Skip Headers
Oracle® Fusion Middleware Release Notes
11g Release 1 (11.1.1) for IBM AIX on POWER System (64-Bit)

Part Number E14771-34
Go to Documentation Home
Home
Go to Book List
Book List
Go to Table of Contents
Contents
Go to Master Index
Master Index
Go to Feedback page
Contact Us

Go to previous page
Previous
Go to next page
Next
PDF · Mobi · ePub

21 Oracle Directory Integration Platform

This chapter describes issues associated with Oracle Directory Integration Platform. It includes the following topics:

21.1 General Issues and Workarounds

This section describes general issues and workarounds. It includes the following topics:

21.1.1 The Oracle Password Filter for Microsoft Active Directory is not Certified for use With Oracle Unified Directory or Oracle Directory Server Enterprise Edition

To use the Oracle Password Filter for Microsoft Active Directory, your Oracle back-end directory must be Oracle Internet Directory. The Oracle Unified Directory back-end directory and the Oracle Directory Server Enterprise Edition back-end directory do not support integration with the Oracle Password Filter for Microsoft Active Directory.

21.1.2 LDIF Files That Contain Non-ASCII Characters Will Cause the testProfile Command Option to Fail if the LDIF File has Native Encoding

When running DIP Tester from a command-line, the manageSyncProfiles testProfile command will fail if the -ldiffile option is specified and the LDIF file contains non-ASCII characters.

Note that LDIF files with UTF-8 encoding are not impacted by this limitation. If an LDIF file containing multibyte characters cannot be saved with UTF-8 encoding, then use the following workaround:

  1. From a command-line, add the entry using the ldapadd command and include the -E option to specify the locale. See the Oracle Fusion Middleware User Reference for Oracle Identity Management for the required command syntax.

  2. Get the specific changeNumber for the last add operation.

  3. Execute the testProfile command using the changeNumber from the previous step.

For more information, see "Section 7.1.5.2, Running DIP Tester From the WLST Command-Line Interface" in the Administrator's Guide for Oracle Directory Integration Platform.

21.1.3 Some Changes May Not Get Synchronized Due to Race Condition in Heavily-Loaded Source Directory

If the source directory is heavily-loaded, a race condition may occur where database commits cannot keep pace with updates to the lastchangenumber. If this race condition occurs, Oracle Directory Integration Platform may not be able to synchronize some of the changes.

To work around this issue, perform the following steps to enable database commits to keep pace with the lastchangenumber:

  1. Increase the value of the synchronization profile's Scheduling Interval.

  2. Control the number of times the search is performed on the source directory during a synchronization cycle by setting the searchDeltaSize parameter in the profile. Oracle suggests starting with a value of 10, then adjusting the value as needed.

21.1.4 Synchronization Continues After Stopping Oracle Directory Integration Platform

If you stop the Oracle Directory Integration Platform application during synchronization, the synchronization process that the Quartz scheduler started will continue to run.

To work around this issue, restart the Oracle WebLogic Managed Server hosting Oracle Directory Integration Platform or redeploy the Oracle Directory Integration Platform application.

21.2 Configuration Issues and Workarounds

This section describes configuration issues and their workarounds. It includes the following topics:

21.2.1 Do not use localhost as Oracle Internet Directory Hostname When Configuring Oracle Directory Integration Platform

When configuring Oracle Directory Integration Platform against an existing Oracle Internet Directory—using either the installer's Install and Configure installation option or the Oracle Identity Management 11g Release 1 (11.1.1) Configuration Wizard—you must specify the hostname for Oracle Internet Directory using only its fully qualified domain name (such as myhost.example.com). Do not use localhost as the Oracle Internet Directory hostname even if Oracle Directory Integration Platform and Oracle Internet Directory are collocated on the same host.

If you use localhost as the Oracle Internet Directory hostname, you will not be able to start the Oracle WebLogic Managed Server hosting Oracle Directory Integration Platform.

21.2.2 DIP Deployment Fails on AIX During 11g Configuration While Upgrading From 10.1.4. IM

11g configuration fails on IBM AIX on POWER Systems (64-Bit) during the deployment of Oracle Directory Integration Platform with the following exception shown in the installation logs while upgrading from 10.1.4 IM:

2011-04-06T07:45:46.353+00:00] [as] [ERROR] [] [oracle.as.provisioning]
[tid: 2] [ecid: 0000IwdcrC07q2P_UdG7yc1Db11s000003,0] DIP-00004: Error in
connecting to Oracle Internet Directory Server.[[
[2011-04-06T07:45:46.353+00:00] [as] [ERROR] [] [oracle.as.provisioning]
[tid: 2] [ecid: 0000IwdcrC07q2P_UdG7yc1Db11s000003,0] DIP-00022: Connection
to LDAP server failed.
[2011-04-06T07:45:46.353+00:00] [as] [ERROR] [] [oracle.as.provisioning]
[tid: 2] [ecid: 0000IwdcrC07q2P_UdG7yc1Db11s000003,0] DIP-00004: Error in
connecting to Oracle Internet Directory Server.[[
javax.naming.CommunicationException: simple bind failed:
stuzu23.us.oracle.com:636 [Root exception is javax.net.ssl.SSLException:
Received fatal alert: unexpected_message]
       at com.sun.jndi.ldap.LdapClient.authenticate(LdapClient.java:197)
       at com.sun.jndi.ldap.LdapCtx.connect(LdapCtx.java:2694)
       at com.sun.jndi.ldap.LdapCtx.<init>(LdapCtx.java:293)
       at
com.sun.jndi.ldap.LdapCtxFactory.getUsingURL(LdapCtxFactory.java:175)
       at
com.sun.jndi.ldap.LdapCtxFactory.getUsingURLs(LdapCtxFactory.java:193)
       at
com.sun.jndi.ldap.LdapCtxFactory.getLdapCtxInstance(LdapCtxFactory.java:136)
       at
com.sun.jndi.ldap.LdapCtxFactory.getInitialContext(LdapCtxFactory.java:66)
       at
javax.naming.spi.NamingManager.getInitialContext(NamingManager.java:235)

This issue occurs as the starting point for Oracle Internet Directory (OID) upgrade is an an earlier version of OID. For example, 10.1.4.0.1.

To workaround this issue, upgrade to 10.1.4.3 version of OID before upgrading to 11.1.1.5.0 (PS4).

21.2.3 You may Need to Restart the Directory Integration Platform After Running dipConfigurator Against Oracle Unified Directory

After running dipConfigurator against an Oracle Unified Directory (OUD) endpoint, if you are unable to open the Directory Integration Platform (DIP) UI in Enterprise Manger, stop and start DIP to fix the UI problem.

21.2.4 When Configuring a Profile, you may Need to Scroll Past a Section of Whitespace to View Mapping Rules

If you are using Internet Explorer to view the Directory Integration Platform (DIP) UI, you may need to scroll past a large blank space to see the profile mapping rules section. This issue is not known to affect other browsers.

21.2.5 Resource Usage Charts will not Display if Multiple IDM Domains are Running on the Same Host

If two IDM domains on the same host share the same Oracle home and are both configured to use wls_ods1 managed servers, then the DIP home page will not display the resource usage charts if both instances are running at the same time.

21.3 Documentation Errata

There are no known documentation issues at this time.