]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.767]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.767]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.768]:ADTRACE ST:Applying policy: %+C%14C'A set of
rules that are executed when any one of the user name mapping options
are selected.'%-C.
[05/26/08 13:56:40.768]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.768]:ADTRACE ST: Evaluating selection criteria for
rule 'consider user objects when name mapping is enabled'.
[05/26/08 13:56:40.768]:ADTRACE ST: (if-class-name not-equal
"User") = FALSE.
[05/26/08 13:56:40.768]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "false") = FALSE.
[05/26/08 13:56:40.768]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.768]:ADTRACE ST: Evaluating selection criteria for
rule 'generate full name on merge'.
[05/26/08 13:56:40.768]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:40.768]:ADTRACE ST: (if-xpath true
".[@from-merge='true']") = FALSE.
[05/26/08 13:56:40.768]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.768]:ADTRACE ST: Evaluating selection criteria for
rule 'map full name to destination object name'.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:40.769]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.769]:ADTRACE ST: Evaluating selection criteria for
rule 'escape source object name'.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:40.769]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.769]:ADTRACE ST: Evaluating selection criteria for
rule 'map rename to NT logon name'.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-global-variable
'LogonNameMap' equal "true") = TRUE.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:40.769]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.769]:ADTRACE ST: Evaluating selection criteria for
rule 'map rename to Active Directory logon name'.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-name-auth") = FALSE.
[05/26/08 13:56:40.769]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.769]:ADTRACE ST: Evaluating selection criteria for
rule 'map e-mail address to Active Directory logon name'.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:40.769]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.769]:ADTRACE ST: Evaluating selection criteria for
rule 'unmap e-mail address from Active Directory logon name'.
[05/26/08 13:56:40.769]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:40.769]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.769]:ADTRACE ST: Evaluating selection criteria for
rule 'map e-mail address to Active Directory logon name on merge'.
[05/26/08 13:56:40.770]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:40.770]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.770]:ADTRACE ST: Evaluating selection criteria for
rule 'unmap e-mail address from Active Directory logon name on merge'.
[05/26/08 13:56:40.770]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:40.770]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.770]:ADTRACE ST: Evaluating selection criteria for
rule 'discard unwanted renames'.
[05/26/08 13:56:40.770]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:40.770]:ADTRACE ST: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:40.770]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.770]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.770]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.771]:ADTRACE ST:Applying policy: %+C%14C'Transform
NMAS attribute to password elements'%-C.
[05/26/08 13:56:40.771]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.771]:ADTRACE ST: Evaluating selection criteria for
rule 'Convert adds of the nspmDistributionPassword attribute to password
elements'.
[05/26/08 13:56:40.771]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:40.771]:ADTRACE ST: (if-op-attr
'nspmDistributionPassword' available) = TRUE.
[05/26/08 13:56:40.771]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.771]:ADTRACE ST: Applying rule 'Convert adds of
the nspmDistributionPassword attribute to password elements'.
[05/26/08 13:56:40.771]:ADTRACE ST: Action:
do-set-dest-password(token-xpath("add-attr[@attr-name='nspmDistributionPassword']//value")).
[05/26/08 13:56:40.771]:ADTRACE ST:
arg-string(token-xpath("add-attr[@attr-name='nspmDistributionPassword']//value"))
[05/26/08 13:56:40.771]:ADTRACE ST:
token-xpath("add-attr[@attr-name='nspmDistributionPassword']//value")
[05/26/08 13:56:40.771]:ADTRACE ST: Token Value: "--
suppressed --".
[05/26/08 13:56:40.771]:ADTRACE ST: Arg Value: "-- suppressed --".
[05/26/08 13:56:40.772]:ADTRACE ST: Action:
do-strip-op-attr("nspmDistributionPassword").
[05/26/08 13:56:40.772]:ADTRACE ST: Evaluating selection criteria for
rule 'Block modifies for failed password publish operations if reset
password is false'.
[05/26/08 13:56:40.772]:ADTRACE ST: (if-global-variable
'reset-external-password-on-failure' equal "false") = FALSE.
[05/26/08 13:56:40.772]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.772]:ADTRACE ST: Evaluating selection criteria for
rule 'Convert modifies of a nspmDistributionPassword attribute to a
modify password operation'.
[05/26/08 13:56:40.772]:ADTRACE ST: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:40.772]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.772]:ADTRACE ST: Evaluating selection criteria for
rule 'Block empty modify operations'.
[05/26/08 13:56:40.772]:ADTRACE ST: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:40.772]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.772]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.772]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.773]:ADTRACE ST:Applying policy:
%+C%14CPassword(Sub)-Default Password Policy%-C.
[05/26/08 13:56:40.773]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.773]:ADTRACE ST: Evaluating selection criteria for
rule 'On User add, provide default password of Surname if no password
exists'.
[05/26/08 13:56:40.773]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:40.773]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.773]:ADTRACE ST: (if-password not-available) =
FALSE.
[05/26/08 13:56:40.773]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.773]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.774]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.774]:ADTRACE ST:Applying policy: %+C%14C'Subscribe to
password changes'%-C.
[05/26/08 13:56:40.774]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.774]:ADTRACE ST: Evaluating selection criteria for
rule 'Block subscribing to passwords when objects are added'.
[05/26/08 13:56:40.774]:ADTRACE ST: (if-global-variable
'enable-password-subscribe' equal "false") = FALSE.
[05/26/08 13:56:40.774]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.774]:ADTRACE ST: Evaluating selection criteria for
rule 'Block subscribing to password modifications'.
[05/26/08 13:56:40.774]:ADTRACE ST: (if-global-variable
'enable-password-subscribe' equal "false") = FALSE.
[05/26/08 13:56:40.774]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.774]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.775]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:40.775]:ADTRACE ST:Applying policy: %+C%14C'Payloads for
subscribe to password changes'%-C.
[05/26/08 13:56:40.775]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.775]:ADTRACE ST: Evaluating selection criteria for
rule 'Add operation-data element to password subscribe operations'.
[05/26/08 13:56:40.775]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:40.775]:ADTRACE ST: (if-password available) = TRUE.
[05/26/08 13:56:40.775]:ADTRACE ST: (if-xpath not-true
"operation-data") = FALSE.
[05/26/08 13:56:40.776]:ADTRACE ST: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:40.776]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.776]:ADTRACE ST: Evaluating selection criteria for
rule 'Add payload data to a reset password from a failed password
publish operation'.
[05/26/08 13:56:40.776]:ADTRACE ST: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:40.776]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.776]:ADTRACE ST: Evaluating selection criteria for
rule 'Add payload data to password subscribe operations'.
[05/26/08 13:56:40.776]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:40.776]:ADTRACE ST: (if-password available) = TRUE.
[05/26/08 13:56:40.776]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.776]:ADTRACE ST: Applying rule 'Add payload data
to password subscribe operations'.
[05/26/08 13:56:40.776]:ADTRACE ST: Action:
do-append-xml-element("password-subscribe-status","operation-data").
[05/26/08 13:56:40.776]:ADTRACE ST: Action:
do-append-xml-element("association","operation-data/password-subscribe-status").
[05/26/08 13:56:40.776]:ADTRACE ST: Action:
do-append-xml-text("operation-data/password-subscribe-status/association",token-association()).
[05/26/08 13:56:40.776]:ADTRACE ST: arg-string(token-association())
[05/26/08 13:56:40.776]:ADTRACE ST: token-association()
[05/26/08 13:56:40.776]:ADTRACE ST: Token Value: "".
[05/26/08 13:56:40.776]:ADTRACE ST: Arg Value: "".
[05/26/08 13:56:40.776]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.777]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:40.777]:ADTRACE ST:Applying policy: %+C%14C'Resolve
group memberships on an add user'%-C.
[05/26/08 13:56:40.777]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.777]:ADTRACE ST: Evaluating selection criteria for
rule 'Add new user to associated groups'.
[05/26/08 13:56:40.777]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:40.777]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.778]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.778]:ADTRACE ST: Applying rule 'Add new user to
associated groups'.
[05/26/08 13:56:40.778]:ADTRACE ST: Action:
do-set-local-variable("groupAssociations",arg-node-set(token-xpath("empty"))).
[05/26/08 13:56:40.778]:ADTRACE ST:
arg-node-set(token-xpath("empty"))
[05/26/08 13:56:40.778]:ADTRACE ST: token-xpath("empty")
[05/26/08 13:56:40.778]:ADTRACE ST: Token Value: {}.
[05/26/08 13:56:40.778]:ADTRACE ST: Arg Value: {}.
[05/26/08 13:56:40.778]:ADTRACE ST: Action:
do-for-each(arg-node-set(token-src-attr("Group Membership"))).
[05/26/08 13:56:40.778]:ADTRACE ST:
arg-node-set(token-src-attr("Group Membership"))
[05/26/08 13:56:40.778]:ADTRACE ST: token-src-attr("Group
Membership")
[05/26/08 13:56:40.778]:ADTRACE ST: Query from policy
[05/26/08 13:56:40.778]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User"
dest-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" dest-entry-id="35238"
scope="entry">
<read-attr attr-name="Group Membership"/>
</query>
</input>
</nds>
[05/26/08 13:56:40.778]:ADTRACE ST: Pumping XDS to eDirectory.
[05/26/08 13:56:40.778]:ADTRACE ST: Performing operation
query for \IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:40.779]:ADTRACE ST: Query from policy result
[05/26/08 13:56:40.779]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="User"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<association state="manual"></association>
</instance>
<status level="success"></status>
</output>
</nds>
[05/26/08 13:56:40.780]:ADTRACE ST: Token Value: {}.
[05/26/08 13:56:40.780]:ADTRACE ST: Arg Value: {}.
[05/26/08 13:56:40.780]:ADTRACE ST: Action:
do-for-each(arg-node-set(token-local-variable("groupAssociations"))).
[05/26/08 13:56:40.780]:ADTRACE ST:
arg-node-set(token-local-variable("groupAssociations"))
[05/26/08 13:56:40.780]:ADTRACE ST:
token-local-variable("groupAssociations")
[05/26/08 13:56:40.780]:ADTRACE ST: Token Value: {}.
[05/26/08 13:56:40.780]:ADTRACE ST: Arg Value: {}.
[05/26/08 13:56:40.780]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.780]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:40.781]:ADTRACE ST:Filtering out notification-only
attributes.
[05/26/08 13:56:40.781]:ADTRACE ST:Fixing up association references.
[05/26/08 13:56:40.781]:ADTRACE ST:Applying schema mapping policies to
output.
[05/26/08 13:56:40.781]:ADTRACE ST:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:40.781]:ADTRACE ST: Mapping attr-name 'Full Name' to
'displayName'.
[05/26/08 13:56:40.781]:ADTRACE ST: Mapping attr-name 'Given Name' to
'givenName'.
[05/26/08 13:56:40.781]:ADTRACE ST: Mapping attr-name 'Internet EMail
Address' to 'mail'.
[05/26/08 13:56:40.781]:ADTRACE ST: Mapping attr-name 'Surname' to 'sn'.
[05/26/08 13:56:40.782]:ADTRACE ST: Mapping attr-name
'DirXML-ADAliasName' to 'sAMAccountName'.
[05/26/08 13:56:40.782]:ADTRACE ST: Mapping attr-name 'Login Disabled'
to 'dirxml-uACAccountDisable'.
[05/26/08 13:56:40.782]:ADTRACE ST: Mapping class-name 'User' to 'user'.
[05/26/08 13:56:40.782]:ADTRACE ST:Applying output transformation policies.
[05/26/08 13:56:40.782]:ADTRACE ST:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in Active Directory.'%-C.
[05/26/08 13:56:40.782]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.782]:ADTRACE ST: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:40.782]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.782]:ADTRACE ST: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:40.782]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:40.782]:ADTRACE ST: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:40.783]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.783]:ADTRACE ST: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:40.783]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:40.783]:ADTRACE ST: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:40.783]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.783]:ADTRACE ST: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:40.783]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:40.783]:ADTRACE ST: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:40.783]:ADTRACE ST: Rule selected.
[05/26/08 13:56:40.783]:ADTRACE ST: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:40.783]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:40.783]:ADTRACE ST: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:40.783]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:40.783]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:40.783]:ADTRACE ST: (if-op-attr 'telephoneNumber'
available) = FALSE.
[05/26/08 13:56:40.783]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.783]:ADTRACE ST: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:40.783]:ADTRACE ST: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:40.784]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.784]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.784]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:40.784]:ADTRACE ST:Applying policy: %+C%14C'Email
notifications for failed password publications'%-C.
[05/26/08 13:56:40.784]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:40.785]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:40.785]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:40.785]:ADTRACE ST: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:40.785]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:40.785]:ADTRACE ST:Policy returned:
[05/26/08 13:56:40.785]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:40.786]:ADTRACE ST:Submitting document to subscriber shim:
[05/26/08 13:56:40.786]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:40.787]:ADTRACE ST:Stripping operation data from input
document
[05/26/08 13:56:40.787]:ADTRACE ST:Remote Interface Driver: Sending...
[05/26/08 13:56:40.787]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115506#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
</add>
</input>
</nds>
[05/26/08 13:56:40.787]:ADTRACE ST:Remote Interface Driver: Document sent.
[05/26/08 13:56:42.648]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:42.649]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115506#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
</status>
</output>
</nds>
[05/26/08 13:56:42.649]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:42.649]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:42.649]:ADTRACE ST:Restoring operation data to output
document
[05/26/08 13:56:42.649]:ADTRACE ST:SubscriptionShim.execute() returned:
[05/26/08 13:56:42.649]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115506#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
[05/26/08 13:56:42.650]:ADTRACE ST:Applying input transformation policies.
[05/26/08 13:56:42.650]:ADTRACE ST:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:42.650]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:42.650]:ADTRACE ST: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:42.650]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.650]:ADTRACE ST: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:42.650]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:42.650]:ADTRACE ST: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:42.650]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.650]:ADTRACE ST: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:42.650]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:42.650]:ADTRACE ST: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:42.650]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.650]:ADTRACE ST: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:42.650]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:42.651]:ADTRACE ST: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:42.651]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.651]:ADTRACE ST: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:42.651]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:42.651]:ADTRACE ST:Policy returned:
[05/26/08 13:56:42.651]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115506#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
[05/26/08 13:56:42.651]:ADTRACE ST:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:42.651]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:42.651]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:42.652]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:42.652]:ADTRACE ST: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:42.652]:ADTRACE ST: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:42.652]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:42.652]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:42.652]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:42.652]:ADTRACE ST: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:42.652]:ADTRACE ST: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:42.652]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:42.652]:ADTRACE ST:Policy returned:
[05/26/08 13:56:42.652]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115506#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
[05/26/08 13:56:42.653]:ADTRACE ST:Applying schema mapping policies to
input.
[05/26/08 13:56:42.653]:ADTRACE ST:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:42.653]:ADTRACE ST:Resolving association references.
[05/26/08 13:56:42.653]:ADTRACE ST:Processing returned document.
[05/26/08 13:56:42.653]:ADTRACE ST:Processing operation <status> for .
[05/26/08 13:56:42.654]:ADTRACE ST:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Subscriber
Object: \IDMEDIR\Users\HESOCT\Testbak\teststud1
Status: Warning
Message: <ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No Such
Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT),
data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
[05/26/08 13:56:42.658]:ADTRACE ST:End transaction.
[05/26/08 13:56:42.658]:ADTRACE ST:Start transaction.
[05/26/08 13:56:42.658]:ADTRACE ST:Processing events for transaction.
[05/26/08 13:56:42.659]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<sync cached-time="20080526115629.521Z" class-name="User"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238"
timestamp="0#0">
<association state="manual"></association>
</sync>
</input>
</nds>
[05/26/08 13:56:42.659]:ADTRACE ST:No event transformation policies.
[05/26/08 13:56:42.659]:ADTRACE ST:Subscriber processing sync for
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:42.659]:ADTRACE ST:Reading relevant attributes from
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:42.659]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User"
dest-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" dest-entry-id="35238"
scope="entry">
<read-attr attr-name="Description"/>
<read-attr attr-name="Facsimile Telephone Number"/>
<read-attr attr-name="Full Name"/>
<read-attr attr-name="Given Name"/>
<read-attr attr-name="Initials"/>
<read-attr attr-name="Internet EMail Address"/>
<read-attr attr-name="L"/>
<read-attr attr-name="Login Allowed Time Map"/>
<read-attr attr-name="Login Disabled"/>
<read-attr attr-name="nspmDistributionPassword"/>
<read-attr attr-name="Physical Delivery Office Name"/>
<read-attr attr-name="Postal Code"/>
<read-attr attr-name="Postal Office Box"/>
<read-attr attr-name="S"/>
<read-attr attr-name="SA"/>
<read-attr attr-name="Surname"/>
<read-attr attr-name="Telephone Number"/>
<read-attr attr-name="Title"/>
</query>
</input>
</nds>
[05/26/08 13:56:42.660]:ADTRACE ST:Pumping XDS to eDirectory.
[05/26/08 13:56:42.660]:ADTRACE ST:Performing operation query for
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:42.663]:ADTRACE ST:Read result:
[05/26/08 13:56:42.664]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="User"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<association state="manual"></association>
<attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</attr>
<attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</attr>
<attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</attr>
<attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</attr>
<attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</attr>
</instance>
<status level="success"></status>
</output>
</nds>
[05/26/08 13:56:42.664]:ADTRACE ST:Synthetic add:
[05/26/08 13:56:42.664]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<add class-name="User" event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<association state="manual"></association>
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
</add>
<status level="success"></status>
</output>
</nds>
[05/26/08 13:56:42.665]:ADTRACE ST:Applying object matching policies.
[05/26/08 13:56:42.665]:ADTRACE ST:Applying policy: %+C%14C'Find
matching object in Active Directory'%-C.
[05/26/08 13:56:42.665]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:42.665]:ADTRACE ST: Evaluating selection criteria for
rule 'remember relative position in hierarchy'.
[05/26/08 13:56:42.665]:ADTRACE ST: (if-src-dn in-subtree "Users")
= TRUE.
[05/26/08 13:56:42.665]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.665]:ADTRACE ST: Applying rule 'remember relative
position in hierarchy'.
[05/26/08 13:56:42.665]:ADTRACE ST: Action:
do-set-op-property("unmatched-src-dn",token-unmatched-src-dn(convert="true")).
[05/26/08 13:56:42.665]:ADTRACE ST:
arg-string(token-unmatched-src-dn(convert="true"))
[05/26/08 13:56:42.665]:ADTRACE ST:
token-unmatched-src-dn(convert="true")
[05/26/08 13:56:42.665]:ADTRACE ST: Token Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:42.666]:ADTRACE ST: Arg Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:42.666]:ADTRACE ST: Evaluating selection criteria for
rule 'veto out-of-scope events'.
[05/26/08 13:56:42.666]:ADTRACE ST: (if-op-property
'unmatched-src-dn' not-available) = FALSE.
[05/26/08 13:56:42.666]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:42.666]:ADTRACE ST: Evaluating selection criteria for
rule 'generate full name if not in Identity Vault'.
[05/26/08 13:56:42.666]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:42.666]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:42.666]:ADTRACE ST: (if-attr 'Full Name'
not-available) = FALSE.
[05/26/08 13:56:42.666]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:42.666]:ADTRACE ST: Evaluating selection criteria for
rule 'match users based on NT logon name'.
[05/26/08 13:56:42.666]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:42.666]:ADTRACE ST: (if-global-variable
'LogonNameMap' equal "true") = TRUE.
[05/26/08 13:56:42.666]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.666]:ADTRACE ST: Applying rule 'match users based
on NT logon name'.
[05/26/08 13:56:42.666]:ADTRACE ST: Action:
do-find-matching-object(scope="subtree",arg-dn("OU=SynchronizedUsers,DC=tse,DC=local"),arg-match-attr("DirXML-ADAliasName",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
[05/26/08 13:56:42.666]:ADTRACE ST:
arg-dn("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:42.666]:ADTRACE ST:
token-text("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:42.667]:ADTRACE ST: Arg Value:
"OU=SynchronizedUsers,DC=tse,DC=local".
[05/26/08 13:56:42.667]:ADTRACE ST:
arg-match-attr("DirXML-ADAliasName",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:42.667]:ADTRACE ST:
arg-string(token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:42.667]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:42.667]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:42.667]:ADTRACE ST: token-src-name()
[05/26/08 13:56:42.667]:ADTRACE ST: Token Value:
"teststud1".
[05/26/08 13:56:42.667]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:42.667]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:42.667]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:42.667]:ADTRACE ST: Query from policy
[05/26/08 13:56:42.667]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" scope="subtree">
<search-class class-name="User"/>
<search-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:42.668]:ADTRACE ST: Fixing up association references.
[05/26/08 13:56:42.668]:ADTRACE ST: Applying schema mapping
policies to output.
[05/26/08 13:56:42.668]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:42.668]:ADTRACE ST: Mapping attr-name
'DirXML-ADAliasName' to 'sAMAccountName'.
[05/26/08 13:56:42.668]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:42.668]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:42.668]:ADTRACE ST: Applying output
transformation policies.
[05/26/08 13:56:42.668]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in
Active Directory.'%-C.
[05/26/08 13:56:42.668]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:42.668]:ADTRACE ST: Evaluating selection
criteria for rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:42.668]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.668]:ADTRACE ST: Applying rule 'Street
Address: Convert LF to CR-LF'.
[05/26/08 13:56:42.668]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:42.668]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:42.669]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.669]:ADTRACE ST: Applying rule
'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:42.669]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:42.669]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:42.669]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.669]:ADTRACE ST: Applying rule
'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:42.669]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:42.669]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:42.669]:ADTRACE ST: Rule selected.
[05/26/08 13:56:42.669]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:42.669]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:42.669]:ADTRACE ST: Evaluating selection
criteria for rule 'Add: User - convert multi-valued Telephone to single
value'.
[05/26/08 13:56:42.669]:ADTRACE ST: (if-operation equal
"add") = FALSE.
[05/26/08 13:56:42.669]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:42.669]:ADTRACE ST: Evaluating selection
criteria for rule 'update Active Directory logon name'.
[05/26/08 13:56:42.669]:ADTRACE ST: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:42.669]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:42.670]:ADTRACE ST: Policy returned:
[05/26/08 13:56:42.670]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:42.670]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password publications'%-C.
[05/26/08 13:56:42.670]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:42.670]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:42.670]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:42.670]:ADTRACE ST: (if-operation equal
"status") = FALSE.
[05/26/08 13:56:42.670]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:42.670]:ADTRACE ST: Policy returned:
[05/26/08 13:56:42.670]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:42.671]:ADTRACE ST: Submitting document to
subscriber shim:
[05/26/08 13:56:42.671]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:42.671]:ADTRACE ST: Remote Interface Driver:
Sending...
[05/26/08 13:56:42.671]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user"
dest-dn="OU=SynchronizedUsers,DC=tse,DC=local" event-id="0" scope="subtree">
<search-class class-name="user"/>
<search-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</search-attr>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:42.671]:ADTRACE ST: Remote Interface Driver:
Document sent.
[05/26/08 13:56:43.511]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:43.511]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:43.511]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:43.511]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:43.511]:ADTRACE ST: SubscriptionShim.execute()
returned:
[05/26/08 13:56:43.511]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:43.511]:ADTRACE ST: Applying input transformation
policies.
[05/26/08 13:56:43.511]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in the
Identity Vault.'%-C.
[05/26/08 13:56:43.512]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:43.512]:ADTRACE ST: Evaluating selection
criteria for rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:43.512]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.512]:ADTRACE ST: Applying rule
'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:43.512]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:43.512]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:43.512]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.512]:ADTRACE ST: Applying rule
'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:43.512]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:43.512]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:43.512]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.512]:ADTRACE ST: Applying rule
'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:43.512]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:43.512]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:43.512]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.513]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:43.513]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:43.513]:ADTRACE ST: Policy returned:
[05/26/08 13:56:43.513]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:43.513]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password subscriptions'%-C.
[05/26/08 13:56:43.513]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:43.513]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:43.513]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:43.513]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:43.513]:ADTRACE ST: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:43.513]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:43.513]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on failure to reset connected system
password using the Identity Manager data store password'.
[05/26/08 13:56:43.514]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:43.514]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:43.514]:ADTRACE ST: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:43.514]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:43.514]:ADTRACE ST: Policy returned:
[05/26/08 13:56:43.514]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:43.514]:ADTRACE ST: Applying schema mapping
policies to input.
[05/26/08 13:56:43.514]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:43.514]:ADTRACE ST: Resolving association references.
[05/26/08 13:56:43.514]:ADTRACE ST: Query from policy result
[05/26/08 13:56:43.515]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:43.515]:ADTRACE ST: No matches found.
[05/26/08 13:56:43.515]:ADTRACE ST: Evaluating selection criteria for
rule 'match users based on full name'.
[05/26/08 13:56:43.515]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:43.515]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:43.515]:ADTRACE ST: (if-op-attr 'Full Name'
available) = TRUE.
[05/26/08 13:56:43.515]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.515]:ADTRACE ST: Applying rule 'match users based
on full name'.
[05/26/08 13:56:43.515]:ADTRACE ST: Action:
do-find-matching-object(scope="entry",arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))+"OU=SynchronizedUsers,DC=tse,DC=local")).
[05/26/08 13:56:43.515]:ADTRACE ST:
arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))+"OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:43.515]:ADTRACE ST: token-text("CN=")
[05/26/08 13:56:43.515]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:43.515]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:43.515]:ADTRACE ST: token-attr("Full Name")
[05/26/08 13:56:43.515]:ADTRACE ST: Token Value: "test
tester".
[05/26/08 13:56:43.516]:ADTRACE ST: Arg Value: "test tester".
[05/26/08 13:56:43.516]:ADTRACE ST: Token Value: "test tester".
[05/26/08 13:56:43.516]:ADTRACE ST: token-text(",")
[05/26/08 13:56:43.516]:ADTRACE ST:
token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))
[05/26/08 13:56:43.516]:ADTRACE ST:
token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))
[05/26/08 13:56:43.516]:ADTRACE ST:
token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn"))
[05/26/08 13:56:43.516]:ADTRACE ST:
token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn"))
[05/26/08 13:56:43.516]:ADTRACE ST:
token-op-property("unmatched-src-dn")
[05/26/08 13:56:43.516]:ADTRACE ST: Token Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:43.516]:ADTRACE ST: Arg Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:43.516]:ADTRACE ST: Token Value:
"OU=Testbak,OU=HESOCT".
[05/26/08 13:56:43.516]:ADTRACE ST: Arg Value:
"OU=Testbak,OU=HESOCT".
[05/26/08 13:56:43.516]:ADTRACE ST: Token Value:
"OU=Testbak,OU=HESOCT,".
[05/26/08 13:56:43.516]:ADTRACE ST:
token-text("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:43.516]:ADTRACE ST: Arg Value: "CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local".
[05/26/08 13:56:43.516]:ADTRACE ST: Query from policy
[05/26/08 13:56:43.517]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
scope="entry">
<search-class class-name="User"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:43.517]:ADTRACE ST: Fixing up association references.
[05/26/08 13:56:43.517]:ADTRACE ST: Applying schema mapping
policies to output.
[05/26/08 13:56:43.517]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:43.517]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:43.517]:ADTRACE ST: Mapping class-name 'User'
to 'user'.
[05/26/08 13:56:43.517]:ADTRACE ST: Applying output
transformation policies.
[05/26/08 13:56:43.517]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in
Active Directory.'%-C.
[05/26/08 13:56:43.517]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:43.517]:ADTRACE ST: Evaluating selection
criteria for rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:43.517]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.517]:ADTRACE ST: Applying rule 'Street
Address: Convert LF to CR-LF'.
[05/26/08 13:56:43.517]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:43.518]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:43.518]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.518]:ADTRACE ST: Applying rule
'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:43.518]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:43.518]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:43.518]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.518]:ADTRACE ST: Applying rule
'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:43.518]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:43.518]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:43.518]:ADTRACE ST: Rule selected.
[05/26/08 13:56:43.518]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:43.518]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:43.518]:ADTRACE ST: Evaluating selection
criteria for rule 'Add: User - convert multi-valued Telephone to single
value'.
[05/26/08 13:56:43.518]:ADTRACE ST: (if-operation equal
"add") = FALSE.
[05/26/08 13:56:43.518]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:43.518]:ADTRACE ST: Evaluating selection
criteria for rule 'update Active Directory logon name'.
[05/26/08 13:56:43.518]:ADTRACE ST: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:43.519]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:43.519]:ADTRACE ST: Policy returned:
[05/26/08 13:56:43.519]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:43.519]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password publications'%-C.
[05/26/08 13:56:43.519]:ADTRACE ST: Applying to query #1.
[05/26/08 13:56:43.519]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:43.519]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:43.519]:ADTRACE ST: (if-operation equal
"status") = FALSE.
[05/26/08 13:56:43.519]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:43.519]:ADTRACE ST: Policy returned:
[05/26/08 13:56:43.519]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:43.520]:ADTRACE ST: Submitting document to
subscriber shim:
[05/26/08 13:56:43.520]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:43.520]:ADTRACE ST: Remote Interface Driver:
Sending...
[05/26/08 13:56:43.520]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="0" scope="entry">
<search-class class-name="user"/>
<read-attr/>
</query>
</input>
</nds>
[05/26/08 13:56:43.520]:ADTRACE ST: Remote Interface Driver:
Document sent.
[05/26/08 13:56:44.010]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:44.010]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:44.010]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:44.010]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:44.010]:ADTRACE ST: SubscriptionShim.execute()
returned:
[05/26/08 13:56:44.010]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:44.010]:ADTRACE ST: Applying input transformation
policies.
[05/26/08 13:56:44.010]:ADTRACE ST: Applying policy:
%+C%14C'Convert selected attributes to a form most commonly used in the
Identity Vault.'%-C.
[05/26/08 13:56:44.011]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:44.011]:ADTRACE ST: Evaluating selection
criteria for rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:44.011]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.011]:ADTRACE ST: Applying rule
'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:44.011]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:44.011]:ADTRACE ST: Evaluating selection
criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:44.011]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.011]:ADTRACE ST: Applying rule
'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:44.011]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:44.011]:ADTRACE ST: Evaluating selection
criteria for rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:44.011]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.011]:ADTRACE ST: Applying rule
'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:44.011]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:44.011]:ADTRACE ST: Evaluating selection
criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:44.011]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.011]:ADTRACE ST: Applying rule
'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:44.011]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:44.012]:ADTRACE ST: Policy returned:
[05/26/08 13:56:44.012]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:44.012]:ADTRACE ST: Applying policy:
%+C%14C'Email notifications for failed password subscriptions'%-C.
[05/26/08 13:56:44.012]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:44.012]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:44.012]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:44.012]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:44.012]:ADTRACE ST: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:44.012]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.012]:ADTRACE ST: Evaluating selection
criteria for rule 'Send e-mail on failure to reset connected system
password using the Identity Manager data store password'.
[05/26/08 13:56:44.012]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:44.012]:ADTRACE ST: (if-operation equal
"status") = TRUE.
[05/26/08 13:56:44.012]:ADTRACE ST: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:44.012]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.013]:ADTRACE ST: Policy returned:
[05/26/08 13:56:44.013]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:44.013]:ADTRACE ST: Applying schema mapping
policies to input.
[05/26/08 13:56:44.013]:ADTRACE ST: Applying policy:
%+C%14CSchemaMapping%-C.
[05/26/08 13:56:44.013]:ADTRACE ST: Resolving association references.
[05/26/08 13:56:44.013]:ADTRACE ST: Query from policy result
[05/26/08 13:56:44.013]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="0" level="success"/>
</output>
</nds>
[05/26/08 13:56:44.013]:ADTRACE ST: No matches found.
[05/26/08 13:56:44.013]:ADTRACE ST: Evaluating selection criteria for
rule 'match everything else'.
[05/26/08 13:56:44.013]:ADTRACE ST: (if-class-name not-equal
"User") = FALSE.
[05/26/08 13:56:44.013]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.014]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.014]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.014]:ADTRACE ST:No match found.
[05/26/08 13:56:44.014]:ADTRACE ST:Applying object creation policies.
[05/26/08 13:56:44.014]:ADTRACE ST:Applying policy: %+C%14CCreation%-C.
[05/26/08 13:56:44.015]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.015]:ADTRACE ST: Evaluating selection criteria for
rule 'Veto if nspmDistributionPassword is not available'.
[05/26/08 13:56:44.015]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:44.015]:ADTRACE ST: (if-global-variable
'enable-password-subscribe' equal "true") = TRUE.
[05/26/08 13:56:44.015]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.015]:ADTRACE ST: Applying rule 'Veto if
nspmDistributionPassword is not available'.
[05/26/08 13:56:44.015]:ADTRACE ST: Action:
do-veto-if-op-attr-not-available("nspmDistributionPassword").
[05/26/08 13:56:44.015]:ADTRACE ST: Evaluating selection criteria for
rule 'Create User objects'.
[05/26/08 13:56:44.015]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:44.015]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.015]:ADTRACE ST: Applying rule 'Create User objects'.
[05/26/08 13:56:44.015]:ADTRACE ST: Action:
do-veto-if-op-attr-not-available("Full Name").
[05/26/08 13:56:44.015]:ADTRACE ST: Action:
do-set-dest-attr-value("DirXML-ADAliasName",token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
[05/26/08 13:56:44.015]:ADTRACE ST:
arg-string(token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())))
[05/26/08 13:56:44.015]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:44.015]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:44.016]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:44.016]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:44.016]:ADTRACE ST: token-src-name()
[05/26/08 13:56:44.016]:ADTRACE ST: Token Value:
"teststud1".
[05/26/08 13:56:44.016]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:44.016]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:44.016]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:44.016]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:44.016]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:44.016]:ADTRACE ST: Action:
do-add-src-attr-value("Object
Class",class-name="User","DirXML-ApplicationAttrs").
[05/26/08 13:56:44.016]:ADTRACE ST:
arg-string("DirXML-ApplicationAttrs")
[05/26/08 13:56:44.016]:ADTRACE ST:
token-text("DirXML-ApplicationAttrs")
[05/26/08 13:56:44.016]:ADTRACE ST: Arg Value:
"DirXML-ApplicationAttrs".
[05/26/08 13:56:44.016]:ADTRACE ST: Action:
do-set-src-attr-value("DirXML-ADAliasName",token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
[05/26/08 13:56:44.016]:ADTRACE ST:
arg-string(token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())))
[05/26/08 13:56:44.017]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:44.017]:ADTRACE ST:
token-substring(length="20",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
[05/26/08 13:56:44.017]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:44.017]:ADTRACE ST:
token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
[05/26/08 13:56:44.017]:ADTRACE ST: token-src-name()
[05/26/08 13:56:44.017]:ADTRACE ST: Token Value:
"teststud1".
[05/26/08 13:56:44.017]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:44.017]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:44.017]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:44.017]:ADTRACE ST: Token Value: "teststud1".
[05/26/08 13:56:44.017]:ADTRACE ST: Arg Value: "teststud1".
[05/26/08 13:56:44.017]:ADTRACE ST: Action:
do-set-dest-password(token-op-attr("Surname")+"-- suppressed --").
[05/26/08 13:56:44.017]:ADTRACE ST:
arg-string(token-op-attr("Surname")+"-- suppressed --")
[05/26/08 13:56:44.017]:ADTRACE ST: token-op-attr("Surname")
[05/26/08 13:56:44.017]:ADTRACE ST: Token Value: "--
suppressed --".
[05/26/08 13:56:44.017]:ADTRACE ST: token-text("-- suppressed --")
[05/26/08 13:56:44.017]:ADTRACE ST: Arg Value: "-- suppressed --".
[05/26/08 13:56:44.017]:ADTRACE ST: Evaluating selection criteria for
rule 'map user name to Windows logon name'.
[05/26/08 13:56:44.018]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-name-auth") = FALSE.
[05/26/08 13:56:44.018]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.018]:ADTRACE ST: Evaluating selection criteria for
rule 'Create Group objects'.
[05/26/08 13:56:44.018]:ADTRACE ST: (if-class-name equal "Group") =
FALSE.
[05/26/08 13:56:44.018]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.018]:ADTRACE ST: Evaluating selection criteria for
rule 'Identity Vault accounts are enabled if Login Disabled does not exist'.
[05/26/08 13:56:44.018]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:44.018]:ADTRACE ST: (if-op-attr 'Login Disabled'
not-available) = TRUE.
[05/26/08 13:56:44.018]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.018]:ADTRACE ST: Applying rule 'Identity Vault
accounts are enabled if Login Disabled does not exist'.
[05/26/08 13:56:44.018]:ADTRACE ST: Action:
do-set-dest-attr-value("Login Disabled","false").
[05/26/08 13:56:44.018]:ADTRACE ST: arg-string("false")
[05/26/08 13:56:44.018]:ADTRACE ST: token-text("false")
[05/26/08 13:56:44.018]:ADTRACE ST: Arg Value: "false".
[05/26/08 13:56:44.018]:ADTRACE ST: Evaluating selection criteria for
rule 'default Exchange assignment'.
[05/26/08 13:56:44.018]:ADTRACE ST: (if-global-variable
'ExchMailboxPolicy' equal "policy") = FALSE.
[05/26/08 13:56:44.018]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.018]:ADTRACE ST: Direct command from policy
[05/26/08 13:56:44.019]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<modify class-name="User"
dest-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" dest-entry-id="35238"
event-id="IDMVAULT#20080526115629#1#1">
<modify-attr attr-name="Object Class">
<add-value>
<value>DirXML-ApplicationAttrs</value>
</add-value>
</modify-attr>
<modify-attr attr-name="DirXML-ADAliasName">
<remove-all-values/>
<add-value>
<value type="string">teststud1</value>
</add-value>
</modify-attr>
</modify>
</input>
</nds>
[05/26/08 13:56:44.019]:ADTRACE ST: Pumping XDS to eDirectory.
[05/26/08 13:56:44.019]:ADTRACE ST: Performing operation modify for
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:44.020]:ADTRACE ST: Modifying entry
\IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:44.021]:ADTRACE ST: Processing returned document.
[05/26/08 13:56:44.021]:ADTRACE ST: Processing operation <status> for .
[05/26/08 13:56:44.021]:ADTRACE ST:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Subscriber
Object: \IDMEDIR\Users\HESOCT\Testbak\teststud1
Status: Success
[05/26/08 13:56:44.021]:ADTRACE ST: Direct command from policy result
[05/26/08 13:56:44.022]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115629#1#1"
level="success"><application>DirXML</application>
<module>Active Directory</module>
<object-dn>\IDMEDIR\Users\HESOCT\Testbak\teststud1</object-dn>
<component>Subscriber</component>
</status>
</output>
</nds>
[05/26/08 13:56:44.022]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.022]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.023]:ADTRACE ST:Applying object placement policies.
[05/26/08 13:56:44.023]:ADTRACE ST:Applying policy: %+C%14CPlacement%-C.
[05/26/08 13:56:44.023]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.023]:ADTRACE ST: Evaluating selection criteria for
rule 'placement for all objects'.
[05/26/08 13:56:44.023]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.023]:ADTRACE ST: Applying rule 'placement for all
objects'.
[05/26/08 13:56:44.023]:ADTRACE ST: Action:
do-set-op-dest-dn(arg-dn(token-op-property("unmatched-src-dn")+","+"OU=SynchronizedUsers,DC=tse,DC=local") ).
[05/26/08 13:56:44.023]:ADTRACE ST:
arg-dn(token-op-property("unmatched-src-dn")+","+"OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:44.023]:ADTRACE ST:
token-op-property("unmatched-src-dn")
[05/26/08 13:56:44.023]:ADTRACE ST: Token Value:
"CN=teststud1,OU=Testbak,OU=HESOCT".
[05/26/08 13:56:44.023]:ADTRACE ST: token-text(",")
[05/26/08 13:56:44.023]:ADTRACE ST:
token-text("OU=SynchronizedUsers,DC=tse,DC=local")
[05/26/08 13:56:44.023]:ADTRACE ST: Arg Value:
"CN=teststud1,OU=Testbak,OU=HESOCT,OU=Synchronized Users,DC=tse,DC=local".
[05/26/08 13:56:44.024]:ADTRACE ST: Evaluating selection criteria for
rule 'Use Full Name for naming user objects'.
[05/26/08 13:56:44.024]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:44.024]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:44.024]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.024]:ADTRACE ST: Applying rule 'Use Full Name for
naming user objects'.
[05/26/08 13:56:44.024]:ADTRACE ST: Action:
do-set-op-dest-dn(arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-dest-dn(length="-2"))).
[05/26/08 13:56:44.024]:ADTRACE ST:
arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full
Name"))+","+token-dest-dn(length="-2"))
[05/26/08 13:56:44.024]:ADTRACE ST: token-text("CN=")
[05/26/08 13:56:44.024]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:44.024]:ADTRACE ST:
token-escape-for-dest-dn(token-attr("Full Name"))
[05/26/08 13:56:44.024]:ADTRACE ST: token-attr("Full Name")
[05/26/08 13:56:44.024]:ADTRACE ST: Token Value: "test
tester".
[05/26/08 13:56:44.024]:ADTRACE ST: Arg Value: "test tester".
[05/26/08 13:56:44.024]:ADTRACE ST: Token Value: "test tester".
[05/26/08 13:56:44.024]:ADTRACE ST: token-text(",")
[05/26/08 13:56:44.024]:ADTRACE ST: token-dest-dn(length="-2")
[05/26/08 13:56:44.024]:ADTRACE ST: Token Value:
"OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,DC=tse, DC=local".
[05/26/08 13:56:44.024]:ADTRACE ST: Arg Value: "CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local".
[05/26/08 13:56:44.025]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.025]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.026]:ADTRACE ST:Submitting add to subscriber shim.
[05/26/08 13:56:44.026]:ADTRACE ST:Applying command transformation policies.
[05/26/08 13:56:44.026]:ADTRACE ST:Applying policy: %+C%14CCommand%-C.
[05/26/08 13:56:44.026]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.026]:ADTRACE ST: Evaluating selection criteria for
rule 'default Exchange assignment'.
[05/26/08 13:56:44.026]:ADTRACE ST: (if-global-variable
'ExchMailboxPolicy' equal "policy") = FALSE.
[05/26/08 13:56:44.026]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.026]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.026]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.027]:ADTRACE ST:Applying policy: %+C%14C'A set of
rules that are executed when any one of the user name mapping options
are selected.'%-C.
[05/26/08 13:56:44.027]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.027]:ADTRACE ST: Evaluating selection criteria for
rule 'consider user objects when name mapping is enabled'.
[05/26/08 13:56:44.027]:ADTRACE ST: (if-class-name not-equal
"User") = FALSE.
[05/26/08 13:56:44.027]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "false") = FALSE.
[05/26/08 13:56:44.027]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.027]:ADTRACE ST: Evaluating selection criteria for
rule 'generate full name on merge'.
[05/26/08 13:56:44.027]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:44.027]:ADTRACE ST: (if-xpath true
".[@from-merge='true']") = FALSE.
[05/26/08 13:56:44.027]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.027]:ADTRACE ST: Evaluating selection criteria for
rule 'map full name to destination object name'.
[05/26/08 13:56:44.027]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:44.027]:ADTRACE ST: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:44.027]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.028]:ADTRACE ST: Evaluating selection criteria for
rule 'escape source object name'.
[05/26/08 13:56:44.028]:ADTRACE ST: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:44.028]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.028]:ADTRACE ST: Evaluating selection criteria for
rule 'map rename to NT logon name'.
[05/26/08 13:56:44.028]:ADTRACE ST: (if-global-variable
'LogonNameMap' equal "true") = TRUE.
[05/26/08 13:56:44.028]:ADTRACE ST: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:44.028]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.028]:ADTRACE ST: Evaluating selection criteria for
rule 'map rename to Active Directory logon name'.
[05/26/08 13:56:44.028]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-name-auth") = FALSE.
[05/26/08 13:56:44.028]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.028]:ADTRACE ST: Evaluating selection criteria for
rule 'map e-mail address to Active Directory logon name'.
[05/26/08 13:56:44.028]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:44.028]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.028]:ADTRACE ST: Evaluating selection criteria for
rule 'unmap e-mail address from Active Directory logon name'.
[05/26/08 13:56:44.028]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:44.028]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.028]:ADTRACE ST: Evaluating selection criteria for
rule 'map e-mail address to Active Directory logon name on merge'.
[05/26/08 13:56:44.028]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:44.028]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.028]:ADTRACE ST: Evaluating selection criteria for
rule 'unmap e-mail address from Active Directory logon name on merge'.
[05/26/08 13:56:44.029]:ADTRACE ST: (if-global-variable 'UpnMap'
equal "edir-mail-auth") = FALSE.
[05/26/08 13:56:44.029]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.029]:ADTRACE ST: Evaluating selection criteria for
rule 'discard unwanted renames'.
[05/26/08 13:56:44.029]:ADTRACE ST: (if-global-variable
'FullNameMap' equal "true") = TRUE.
[05/26/08 13:56:44.029]:ADTRACE ST: (if-operation equal "rename") =
FALSE.
[05/26/08 13:56:44.029]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.029]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.029]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="nspmDistributionPassword"><!-- content
suppressed -->
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.030]:ADTRACE ST:Applying policy: %+C%14C'Transform
NMAS attribute to password elements'%-C.
[05/26/08 13:56:44.030]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.030]:ADTRACE ST: Evaluating selection criteria for
rule 'Convert adds of the nspmDistributionPassword attribute to password
elements'.
[05/26/08 13:56:44.030]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:44.030]:ADTRACE ST: (if-op-attr
'nspmDistributionPassword' available) = TRUE.
[05/26/08 13:56:44.030]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.030]:ADTRACE ST: Applying rule 'Convert adds of
the nspmDistributionPassword attribute to password elements'.
[05/26/08 13:56:44.030]:ADTRACE ST: Action:
do-set-dest-password(token-xpath("add-attr[@attr-name='nspmDistributionPassword']//value")).
[05/26/08 13:56:44.030]:ADTRACE ST:
arg-string(token-xpath("add-attr[@attr-name='nspmDistributionPassword']//value"))
[05/26/08 13:56:44.030]:ADTRACE ST:
token-xpath("add-attr[@attr-name='nspmDistributionPassword']//value")
[05/26/08 13:56:44.030]:ADTRACE ST: Token Value: "--
suppressed --".
[05/26/08 13:56:44.030]:ADTRACE ST: Arg Value: "-- suppressed --".
[05/26/08 13:56:44.030]:ADTRACE ST: Action:
do-strip-op-attr("nspmDistributionPassword").
[05/26/08 13:56:44.030]:ADTRACE ST: Evaluating selection criteria for
rule 'Block modifies for failed password publish operations if reset
password is false'.
[05/26/08 13:56:44.031]:ADTRACE ST: (if-global-variable
'reset-external-password-on-failure' equal "false") = FALSE.
[05/26/08 13:56:44.031]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.031]:ADTRACE ST: Evaluating selection criteria for
rule 'Convert modifies of a nspmDistributionPassword attribute to a
modify password operation'.
[05/26/08 13:56:44.031]:ADTRACE ST: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:44.031]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.031]:ADTRACE ST: Evaluating selection criteria for
rule 'Block empty modify operations'.
[05/26/08 13:56:44.031]:ADTRACE ST: (if-operation equal "modify") =
FALSE.
[05/26/08 13:56:44.031]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.031]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.031]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.032]:ADTRACE ST:Applying policy:
%+C%14CPassword(Sub)-Default Password Policy%-C.
[05/26/08 13:56:44.032]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.032]:ADTRACE ST: Evaluating selection criteria for
rule 'On User add, provide default password of Surname if no password
exists'.
[05/26/08 13:56:44.032]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:44.032]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:44.032]:ADTRACE ST: (if-password not-available) =
FALSE.
[05/26/08 13:56:44.032]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.032]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.032]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.033]:ADTRACE ST:Applying policy: %+C%14C'Subscribe to
password changes'%-C.
[05/26/08 13:56:44.033]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.033]:ADTRACE ST: Evaluating selection criteria for
rule 'Block subscribing to passwords when objects are added'.
[05/26/08 13:56:44.033]:ADTRACE ST: (if-global-variable
'enable-password-subscribe' equal "false") = FALSE.
[05/26/08 13:56:44.033]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.033]:ADTRACE ST: Evaluating selection criteria for
rule 'Block subscribing to password modifications'.
[05/26/08 13:56:44.033]:ADTRACE ST: (if-global-variable
'enable-password-subscribe' equal "false") = FALSE.
[05/26/08 13:56:44.033]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.033]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.034]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data
unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT"/>
</add>
</input>
</nds>
[05/26/08 13:56:44.034]:ADTRACE ST:Applying policy: %+C%14C'Payloads for
subscribe to password changes'%-C.
[05/26/08 13:56:44.034]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.034]:ADTRACE ST: Evaluating selection criteria for
rule 'Add operation-data element to password subscribe operations'.
[05/26/08 13:56:44.034]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:44.034]:ADTRACE ST: (if-password available) = TRUE.
[05/26/08 13:56:44.034]:ADTRACE ST: (if-xpath not-true
"operation-data") = FALSE.
[05/26/08 13:56:44.034]:ADTRACE ST: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:44.034]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.034]:ADTRACE ST: Evaluating selection criteria for
rule 'Add payload data to a reset password from a failed password
publish operation'.
[05/26/08 13:56:44.034]:ADTRACE ST: (if-operation equal
"modify-password") = FALSE.
[05/26/08 13:56:44.035]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.035]:ADTRACE ST: Evaluating selection criteria for
rule 'Add payload data to password subscribe operations'.
[05/26/08 13:56:44.035]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:44.035]:ADTRACE ST: (if-password available) = TRUE.
[05/26/08 13:56:44.035]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.035]:ADTRACE ST: Applying rule 'Add payload data
to password subscribe operations'.
[05/26/08 13:56:44.035]:ADTRACE ST: Action:
do-append-xml-element("password-subscribe-status","operation-data").
[05/26/08 13:56:44.035]:ADTRACE ST: Action:
do-append-xml-element("association","operation-data/password-subscribe-status").
[05/26/08 13:56:44.035]:ADTRACE ST: Action:
do-append-xml-text("operation-data/password-subscribe-status/association",token-association()).
[05/26/08 13:56:44.035]:ADTRACE ST: arg-string(token-association())
[05/26/08 13:56:44.035]:ADTRACE ST: token-association()
[05/26/08 13:56:44.035]:ADTRACE ST: Token Value: "".
[05/26/08 13:56:44.035]:ADTRACE ST: Arg Value: "".
[05/26/08 13:56:44.035]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.036]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:44.036]:ADTRACE ST:Applying policy: %+C%14C'Resolve
group memberships on an add user'%-C.
[05/26/08 13:56:44.036]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.036]:ADTRACE ST: Evaluating selection criteria for
rule 'Add new user to associated groups'.
[05/26/08 13:56:44.036]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:44.036]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:44.036]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.036]:ADTRACE ST: Applying rule 'Add new user to
associated groups'.
[05/26/08 13:56:44.036]:ADTRACE ST: Action:
do-set-local-variable("groupAssociations",arg-node-set(token-xpath("empty"))).
[05/26/08 13:56:44.036]:ADTRACE ST:
arg-node-set(token-xpath("empty"))
[05/26/08 13:56:44.037]:ADTRACE ST: token-xpath("empty")
[05/26/08 13:56:44.037]:ADTRACE ST: Token Value: {}.
[05/26/08 13:56:44.037]:ADTRACE ST: Arg Value: {}.
[05/26/08 13:56:44.037]:ADTRACE ST: Action:
do-for-each(arg-node-set(token-src-attr("Group Membership"))).
[05/26/08 13:56:44.037]:ADTRACE ST:
arg-node-set(token-src-attr("Group Membership"))
[05/26/08 13:56:44.037]:ADTRACE ST: token-src-attr("Group
Membership")
[05/26/08 13:56:44.037]:ADTRACE ST: Query from policy
[05/26/08 13:56:44.037]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<query class-name="User"
dest-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" dest-entry-id="35238"
scope="entry">
<read-attr attr-name="Group Membership"/>
</query>
</input>
</nds>
[05/26/08 13:56:44.037]:ADTRACE ST: Pumping XDS to eDirectory.
[05/26/08 13:56:44.037]:ADTRACE ST: Performing operation
query for \IDMEDIR\Users\HESOCT\Testbak\teststud1.
[05/26/08 13:56:44.038]:ADTRACE ST: Query from policy result
[05/26/08 13:56:44.038]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<instance class-name="User"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<association state="manual"></association>
</instance>
<status level="success"></status>
</output>
</nds>
[05/26/08 13:56:44.038]:ADTRACE ST: Token Value: {}.
[05/26/08 13:56:44.038]:ADTRACE ST: Arg Value: {}.
[05/26/08 13:56:44.039]:ADTRACE ST: Action:
do-for-each(arg-node-set(token-local-variable("groupAssociations"))).
[05/26/08 13:56:44.039]:ADTRACE ST:
arg-node-set(token-local-variable("groupAssociations"))
[05/26/08 13:56:44.039]:ADTRACE ST:
token-local-variable("groupAssociations")
[05/26/08 13:56:44.039]:ADTRACE ST: Token Value: {}.
[05/26/08 13:56:44.039]:ADTRACE ST: Arg Value: {}.
[05/26/08 13:56:44.039]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.039]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="User" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="Full Name">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="Given Name">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="Internet EMail Address">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="Surname">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="DirXML-ADAliasName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="Login Disabled">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:44.040]:ADTRACE ST:Filtering out notification-only
attributes.
[05/26/08 13:56:44.040]:ADTRACE ST:Fixing up association references.
[05/26/08 13:56:44.040]:ADTRACE ST:Applying schema mapping policies to
output.
[05/26/08 13:56:44.040]:ADTRACE ST:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:44.040]:ADTRACE ST: Mapping attr-name 'Full Name' to
'displayName'.
[05/26/08 13:56:44.040]:ADTRACE ST: Mapping attr-name 'Given Name' to
'givenName'.
[05/26/08 13:56:44.040]:ADTRACE ST: Mapping attr-name 'Internet EMail
Address' to 'mail'.
[05/26/08 13:56:44.040]:ADTRACE ST: Mapping attr-name 'Surname' to 'sn'.
[05/26/08 13:56:44.040]:ADTRACE ST: Mapping attr-name
'DirXML-ADAliasName' to 'sAMAccountName'.
[05/26/08 13:56:44.040]:ADTRACE ST: Mapping attr-name 'Login Disabled'
to 'dirxml-uACAccountDisable'.
[05/26/08 13:56:44.040]:ADTRACE ST: Mapping class-name 'User' to 'user'.
[05/26/08 13:56:44.041]:ADTRACE ST:Applying output transformation policies.
[05/26/08 13:56:44.041]:ADTRACE ST:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in Active Directory.'%-C.
[05/26/08 13:56:44.042]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.042]:ADTRACE ST: Evaluating selection criteria for
rule 'Street Address: Convert LF to CR-LF'.
[05/26/08 13:56:44.042]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.042]:ADTRACE ST: Applying rule 'Street Address:
Convert LF to CR-LF'.
[05/26/08 13:56:44.042]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
[05/26/08 13:56:44.043]:ADTRACE ST: Evaluating selection criteria for
rule 'logonHours: Convert to Active Directory form'.
[05/26/08 13:56:44.043]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.043]:ADTRACE ST: Applying rule 'logonHours:
Convert to Active Directory form'.
[05/26/08 13:56:44.043]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
[05/26/08 13:56:44.043]:ADTRACE ST: Evaluating selection criteria for
rule 'accountExpires: Convert to Active Directory form'.
[05/26/08 13:56:44.043]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.043]:ADTRACE ST: Applying rule 'accountExpires:
Convert to Active Directory form'.
[05/26/08 13:56:44.043]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:44.043]:ADTRACE ST: Evaluating selection criteria for
rule 'lockoutTime: Convert to Active Directory form'.
[05/26/08 13:56:44.043]:ADTRACE ST: Rule selected.
[05/26/08 13:56:44.043]:ADTRACE ST: Applying rule 'lockoutTime:
Convert to Active Directory form'.
[05/26/08 13:56:44.043]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
[05/26/08 13:56:44.043]:ADTRACE ST: Evaluating selection criteria for
rule 'Add: User - convert multi-valued Telephone to single value'.
[05/26/08 13:56:44.043]:ADTRACE ST: (if-operation equal "add") = TRUE.
[05/26/08 13:56:44.043]:ADTRACE ST: (if-class-name equal "User") =
TRUE.
[05/26/08 13:56:44.043]:ADTRACE ST: (if-op-attr 'telephoneNumber'
available) = FALSE.
[05/26/08 13:56:44.043]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.043]:ADTRACE ST: Evaluating selection criteria for
rule 'update Active Directory logon name'.
[05/26/08 13:56:44.044]:ADTRACE ST: (if-xpath true
"self::status[@level =
'success']/operation-data/windows-2000-logon-name") = FALSE.
[05/26/08 13:56:44.044]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.044]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.044]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:44.044]:ADTRACE ST:Applying policy: %+C%14C'Email
notifications for failed password publications'%-C.
[05/26/08 13:56:44.045]:ADTRACE ST: Applying to add #1.
[05/26/08 13:56:44.045]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail for a failed publish password operation'.
[05/26/08 13:56:44.045]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:44.045]:ADTRACE ST: (if-operation equal "status") =
FALSE.
[05/26/08 13:56:44.045]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:44.045]:ADTRACE ST:Policy returned:
[05/26/08 13:56:44.045]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:44.046]:ADTRACE ST:Submitting document to subscriber shim:
[05/26/08 13:56:44.046]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</add>
</input>
</nds>
[05/26/08 13:56:44.047]:ADTRACE ST:Stripping operation data from input
document
[05/26/08 13:56:44.047]:ADTRACE ST:Remote Interface Driver: Sending...
[05/26/08 13:56:44.047]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<source>
<product version="3.5.10.20070918 ">DirXML</product>
<contact>Novell, Inc.</contact>
</source>
<input>
<add class-name="user" dest-dn="CN=test
tester,OU=Testbak,OU=HESOCT,OU=SynchronizedUsers,D C=tse,DC=local"
event-id="IDMVAULT#20080526115629#1#1"
qualified-src-dn="O=Users\OU=HESOCT\OU=Testbak\CN=teststud1"
src-dn="\IDMEDIR\Users\HESOCT\Testbak\teststud1" src-entry-id="35238">
<add-attr attr-name="displayName">
<value timestamp="1204884219#6" type="string">test tester</value>
</add-attr>
<add-attr attr-name="givenName">
<value timestamp="1204884219#4" type="string">test</value>
</add-attr>
<add-attr attr-name="mail">
<value timestamp="1205329608#1"
type="string">teststud1@student.edith.nl</value>
</add-attr>
<add-attr attr-name="sn">
<value timestamp="1204884219#3" type="string">tester</value>
</add-attr>
<add-attr attr-name="sAMAccountName">
<value type="string">teststud1</value>
</add-attr>
<add-attr attr-name="dirxml-uACAccountDisable">
<value type="string">false</value>
</add-attr>
<password><!-- content suppressed --></password>
</add>
</input>
</nds>
[05/26/08 13:56:44.048]:ADTRACE ST:Remote Interface Driver: Document sent.
[05/26/08 13:56:45.911]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:56:45.911]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115629#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
</status>
</output>
</nds>
[05/26/08 13:56:45.911]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:56:45.911]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:56:45.911]:ADTRACE ST:Restoring operation data to output
document
[05/26/08 13:56:45.911]:ADTRACE ST:SubscriptionShim.execute() returned:
[05/26/08 13:56:45.911]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115629#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
[05/26/08 13:56:45.912]:ADTRACE ST:Applying input transformation policies.
[05/26/08 13:56:45.912]:ADTRACE ST:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:56:45.912]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:45.912]:ADTRACE ST: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:56:45.912]:ADTRACE ST: Rule selected.
[05/26/08 13:56:45.912]:ADTRACE ST: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:56:45.912]:ADTRACE ST: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:56:45.912]:ADTRACE ST: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:56:45.912]:ADTRACE ST: Rule selected.
[05/26/08 13:56:45.912]:ADTRACE ST: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:56:45.912]:ADTRACE ST: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:56:45.912]:ADTRACE ST: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:56:45.912]:ADTRACE ST: Rule selected.
[05/26/08 13:56:45.912]:ADTRACE ST: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:56:45.912]:ADTRACE ST: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:45.913]:ADTRACE ST: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:56:45.913]:ADTRACE ST: Rule selected.
[05/26/08 13:56:45.913]:ADTRACE ST: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:56:45.913]:ADTRACE ST: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:56:45.913]:ADTRACE ST:Policy returned:
[05/26/08 13:56:45.913]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115629#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
[05/26/08 13:56:45.913]:ADTRACE ST:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:56:45.913]:ADTRACE ST: Applying to status #1.
[05/26/08 13:56:45.913]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:56:45.914]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:45.914]:ADTRACE ST: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:45.914]:ADTRACE ST: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:56:45.914]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:45.914]:ADTRACE ST: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:56:45.914]:ADTRACE ST: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:56:45.914]:ADTRACE ST: (if-operation equal "status") =
TRUE.
[05/26/08 13:56:45.914]:ADTRACE ST: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:56:45.914]:ADTRACE ST: Rule rejected.
[05/26/08 13:56:45.914]:ADTRACE ST:Policy returned:
[05/26/08 13:56:45.914]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status event-id="IDMVAULT#20080526115629#1#1" level="warning"
type="driver-general">
<ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No
Such Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001
(NO_OBJECT), data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
<operation-data unmatched-src-dn="CN=teststud1,OU=Testbak,OU=HESOCT">
<password-subscribe-status>
<association/>
</password-subscribe-status>
</operation-data>
</status>
</output>
</nds>
[05/26/08 13:56:45.915]:ADTRACE ST:Applying schema mapping policies to
input.
[05/26/08 13:56:45.915]:ADTRACE ST:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:56:45.915]:ADTRACE ST:Resolving association references.
[05/26/08 13:56:45.915]:ADTRACE ST:Processing returned document.
[05/26/08 13:56:45.915]:ADTRACE ST:Processing operation <status> for .
[05/26/08 13:56:45.916]:ADTRACE ST:
DirXML Log Event -------------------
Driver: \IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active
Directory
Channel: Subscriber
Object: \IDMEDIR\Users\HESOCT\Testbak\teststud1
Status: Warning
Message: <ldap-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">
<client-err ldap-rc="32" ldap-rc-name="LDAP_NO_SUCH_OBJECT">No Such
Object</client-err>
<server-err>0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT),
data 0, best match of:
'OU=SynchronizedUsers,DC=tse,DC=local'
</server-err>
<server-err-ex win32-rc="8333"/>
</ldap-err>
[05/26/08 13:56:46.227]:ADTRACE ST:End transaction.
[05/26/08 13:57:24.378]:ADTRACE ST:Received state change event.
[05/26/08 13:57:24.379]:ADTRACE ST:Transitioned from state
'%+C%14CRunning%-C' to state '%+C%14CShutdown Pending%-C'.
[05/26/08 13:57:24.379]:ADTRACE ST:Successfully processed state change
event.
[05/26/08 13:57:24.379]:ADTRACE ST:Leaving event loop.
[05/26/08 13:57:24.379]:ADTRACE ST:Shutting down DirXML driver
\IDMEDIR\IDM Driver Set\Identity Manager Drivers\Active Directory.
[05/26/08 13:57:24.379]:ADTRACE ST:Remote Interface Driver: Sending...
[05/26/08 13:57:24.379]:ADTRACE ST:
<nds dtdversion="3.5" ndsversion="8.x">
<input/>
</nds>
[05/26/08 13:57:24.379]:ADTRACE ST:Remote Interface Driver: Document sent.
[05/26/08 13:57:24.494]:ADTRACE :Remote Interface Driver: Received.
[05/26/08 13:57:24.495]:ADTRACE :
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status level="success"/>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</output>
</nds>
[05/26/08 13:57:24.495]:ADTRACE :Remote Interface Driver: Received
document for subscriber channel
[05/26/08 13:57:24.495]:ADTRACE :Remote Interface Driver: Waiting for
receive...
[05/26/08 13:57:24.495]:ADTRACE ST:Remote Interface Publisher: Received
shutdown.
[05/26/08 13:57:24.495]:ADTRACE ST:Remote Interface Driver: Closing
connection...
[05/26/08 13:57:24.495]:ADTRACE :Remote Interface Driver: Closing
connection...
[05/26/08 13:57:24.495]:ADTRACE :Remote Interface Driver: Connection closed
[05/26/08 13:57:24.495]:ADTRACE PT:PublicationShim.start() returned:
[05/26/08 13:57:24.495]:ADTRACE ST:Remote Interface Driver: Connection
closed
[05/26/08 13:57:24.495]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:57:24.495]:ADTRACE ST:Remote Interface Subscriber: Received
shutdown.
[05/26/08 13:57:24.495]:ADTRACE PT:Applying input transformation policies.
[05/26/08 13:57:24.495]:ADTRACE STriverShim.shutdown() returned:
[05/26/08 13:57:24.495]:ADTRACE PT:Applying policy: %+C%14C'Convert
selected attributes to a form most commonly used in the Identity Vault.'%-C.
[05/26/08 13:57:24.496]:ADTRACE ST:
<nds dtdversion="1.1" ndsversion="8.7">
<source>
<product asn1id="" build="20070823_095000" instance="\IDMEDIR\IDM
Driver Set\Identity Manager Drivers\Active Directory"
version="3.5.1">AD</product>
<contact>Novell, Inc.</contact>
</source>
<output>
<status level="success"/>
<init-params event-id="write state">
<publisher-state>

<cookie>TVNEUwMAAADGbAdsIL/IAQAAAAAAAAAAQAAAADMwAgAAAAAAAAAAAAAAAAAzMAIAAAAAA EU0fgPcFZ5MntWKBv7ZCFEBAAAAAAAAAAIAAAAAAAAARTR+A9w Vnkye1YoG/tkIUZ8wAgAAAAAAD5oDvP7PfkGJ3P+/8Tu9McQAAQAAAAAA</cookie>
</publisher-state>
</init-params>
</output>
</nds>
[05/26/08 13:57:24.496]:ADTRACE PT: Applying to status #1.
[05/26/08 13:57:24.496]:ADTRACE PT: Evaluating selection criteria for
rule 'streetAddress: Convert CR-LF to LF'.
[05/26/08 13:57:24.496]:ADTRACE PT: Rule selected.
[05/26/08 13:57:24.496]:ADTRACE PT: Applying rule 'streetAddress:
Convert CR-LF to LF'.
[05/26/08 13:57:24.496]:ADTRACE PT: Action:
do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
[05/26/08 13:57:24.496]:ADTRACE PT: Evaluating selection criteria for
rule 'logonHours: Convert to Login Allowed Time Map form'.
[05/26/08 13:57:24.496]:ADTRACE ST:Reading XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverStorage.
[05/26/08 13:57:24.496]:ADTRACE PT: Rule selected.
[05/26/08 13:57:24.496]:ADTRACE PT: Applying rule 'logonHours:
Convert to Login Allowed Time Map form'.
[05/26/08 13:57:24.496]:ADTRACE PT: Action:
do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
[05/26/08 13:57:24.496]:ADTRACE PT: Evaluating selection criteria for
rule 'accountExpires: Convert to Identity Vault time format'.
[05/26/08 13:57:24.497]:ADTRACE PT: Rule selected.
[05/26/08 13:57:24.497]:ADTRACE PT: Applying rule 'accountExpires:
Convert to Identity Vault time format'.
[05/26/08 13:57:24.497]:ADTRACE PT: Action:
do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:57:24.497]:ADTRACE ST:Writing driver state.
[05/26/08 13:57:24.497]:ADTRACE PT: Evaluating selection criteria for
rule 'lockoutTime: Convert to Identity Vault time format'.
[05/26/08 13:57:24.497]:ADTRACE PT: Rule selected.
[05/26/08 13:57:24.497]:ADTRACE PT: Applying rule 'lockoutTime:
Convert to Identity Vault time format'.
[05/26/08 13:57:24.497]:ADTRACE ST:Writing XML attribute
vnd.nds.stream://IDMEDIR/IDM+Driver+Set/Identity+Manager+Drivers/Active+Directory#DirXML-DriverStorage.
[05/26/08 13:57:24.497]:ADTRACE PT: Action:
do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
[05/26/08 13:57:24.497]:ADTRACE PT:Policy returned:
[05/26/08 13:57:24.497]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:57:24.497]:ADTRACE PT:Applying policy: %+C%14C'Email
notifications for failed password subscriptions'%-C.
[05/26/08 13:57:24.497]:ADTRACE PT: Applying to status #1.
[05/26/08 13:57:24.497]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on a failure when subscribing to passwords'.
[05/26/08 13:57:24.497]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:57:24.497]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:57:24.497]:ADTRACE PT: (if-xpath true
"self::status[@level != 'success'][text() !=
'']/operation-data/password-subscribe-status/association[text() != '']")
= FALSE.
[05/26/08 13:57:24.498]:ADTRACE PT: Rule rejected.
[05/26/08 13:57:24.498]:ADTRACE PT: Evaluating selection criteria for
rule 'Send e-mail on failure to reset connected system password using
the Identity Manager data store password'.
[05/26/08 13:57:24.498]:ADTRACE PT: (if-global-variable
'notify-user-on-password-dist-failure' equal "true") = TRUE.
[05/26/08 13:57:24.498]:ADTRACE PT: (if-operation equal "status") =
TRUE.
[05/26/08 13:57:24.498]:ADTRACE PT: (if-xpath true
"self::status[@level !=
'success']/operation-data/password-reset-status") = FALSE.
[05/26/08 13:57:24.498]:ADTRACE PT: Rule rejected.
[05/26/08 13:57:24.498]:ADTRACE PT:Policy returned:
[05/26/08 13:57:24.498]:ADTRACE PT:
<nds dtdversion="3.5" ndsversion="8.x">
<output>
<status level="success"/>
</output>
</nds>
[05/26/08 13:57:24.498]:ADTRACE PT:Applying schema mapping policies to
input.
[05/26/08 13:57:24.498]:ADTRACE PT:Applying policy: %+C%14CSchemaMapping%-C.
[05/26/08 13:57:24.498]:ADTRACE PT:Resolving association references.
[05/26/08 13:57:24.498]:ADTRACE PT:Ending publisher thread.
[05/26/08 13:57:24.714]:ADTRACE ST:Waiting for Publisher thread to
terminate...
[05/26/08 13:57:24.714]:ADTRACE ST:Publisher thread terminated.
[05/26/08 13:57:24.722]:ADTRACE STriver terminated.