Re: Active Directory Integration

2015-03-05 Thread Terje Moglestue
Koyb,

How long is a string?

It is difficult or impossible to answer your question. You state, "data in AD 
is messed up" - I assume you got very poor data quality, no naming standard, 
lack of phone number standard, use of incorrect fields, no good unique 
identifier, no standard for department names and more.
There is nothing like a "typical integration" every project is different. Are 
you going to have a one way feed? What about leaver? Are you going to automate 
the leavers' process?
Who or what if feeding AD? Created manually? Integrated with different HR 
systems? Who owns the AD data? How is responsible for maintenance of AD? Is it 
maintained?

If AD is the source of People data in BMC - please do not forget: shit in shit 
out!
Creating staging forms and more within BMC is good and well. Most of us have 
done that a number of times. My first advice would be to clean the data at 
source. AD is more likely feeding a number of systems. I would recommend a AD 
cleanup project. That will benefit a larger audience.

~
Terje

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Koyb P. Liabt
Sent: Thursday, March 05, 2015 5:03 PM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

**
Hi,

Environment: 8.1 x  Oracle 11 R2.  We are trying to integrate AD with Remedy to 
update our people profiles.  Our challenge is that the data in AD is messed up. 
 Approximately how long does it take to typically integrate AD and Remedy (when 
there are data problems)? (from the concept until completion).

We have a couple of options:

create vendor forms
create staging form
create escalation from push AD to Vendor, and from the Vendor to Staging

OR

should I used UDM?

or pre-defined LDAP jobs
use DMT staging form - to validate
LDAP filters

Which approach is better is better? and what are some of the advantages / 
disadvantages?



_ARSlist: "Where the Answers Are" and have been for 20 years_

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Active Directory Integration

2015-03-05 Thread Koyb P. Liabt
Hi,
 
Environment: 8.1 x  Oracle 11 R2.  We are trying to integrate AD  with 
Remedy to update our people profiles.  Our challenge is that the data  in AD is 
messed up.  Approximately how long does it take to typically  integrate AD 
and Remedy (when there are data problems)? (from the concept  until 
completion).  
 
We have a couple of options:
 
create vendor forms
create staging form
create escalation from push AD to Vendor, and from the Vendor to  Staging
 
OR
 
should I used UDM?
 
or pre-defined LDAP jobs
use DMT staging form - to validate
LDAP filters
 
Which approach is better is better? and what are some of the advantages /  
disadvantages?
 
 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"
 

Re: Active Directory Integration Problem

2013-03-25 Thread rajkiran Alle
Hi,

I am working on this task to sync LDAP records with People form. So in that 
process i created a Vendor form to retrieve records from LDAP table and its 
throwing a error(ARERR [91] RPC call failed : RPC: Unable to receive; 
Asynchronous event occurred) while getting the records but when i search for 
single record its retrieving. We have more than 100k records in LDAP and i am 
guessing its not able to retrieve that a huge number.

Is there any way i can avoid this problem and get all the records in to my 
Vendor form.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-22 Thread Jason Miller
Here is a link to the LDAP import document: Configuring Data Management for
LDAP or LDAPS 
import<https://docs.bmc.com/docs/display/public/itsm80/Configuring+Data+Management+for+LDAP+or+LDAPS+import>
.

Here is some info regarding the changes that were introduced in 8.0:
Enhancements
to Data 
Management<https://docs.bmc.com/docs/display/public/itsm80/Enhancements+to+Data+Management>
.

Jason


On Fri, Mar 22, 2013 at 9:44 AM, Logan, Kelly wrote:

> **
>
> Aditya - I have an integration with People (and Attributes) that I am
> running now on ARS/ITSM 7.6.4 following this strategy. I bring the data
> into a staging form, run some queries to set the Manager Login ID, Site ID
> and such  (similar to the Data management tool) and then push to the People
> and Attribute forms. Feel free to contact m
>
> ** **
>
> Karthik – That Pentaho transform sounds very interesting. Is there any
> documentation on it? I was under the impression that you couldn’t run an
> Integrator job to connect to the People form, did this change in 8.x?
>
> ** **
>
> *Kelly Logan*, Sr. Systems Administrator (Remedy, Planview), GEMS
>
> ProQuest | 789 E. Eisenhower Parkway, P.O. Box 1346 | Ann Arbor MI
> 48106-1346 USA | 734.997.4777 
>
> kelly.lo...@proquest.com
>
> www.proquest.com 
>
> ** **
>
> *ProQuest*...Start here. . 2012 InformationWeek 500 Top Innovator | 2012
> Detroit Free Press Michigan Top Workplace
>
> ** **
>
> P Please consider the environment before printing this email. 
>
> ** **
>
> *This email and any files transmitted with it are confidential and
> intended solely for the use of the individual or entity to whom they are
> addressed. If you have received this email in error please notify the
> sender, and delete the message from your computer*.
>
> ** **
>
> *From:* Action Request System discussion list(ARSList) [mailto:
> arslist@ARSLIST.ORG] *On Behalf Of *Karthik
> *Sent:* Thursday, March 21, 2013 10:44 PM
> *To:* arslist@ARSLIST.ORG
> *Subject:* Re: Active Directory Integration Problem
>
> ** **
>
> ** 
>
> Which version of arsystem are you using. If 8.0, there is an OOB pentaho
> transformation available. You can easily manipulate it for your needs
> without any code changes.
>
> Regards,
> Karthik
>
> On Mar 21, 2013 11:11 AM, "SUBSCRIBE arslist Aditya Sharma" <
> heloits...@gmail.com> wrote:
>
> The best practice is to bring data from AD over to vendor form, then push
> that data as it is on a regular form (staging), do all these validation on
> staging form.
>
> You have to build your logic like when your data is being pushed to
> staging form for every record you have to query vendor table such that
> manager's dn equals diastinguished name and set the manager login I'd as
> Manager's login equal unique attribuye of AD (sAMAccountName or uid).
>
> Now when you will push this managers I'd to people form, for the first
> sync certain records will error, those will be the ones whose manager
> record is not created before the reportees record is getting created. After
> second sync all managers should go in successfully.
>
> Regards,
> Aditya
>
> --Original Message--
> From: rajkiran Alle
> Sender: Action Request System discussion list(ARSList)
> To: arslist@ARSLIST.ORG
> ReplyTo: arslist@ARSLIST.ORG
> Subject: Active Directory Integration Problem
> Sent: Mar 21, 2013 4:03 AM
>
> Hi,
>
> I am developing code for data in AD to sync with People record. So in that
> process i am struck with a small problem.
>
> I created a vendor form to bring the LDAP data and creating a escalation
> to push new records into People form. But in the vendor form i only have a
> Manger name but i don't have a ManagerLoginId, which i need to push into
> People record. If i try to Push just the Manager Name leaving Manager Login
> Id to Null its throwing a error. Its working fine if i leave both Manager
> Login ID and Manger Name to Null. But i do need to get both of them to
> complete this task.
>
> So can you give me some ideas to get pass through this problem.
>
>
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> "Where the Answers Are, and have been for 20 years"
>
>
> Sent from my BlackBerry® smartphone from !DEA
>
>
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> "Where the Answers Are, and have been for 20 years"
>
> _ARSlist: "Where the Answers Are" and have been for 20 years_ 
> _ARSlist: "Where the Answers Are" and have been for 20 years_
>

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-22 Thread Mathew Welborn
I am working on a theory. I believe you can simply (maybe) copy the current 
Load_People DMT job / transformation that you would usually use with an excel 
file. This will allow you to pick up all of the validation then simply change 
out the excel file input and grab the data from other sources using Atrium 
Integrator. From there you will have to change around the data mappings to fit. 
I have not full proven this yet, but throwing out another idea. Also I have 
only been doing Remedy stuff for around 3 months so I could be completely off 
my rocker.

-
Mathew Welborn
Commercial Software Developer
Boise Inc. |  Enterprise Applications
mathewwelb...@boiseinc.com | (208) 384-7671



From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Hennigan, Sandra
Sent: Friday, March 22, 2013 1:51 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Problem

**
I am on 8.1 and would be interested in both approaches if you can post to the 
list.

Thank you,

Sandra Hennigan
Remedy Developer

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Logan, Kelly
Sent: Friday, March 22, 2013 12:45 PM
To: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
Subject: Re: Active Directory Integration Problem

**
Aditya - I have an integration with People (and Attributes) that I am running 
now on ARS/ITSM 7.6.4 following this strategy. I bring the data into a staging 
form, run some queries to set the Manager Login ID, Site ID and such  (similar 
to the Data management tool) and then push to the People and Attribute forms. 
Feel free to contact m

Karthik - That Pentaho transform sounds very interesting. Is there any 
documentation on it? I was under the impression that you couldn't run an 
Integrator job to connect to the People form, did this change in 8.x?

Kelly Logan, Sr. Systems Administrator (Remedy, Planview), GEMS
ProQuest | 789 E. Eisenhower Parkway, P.O. Box 1346 | Ann Arbor MI 48106-1346 
USA | 734.997.4777
kelly.lo...@proquest.com<mailto:kelly.lo...@proquest.com>
www.proquest.com

ProQuest...Start here. . 2012 InformationWeek 500 Top Innovator | 2012 Detroit 
Free Press Michigan Top Workplace

P Please consider the environment before printing this email.

This email and any files transmitted with it are confidential and intended 
solely for the use of the individual or entity to whom they are addressed. If 
you have received this email in error please notify the sender, and delete the 
message from your computer.

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Karthik
Sent: Thursday, March 21, 2013 10:44 PM
To: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
Subject: Re: Active Directory Integration Problem

**

Which version of arsystem are you using. If 8.0, there is an OOB pentaho 
transformation available. You can easily manipulate it for your needs without 
any code changes.

Regards,
Karthik
On Mar 21, 2013 11:11 AM, "SUBSCRIBE arslist Aditya Sharma" 
mailto:heloits...@gmail.com>> wrote:
The best practice is to bring data from AD over to vendor form, then push that 
data as it is on a regular form (staging), do all these validation on staging 
form.

You have to build your logic like when your data is being pushed to staging 
form for every record you have to query vendor table such that manager's dn 
equals diastinguished name and set the manager login I'd as Manager's login 
equal unique attribuye of AD (sAMAccountName or uid).

Now when you will push this managers I'd to people form, for the first sync 
certain records will error, those will be the ones whose manager record is not 
created before the reportees record is getting created. After second sync all 
managers should go in successfully.

Regards,
Aditya

--Original Message--
From: rajkiran Alle
Sender: Action Request System discussion list(ARSList)
To: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
ReplyTo: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
Subject: Active Directory Integration Problem
Sent: Mar 21, 2013 4:03 AM

Hi,

I am developing code for data in AD to sync with People record. So in that 
process i am struck with a small problem.

I created a vendor form to bring the LDAP data and creating a escalation to 
push new records into People form. But in the vendor form i only have a Manger 
name but i don't have a ManagerLoginId, which i need to push into People 
record. If i try to Push just the Manager Name leaving Manager Login Id to Null 
its throwing a error. Its working fine if i leave both Manager Login ID and 
Manger Name to Null. But i do need to get both of them to complete this task.

So can you give me some ideas to get pass through this problem.

___
UNSUBSCRIBE or access ARSlist Archives at 
www.a

Re: Active Directory Integration Problem

2013-03-22 Thread Hennigan, Sandra
I am on 8.1 and would be interested in both approaches if you can post to the 
list.

Thank you,

Sandra Hennigan
Remedy Developer

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Logan, Kelly
Sent: Friday, March 22, 2013 12:45 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Problem

**
Aditya - I have an integration with People (and Attributes) that I am running 
now on ARS/ITSM 7.6.4 following this strategy. I bring the data into a staging 
form, run some queries to set the Manager Login ID, Site ID and such  (similar 
to the Data management tool) and then push to the People and Attribute forms. 
Feel free to contact m

Karthik - That Pentaho transform sounds very interesting. Is there any 
documentation on it? I was under the impression that you couldn't run an 
Integrator job to connect to the People form, did this change in 8.x?

Kelly Logan, Sr. Systems Administrator (Remedy, Planview), GEMS
ProQuest | 789 E. Eisenhower Parkway, P.O. Box 1346 | Ann Arbor MI 48106-1346 
USA | 734.997.4777
kelly.lo...@proquest.com<mailto:kelly.lo...@proquest.com>
www.proquest.com

ProQuest...Start here. . 2012 InformationWeek 500 Top Innovator | 2012 Detroit 
Free Press Michigan Top Workplace

P Please consider the environment before printing this email.

This email and any files transmitted with it are confidential and intended 
solely for the use of the individual or entity to whom they are addressed. If 
you have received this email in error please notify the sender, and delete the 
message from your computer.

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Karthik
Sent: Thursday, March 21, 2013 10:44 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Problem

**

Which version of arsystem are you using. If 8.0, there is an OOB pentaho 
transformation available. You can easily manipulate it for your needs without 
any code changes.

Regards,
Karthik
On Mar 21, 2013 11:11 AM, "SUBSCRIBE arslist Aditya Sharma" 
mailto:heloits...@gmail.com>> wrote:
The best practice is to bring data from AD over to vendor form, then push that 
data as it is on a regular form (staging), do all these validation on staging 
form.

You have to build your logic like when your data is being pushed to staging 
form for every record you have to query vendor table such that manager's dn 
equals diastinguished name and set the manager login I'd as Manager's login 
equal unique attribuye of AD (sAMAccountName or uid).

Now when you will push this managers I'd to people form, for the first sync 
certain records will error, those will be the ones whose manager record is not 
created before the reportees record is getting created. After second sync all 
managers should go in successfully.

Regards,
Aditya

--Original Message--
From: rajkiran Alle
Sender: Action Request System discussion list(ARSList)
To: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
ReplyTo: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
Subject: Active Directory Integration Problem
Sent: Mar 21, 2013 4:03 AM

Hi,

I am developing code for data in AD to sync with People record. So in that 
process i am struck with a small problem.

I created a vendor form to bring the LDAP data and creating a escalation to 
push new records into People form. But in the vendor form i only have a Manger 
name but i don't have a ManagerLoginId, which i need to push into People 
record. If i try to Push just the Manager Name leaving Manager Login Id to Null 
its throwing a error. Its working fine if i leave both Manager Login ID and 
Manger Name to Null. But i do need to get both of them to complete this task.

So can you give me some ideas to get pass through this problem.

___
UNSUBSCRIBE or access ARSlist Archives at 
www.arslist.org<http://www.arslist.org>
"Where the Answers Are, and have been for 20 years"


Sent from my BlackBerry(r) smartphone from !DEA

___
UNSUBSCRIBE or access ARSlist Archives at 
www.arslist.org<http://www.arslist.org>
"Where the Answers Are, and have been for 20 years"
_ARSlist: "Where the Answers Are" and have been for 20 years_
_ARSlist: "Where the Answers Are" and have been for 20 years_

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-22 Thread Logan, Kelly
Aditya - I have an integration with People (and Attributes) that I am running 
now on ARS/ITSM 7.6.4 following this strategy. I bring the data into a staging 
form, run some queries to set the Manager Login ID, Site ID and such  (similar 
to the Data management tool) and then push to the People and Attribute forms. 
Feel free to contact m

Karthik - That Pentaho transform sounds very interesting. Is there any 
documentation on it? I was under the impression that you couldn't run an 
Integrator job to connect to the People form, did this change in 8.x?

Kelly Logan, Sr. Systems Administrator (Remedy, Planview), GEMS
ProQuest | 789 E. Eisenhower Parkway, P.O. Box 1346 | Ann Arbor MI 48106-1346 
USA | 734.997.4777
kelly.lo...@proquest.com<mailto:kelly.lo...@proquest.com>
www.proquest.com

ProQuest...Start here. . 2012 InformationWeek 500 Top Innovator | 2012 Detroit 
Free Press Michigan Top Workplace

P Please consider the environment before printing this email.

This email and any files transmitted with it are confidential and intended 
solely for the use of the individual or entity to whom they are addressed. If 
you have received this email in error please notify the sender, and delete the 
message from your computer.

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Karthik
Sent: Thursday, March 21, 2013 10:44 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Problem

**

Which version of arsystem are you using. If 8.0, there is an OOB pentaho 
transformation available. You can easily manipulate it for your needs without 
any code changes.

Regards,
Karthik
On Mar 21, 2013 11:11 AM, "SUBSCRIBE arslist Aditya Sharma" 
mailto:heloits...@gmail.com>> wrote:
The best practice is to bring data from AD over to vendor form, then push that 
data as it is on a regular form (staging), do all these validation on staging 
form.

You have to build your logic like when your data is being pushed to staging 
form for every record you have to query vendor table such that manager's dn 
equals diastinguished name and set the manager login I'd as Manager's login 
equal unique attribuye of AD (sAMAccountName or uid).

Now when you will push this managers I'd to people form, for the first sync 
certain records will error, those will be the ones whose manager record is not 
created before the reportees record is getting created. After second sync all 
managers should go in successfully.

Regards,
Aditya

--Original Message--
From: rajkiran Alle
Sender: Action Request System discussion list(ARSList)
To: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
ReplyTo: arslist@ARSLIST.ORG<mailto:arslist@ARSLIST.ORG>
Subject: Active Directory Integration Problem
Sent: Mar 21, 2013 4:03 AM

Hi,

I am developing code for data in AD to sync with People record. So in that 
process i am struck with a small problem.

I created a vendor form to bring the LDAP data and creating a escalation to 
push new records into People form. But in the vendor form i only have a Manger 
name but i don't have a ManagerLoginId, which i need to push into People 
record. If i try to Push just the Manager Name leaving Manager Login Id to Null 
its throwing a error. Its working fine if i leave both Manager Login ID and 
Manger Name to Null. But i do need to get both of them to complete this task.

So can you give me some ideas to get pass through this problem.

___
UNSUBSCRIBE or access ARSlist Archives at 
www.arslist.org<http://www.arslist.org>
"Where the Answers Are, and have been for 20 years"


Sent from my BlackBerry(r) smartphone from !DEA

___
UNSUBSCRIBE or access ARSlist Archives at 
www.arslist.org<http://www.arslist.org>
"Where the Answers Are, and have been for 20 years"
_ARSlist: "Where the Answers Are" and have been for 20 years_

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-21 Thread Karthik
Which version of arsystem are you using. If 8.0, there is an OOB pentaho
transformation available. You can easily manipulate it for your needs
without any code changes.

Regards,
Karthik
On Mar 21, 2013 11:11 AM, "SUBSCRIBE arslist Aditya Sharma" <
heloits...@gmail.com> wrote:

> The best practice is to bring data from AD over to vendor form, then push
> that data as it is on a regular form (staging), do all these validation on
> staging form.
>
> You have to build your logic like when your data is being pushed to
> staging form for every record you have to query vendor table such that
> manager's dn equals diastinguished name and set the manager login I'd as
> Manager's login equal unique attribuye of AD (sAMAccountName or uid).
>
> Now when you will push this managers I'd to people form, for the first
> sync certain records will error, those will be the ones whose manager
> record is not created before the reportees record is getting created. After
> second sync all managers should go in successfully.
>
> Regards,
> Aditya
>
> --Original Message--
> From: rajkiran Alle
> Sender: Action Request System discussion list(ARSList)
> To: arslist@ARSLIST.ORG
> ReplyTo: arslist@ARSLIST.ORG
> Subject: Active Directory Integration Problem
> Sent: Mar 21, 2013 4:03 AM
>
> Hi,
>
> I am developing code for data in AD to sync with People record. So in that
> process i am struck with a small problem.
>
> I created a vendor form to bring the LDAP data and creating a escalation
> to push new records into People form. But in the vendor form i only have a
> Manger name but i don't have a ManagerLoginId, which i need to push into
> People record. If i try to Push just the Manager Name leaving Manager Login
> Id to Null its throwing a error. Its working fine if i leave both Manager
> Login ID and Manger Name to Null. But i do need to get both of them to
> complete this task.
>
> So can you give me some ideas to get pass through this problem.
>
>
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> "Where the Answers Are, and have been for 20 years"
>
>
> Sent from my BlackBerry® smartphone from !DEA
>
>
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> "Where the Answers Are, and have been for 20 years"
>

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-21 Thread Ashtaputre, Anay
Following articles are worth reviewing -

KA287254 - AD Integration:Using a Vendor Form to Update the SHR: People Form

KA289736 - How to Use a Vendor Form to Update the SHR:People Form


Thanks
Anay..

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of rajkiran Alle
Sent: Tuesday, January 22, 2013 5:24 AM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Problem

Hi Guys,

Currently when we add a new user in Active Directory the record is not creating 
in People record, i mean Active directory is not sinking with people record. 
But the user able to use his credentials to login in Remedy once he has been 
added in AD but actually cannot do any request in Remedy since people record 
isn't created with default permissions. So now we are manually adding a user in 
people form as it is not sinking with AD. 

Can you please provide me your valuable suggestion.

Thanks.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-20 Thread SUBSCRIBE arslist Aditya Sharma
The best practice is to bring data from AD over to vendor form, then push that 
data as it is on a regular form (staging), do all these validation on staging 
form.

You have to build your logic like when your data is being pushed to staging 
form for every record you have to query vendor table such that manager's dn 
equals diastinguished name and set the manager login I'd as Manager's login 
equal unique attribuye of AD (sAMAccountName or uid).

Now when you will push this managers I'd to people form, for the first sync 
certain records will error, those will be the ones whose manager record is not 
created before the reportees record is getting created. After second sync all 
managers should go in successfully.

Regards,
Aditya

--Original Message--
From: rajkiran Alle
Sender: Action Request System discussion list(ARSList)
To: arslist@ARSLIST.ORG
ReplyTo: arslist@ARSLIST.ORG
Subject: Active Directory Integration Problem
Sent: Mar 21, 2013 4:03 AM

Hi,

I am developing code for data in AD to sync with People record. So in that 
process i am struck with a small problem.

I created a vendor form to bring the LDAP data and creating a escalation to 
push new records into People form. But in the vendor form i only have a Manger 
name but i don't have a ManagerLoginId, which i need to push into People 
record. If i try to Push just the Manager Name leaving Manager Login Id to Null 
its throwing a error. Its working fine if i leave both Manager Login ID and 
Manger Name to Null. But i do need to get both of them to complete this task.

So can you give me some ideas to get pass through this problem.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Sent from my BlackBerry® smartphone from !DEA

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-20 Thread Steve Kallestad
When in this situation, I will generally use a display only form as a
filter rather than interacting with the People form directly.

the process goes like this

LDAP Vendor Form (AD Data)--> Display Only Form (DataShaper) --> CTM:People

In my DataShaper Display Only form, I have filters that validate and shape
the data so that I know what I try to send to CTM:People will be successful
and any outliers are either ignored (if they are expected and flagged as
such) or an alternative error handling mechanism is triggered.  (For
instance, creating an incident)

In your case, with a missing manager login ID, the code for pulling in that
login id would happen prior to me pushing the data to CTM:People.  If I
couldn't find one, I'd generate an incident.

For the first few runs in a new environment, I generally don't create
incidents, but instead log and actively research the kinds of problems that
are happening.  That way I can come up with a better ruleset and the number
of incidents created in a live environment are small and less likely to be
ignored.

A design like this keeps the customization out of CTM:People - which is
subject to change with upgrades or patches and collects all of the data
shaping code in one purpose-built location so it can be easily referenced
and any changes are isolated to a single integration point.

It's pretty easy to throw together and it will save you many headaches down
the road.

Thanks,
Steve

On Wed, Mar 20, 2013 at 3:33 PM, rajkiran Alle wrote:

> Hi,
>
> I am developing code for data in AD to sync with People record. So in that
> process i am struck with a small problem.
>
> I created a vendor form to bring the LDAP data and creating a escalation
> to push new records into People form. But in the vendor form i only have a
> Manger name but i don't have a ManagerLoginId, which i need to push into
> People record. If i try to Push just the Manager Name leaving Manager Login
> Id to Null its throwing a error. Its working fine if i leave both Manager
> Login ID and Manger Name to Null. But i do need to get both of them to
> complete this task.
>
> So can you give me some ideas to get pass through this problem.
>
>
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> "Where the Answers Are, and have been for 20 years"
>

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-20 Thread Roger J

If you create a staging form between the two then you can validate specific 
data to eliminate this issue.


-Original Message-
From: rajkiran Alle 
To: arslist 
Sent: Wed, Mar 20, 2013 6:33 pm
Subject: Active Directory Integration Problem


Hi,

I am developing code for data in AD to sync with People record. So in that 
process i am struck with a small problem.

I created a vendor form to bring the LDAP data and creating a escalation to 
push 
new records into People form. But in the vendor form i only have a Manger name 
but i don't have a ManagerLoginId, which i need to push into People record. If 
i 
try to Push just the Manager Name leaving Manager Login Id to Null its throwing 
a error. Its working fine if i leave both Manager Login ID and Manger Name to 
Null. But i do need to get both of them to complete this task.

So can you give me some ideas to get pass through this problem.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-03-20 Thread Rick Westbrock
Could you just have the escalation push the Manager Name and then run a filter 
on People to look up the corresponding Manager Login ID in the People form? I 
am not extremely familiar with ITSM just yet but if you set the execution order 
correctly I think that should work (assuming of course that the manager has a 
People record). You just need to figure out what filter is throwing the error 
and have this new filter execute before that.

-Rick


___
Rick Westbrock
QMX Support Services

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of rajkiran Alle
Sent: Wednesday, March 20, 2013 3:33 PM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Problem

Hi,

I am developing code for data in AD to sync with People record. So in that 
process i am struck with a small problem.

I created a vendor form to bring the LDAP data and creating a escalation to 
push new records into People form. But in the vendor form i only have a Manger 
name but i don't have a ManagerLoginId, which i need to push into People 
record. If i try to Push just the Manager Name leaving Manager Login Id to Null 
its throwing a error. Its working fine if i leave both Manager Login ID and 
Manger Name to Null. But i do need to get both of them to complete this task.

So can you give me some ideas to get pass through this problem.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org "Where the Answers 
Are, and have been for 20 years"

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Active Directory Integration Problem

2013-03-20 Thread rajkiran Alle
Hi,

I am developing code for data in AD to sync with People record. So in that 
process i am struck with a small problem.

I created a vendor form to bring the LDAP data and creating a escalation to 
push new records into People form. But in the vendor form i only have a Manger 
name but i don't have a ManagerLoginId, which i need to push into People 
record. If i try to Push just the Manager Name leaving Manager Login Id to Null 
its throwing a error. Its working fine if i leave both Manager Login ID and 
Manger Name to Null. But i do need to get both of them to complete this task.

So can you give me some ideas to get pass through this problem.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-01-24 Thread Mayuresh Wagh
Make sure Directory Page Size & Base DN for Discovery parameters are set
properly. I think what you are getting data in chunk. I believe ARPlugin
logging will help in identifying the root cause.

On Fri, Jan 25, 2013 at 3:40 AM, rajkiran Alle wrote:

> Hi Guys,
>
> I created a vendor form to bring the data from LDAP but total we have some
> thing 100,000 records in LDAP but when i do search in Remedy vendor form
> its showing me only 33,000. Is there any reason for this ?
>
> Thanks
>
>
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> "Where the Answers Are, and have been for 20 years"
>

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-01-24 Thread rajkiran Alle
Hi Guys,

I created a vendor form to bring the data from LDAP but total we have some 
thing 100,000 records in LDAP but when i do search in Remedy vendor form its 
showing me only 33,000. Is there any reason for this ?

Thanks

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-01-22 Thread Carl Wilson
Hi,

just to note, version 8.0 does actually come with a pre-configured Data
Management  LDAP (and LDAPS) to People integration via AI that I have used
at a customer quite effectively (minor changes to the OOB Transform to
handle data manipulation).  It possibly could be configured for a previous
version where AI is present as it is a standard AI Transform/Job.

 

https://docs.bmc.com/docs/display/public/itsm80/Configuring+Data+Management+
for+LDAP+or+LDAPS+import

 

Cheers

Carl

 

http://www.missingpiecessoftware.com/

 

 

 

From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of Roger J
Sent: 22 January 2013 00:03
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Problem

 

** 

There is no OOTB AD to People sync it has to be built.

 

-Original Message-
From: rajkiran Alle 
To: arslist 
Sent: Mon, Jan 21, 2013 6:54 pm
Subject: Active Directory Integration Problem

Hi Guys,
 
Currently when we add a new user in Active Directory the record is not
creating 
in People record, i mean Active directory is not sinking with people record.
But 
the user able to use his credentials to login in Remedy once he has been
added 
in AD but actually cannot do any request in Remedy since people record isn't

created with default permissions. So now we are manually adding a user in
people 
form as it is not sinking with AD. 
 
Can you please provide me your valuable suggestion.
 
Thanks.
 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

_ARSlist: "Where the Answers Are" and have been for 20 years_


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-01-21 Thread Mayuresh Wagh
it would be depend upon what exactly you want to do. If you are looking for
authenticate users using AD, please configure AREA Plugin. If you looking
for use AD data in Remedy, please configure ARDBC Plugin.

You can login to Support Web & check below link for AREA & ARDBC Plugin
configuration.

https://docs.bmc.com/docs/display/public/ars8000/Using+the+AREA+LDAP+plug-in

https://docs.bmc.com/docs/display/public/ars8000/Configuring+the+ARDBC+LDAP+plug-in

HTH

Mayuresh

On Tue, Jan 22, 2013 at 10:17 AM, rajkiran Alle wrote:

> Can you please send me some documentation how to hook up the vendor form
> to AD if you have any, so that i will try to build the logic.
>
>
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> "Where the Answers Are, and have been for 20 years"
>

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-01-21 Thread rajkiran Alle
Can you please send me some documentation how to hook up the vendor form to AD 
if you have any, so that i will try to build the logic.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Problem

2013-01-21 Thread Roger J

There is no OOTB AD to People sync it has to be built.



-Original Message-
From: rajkiran Alle 
To: arslist 
Sent: Mon, Jan 21, 2013 6:54 pm
Subject: Active Directory Integration Problem


Hi Guys,

Currently when we add a new user in Active Directory the record is not creating 
in People record, i mean Active directory is not sinking with people record. 
But 
the user able to use his credentials to login in Remedy once he has been added 
in AD but actually cannot do any request in Remedy since people record isn't 
created with default permissions. So now we are manually adding a user in 
people 
form as it is not sinking with AD. 

Can you please provide me your valuable suggestion.

Thanks.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Active Directory Integration Problem

2013-01-21 Thread rajkiran Alle
Hi Guys,

Currently when we add a new user in Active Directory the record is not creating 
in People record, i mean Active directory is not sinking with people record. 
But the user able to use his credentials to login in Remedy once he has been 
added in AD but actually cannot do any request in Remedy since people record 
isn't created with default permissions. So now we are manually adding a user in 
people form as it is not sinking with AD. 

Can you please provide me your valuable suggestion.

Thanks.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"


Re: Active Directory Integration Issue with 7.6.04

2011-10-13 Thread Nathan Aker
Update, after sending me 2 hotfixes that didn't work BMC Support came back and 
said this was actually "Functioning as Designed" and that they had changed this 
starting in 7.6.03 to append an identifier to the requestId field in your LDAP 
vendor form.   Because my integration and vendor form was already written with 
the samAccountName as the identifier field, we had to move forward and 
implement a workaround to truncate the leading junk off the name when pushing 
it to the staging form.  

SUBSTR($samAccountName$, 6, LENGTH($samAccountName$))

This actually works ok, because surprisingly you can still search/qualify your 
data as the plugin will find a match of samAccountName=jsmith (for example) on 
the vendor form even though it presents the data as 1|jsmith after 
returning the results.

But I agree with Frederick, the cleaner way would have been to leverage the 
"uSNCreated" attribute as it is always unique.   BMC Support recommended using 
the "cn" attribute which is not a viable solution because it is not unique, 
it's basically just a concatenation of firstname, lastname.

Side note regarding the 15 character maximum, I believe (don't hold me to this) 
that that was a former constraint with some of the older versions.  I want to 
say they addressed that in 7.1 or 7.5 but my memory escapes me at times.  We've 
not had any issues (so far) using the samAccountName, until the upgrade 
interjected this identifier into the mix.

Thanks.  Nate.

Nathan Aker
ITSM Solution Architect
McAfee, Inc.
Direct: 972.963.7611
Mobile: 469.644.7402


-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Grooms, Frederick W
Sent: Thursday, October 13, 2011 1:29 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04

One thing I was told a long time ago (I think it was RUG 2005) was not to map 
the sAMAccountName to the Request ID (since Request ID is supposed to be <= 15 
characters) for a Vendor form on the ARDBCldap plugin.

I have always mapped the uSNCreated to Request ID and just had sAMAccountName 
as a separate field.

Fred

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Brian Gillock
Sent: Thursday, October 13, 2011 1:20 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04

**
Thank you for this, Nathan.  I was having the same issue.  I worked around it 
by parsing out the userid when I stored it on my staging form like so:
 
SUBSTRC($Request ID$, STRSTRC($Request ID$, "|") + 1, LENGTHC($Request ID$))
 
 
-Original Message-
On Fri, Oct 7, 2011 at 11:42 PM, Uday Joshi  wrote:
**
Hi Nathan,
 
I am also struggling with similar issue. Has BMC given any bug number for the 
same?
 
Any workaround possible.
 
Best Regards,
 
Uday

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: Thursday, October 06, 2011 6:32 PM

To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04
 
**
Just got a response from BMC Support.  Appears to be a known defect fixed in 
7.6.04 SP2
 
Thanks.  Nate.
 
Nathan Aker
ITSM Solution Architect
McAfee, Inc.
 
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Danny Kellett
Sent: Thursday, October 06, 2011 4:31 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04
 
**
Hi,
 
Have you tried cn instead of samaccountname?
 
Do you have any filters configured in your ARDBC LDAP configuration?
 
Kind regards
Danny

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: 06 October 2011 21:41
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Issue with 7.6.04
 
**
Hello all,
 
We're running into an issue with our Active Directory LDAP integration after a 
recent upgrade and I'm wondering if anyone else has encountered or is 
encountering:
 
We have a vendor form leveraging the ARDBC plugin to integrate with Active 
Directory for people data.  The vendor form displays people data, with the 
unique attribute being the samAccountName attribute.  In setting up the Vendor 
form, this attribute was mapped as the Request ID.
 
When we were on ARS 7.6.00, when I ran a search against the vendor form I would 
see the samAccountName displayed something like "asmith" for example.
 
After the upgrade to 7.6.04, now when I run a search on this vendor form, the 
samAccountName is prefixed with 1|.  So for example, where I saw "asmith" 
before the upgrade I now see "1|asmith".
 
This is obviously an issue as we are trying to map the samAccountName to the 
LoginID field in Remedy.
 
 
Anyone seen thi

Re: Active Directory Integration Issue with 7.6.04

2011-10-13 Thread Grooms, Frederick W
One thing I was told a long time ago (I think it was RUG 2005) was not to map 
the sAMAccountName to the Request ID (since Request ID is supposed to be <= 15 
characters) for a Vendor form on the ARDBCldap plugin.

I have always mapped the uSNCreated to Request ID and just had sAMAccountName 
as a separate field.

Fred

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Brian Gillock
Sent: Thursday, October 13, 2011 1:20 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04

** 
Thank you for this, Nathan.  I was having the same issue.  I worked around it 
by parsing out the userid when I stored it on my staging form like so:
 
SUBSTRC($Request ID$, STRSTRC($Request ID$, "|") + 1, LENGTHC($Request ID$))
 
 
-Original Message-
On Fri, Oct 7, 2011 at 11:42 PM, Uday Joshi  wrote:
** 
Hi Nathan,
 
I am also struggling with similar issue. Has BMC given any bug number for the 
same?
 
Any workaround possible.
 
Best Regards,
 
Uday

-Original Message- 
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: Thursday, October 06, 2011 6:32 PM

To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04
 
** 
Just got a response from BMC Support.  Appears to be a known defect fixed in 
7.6.04 SP2
 
Thanks.  Nate.
 
Nathan Aker
ITSM Solution Architect
McAfee, Inc.
 
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Danny Kellett
Sent: Thursday, October 06, 2011 4:31 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04
 
** 
Hi,
 
Have you tried cn instead of samaccountname?
 
Do you have any filters configured in your ARDBC LDAP configuration?
 
Kind regards
Danny

-Original Message- 
From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: 06 October 2011 21:41
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Issue with 7.6.04
 
** 
Hello all,
 
We're running into an issue with our Active Directory LDAP integration after a 
recent upgrade and I'm wondering if anyone else has encountered or is 
encountering:
 
We have a vendor form leveraging the ARDBC plugin to integrate with Active 
Directory for people data.  The vendor form displays people data, with the 
unique attribute being the samAccountName attribute.  In setting up the Vendor 
form, this attribute was mapped as the Request ID.
 
When we were on ARS 7.6.00, when I ran a search against the vendor form I would 
see the samAccountName displayed something like "asmith" for example.
 
After the upgrade to 7.6.04, now when I run a search on this vendor form, the 
samAccountName is prefixed with 1|.  So for example, where I saw "asmith" 
before the upgrade I now see "1|asmith".
 
This is obviously an issue as we are trying to map the samAccountName to the 
LoginID field in Remedy.
 
 
Anyone seen this before or know what feature/configuration is appending the 
1 on front?
 
Thanks.  Nate.
 
Nathan Aker
ITSM Solution Architect

McAfee, Inc.
5000 Headquarters Drive
Plano, TX 75024

Direct: 972.963.7611 
Mobile: 469.644.7402
Web:www.mcafee.com

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"


Re: Active Directory Integration Issue with 7.6.04

2011-10-13 Thread Brian Gillock
Thank you for this, Nathan.  I was having the same issue.  I worked around
it by parsing out the userid when I stored it on my staging form like so:

SUBSTRC($Request ID$, STRSTRC($Request ID$, "|") + 1, LENGTHC($Request ID$))






On Fri, Oct 7, 2011 at 11:42 PM, Uday Joshi  wrote:

> **
>
> Hi Nathan,
>
> ** **
>
> I am also struggling with similar issue. Has BMC given any bug number for
> the same?
>
> ** **
>
> Any workaround possible.
>
> ** **
>
> Best Regards,
>
> ** **
>
> Uday
>
> ** **
>
> *From:* Action Request System discussion list(ARSList) [mailto:
> arslist@ARSLIST.ORG] *On Behalf Of *Nathan Aker
> *Sent:* Thursday, October 06, 2011 6:32 PM
>
> *To:* arslist@ARSLIST.ORG
> *Subject:* Re: Active Directory Integration Issue with 7.6.04
>
> ** **
>
> ** 
>
> Just got a response from BMC Support.  Appears to be a known defect fixed
> in 7.6.04 SP2
>
> ** **
>
> Thanks.  Nate.
>
> ** **
>
> *Nathan Aker*
> ITSM Solution Architect
>
> *McAfee, Inc.*
>
> ** **
>
> *From:* Action Request System discussion list(ARSList) [mailto:
> arslist@ARSLIST.ORG] *On Behalf Of *Danny Kellett
> *Sent:* Thursday, October 06, 2011 4:31 PM
> *To:* arslist@ARSLIST.ORG
> *Subject:* Re: Active Directory Integration Issue with 7.6.04
>
> ** **
>
> ** 
>
> Hi,
>
> ** **
>
> Have you tried cn instead of samaccountname?
>
> ** **
>
> Do you have any filters configured in your ARDBC LDAP configuration?
>
> ** **
>
> Kind regards
>
> Danny
>
> ** **
>
> *From:* Action Request System discussion list(ARSList) [mailto:
> arslist@ARSLIST.ORG] *On Behalf Of *Nathan Aker
> *Sent:* 06 October 2011 21:41
> *To:* arslist@ARSLIST.ORG
> *Subject:* Active Directory Integration Issue with 7.6.04
>
> ** **
>
> ** 
>
> Hello all,
>
> ** **
>
> We’re running into an issue with our Active Directory LDAP integration
> after a recent upgrade and I’m wondering if anyone else has encountered or
> is encountering:
>
> ** **
>
> We have a vendor form leveraging the ARDBC plugin to integrate with Active
> Directory for people data.  The vendor form displays people data, with the
> unique attribute being the samAccountName attribute.  In setting up the
> Vendor form, this attribute was mapped as the Request ID.
>
> ** **
>
> When we were on ARS 7.6.00, when I ran a search against the vendor form I
> would see the samAccountName displayed something like “asmith” for example.
> 
>
> ** **
>
> After the upgrade to 7.6.04, now when I run a search on this vendor form,
> the samAccountName is prefixed with 1|.  So for example, where I saw
> “asmith” before the upgrade I now see “1|asmith”.
>
> ** **
>
> This is obviously an issue as we are trying to map the samAccountName to
> the LoginID field in Remedy.
>
> ** **
>
> ** **
>
> Anyone seen this before or know what feature/configuration is appending the
> 1 on front?
>
> ** **
>
> Thanks.  Nate.
>
> ** **
>
> *Nathan Aker*
> ITSM Solution Architect
>
>
> *McAfee, Inc.*
> 5000 Headquarters Drive
>
> Plano, TX 75024
>
> Direct: 972.963.7611
> Mobile: 469.644.7402
>
> *Web:*www.mcafee.com<http://internal.nai.com/division/marketing/BrandMarketing/templates/www.mcafee.com>
> 
>
> ** **
>
> [image: Description: cid:image002.jpg@01CC30F2.B6B584F0]
>
> ** **
>
> _attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ 
>
> _attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ 
>
> _attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ 
>
> * Please do not print this email unless it is absolutely necessary. *
>
> The information contained in this electronic message and any attachments to
> this message are intended for the exclusive use of the addressee(s) and may
> contain proprietary, confidential or privileged information. If you are not
> the intended recipient, you should not disseminate, distribute or copy this
> e-mail. Please notify the sender immediately and destroy all copies of this
> message and any attachments.
>
> WARNING: Computer viruses can be transmitted via email. The recipient
> should check this email and any attachments for the presence of viruses. The
> company accepts no liability for any damage caused by any virus transmitted
> by this email.
>
> www.wipro.com
>  _attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_
>



-- 
Brian Gillock
Principal Consultant, BGBS, Inc
brian.gill...@pbs-consulting.com

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"


Re: Active Directory Integration Issue with 7.6.04

2011-10-07 Thread Uday Joshi
Hi Nathan,

 

I am also struggling with similar issue. Has BMC given any bug number for the 
same?

 

Any workaround possible.

 

Best Regards,

 

Uday

 

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: Thursday, October 06, 2011 6:32 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04

 

** 

Just got a response from BMC Support.  Appears to be a known defect fixed in 
7.6.04 SP2

 

Thanks.  Nate.

 

Nathan Aker
ITSM Solution Architect

McAfee, Inc.

 

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Danny Kellett
Sent: Thursday, October 06, 2011 4:31 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04

 

** 

Hi,

 

Have you tried cn instead of samaccountname?

 

Do you have any filters configured in your ARDBC LDAP configuration?

 

Kind regards

Danny

 

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: 06 October 2011 21:41
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Issue with 7.6.04

 

** 

Hello all,

 

We’re running into an issue with our Active Directory LDAP integration after a 
recent upgrade and I’m wondering if anyone else has encountered or is 
encountering:

 

We have a vendor form leveraging the ARDBC plugin to integrate with Active 
Directory for people data.  The vendor form displays people data, with the 
unique attribute being the samAccountName attribute.  In setting up the Vendor 
form, this attribute was mapped as the Request ID.

 

When we were on ARS 7.6.00, when I ran a search against the vendor form I would 
see the samAccountName displayed something like “asmith” for example.

 

After the upgrade to 7.6.04, now when I run a search on this vendor form, the 
samAccountName is prefixed with 1|.  So for example, where I saw “asmith” 
before the upgrade I now see “1|asmith”.

 

This is obviously an issue as we are trying to map the samAccountName to the 
LoginID field in Remedy.

 

 

Anyone seen this before or know what feature/configuration is appending the 
1 on front?

 

Thanks.  Nate.

 

Nathan Aker
ITSM Solution Architect


McAfee, Inc.
5000 Headquarters Drive

Plano, TX 75024

Direct: 972.963.7611 
Mobile: 469.644.7402

Web:www.mcafee.com 
<http://internal.nai.com/division/marketing/BrandMarketing/templates/www.mcafee.com>
 

 

 

 

_attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ 

_attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ 

_attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ 


Please do not print this email unless it is absolutely necessary. 

The information contained in this electronic message and any attachments to 
this message are intended for the exclusive use of the addressee(s) and may 
contain proprietary, confidential or privileged information. If you are not the 
intended recipient, you should not disseminate, distribute or copy this e-mail. 
Please notify the sender immediately and destroy all copies of this message and 
any attachments. 

WARNING: Computer viruses can be transmitted via email. The recipient should 
check this email and any attachments for the presence of viruses. The company 
accepts no liability for any damage caused by any virus transmitted by this 
email. 

www.wipro.com

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"
<>

Re: Active Directory Integration Issue with 7.6.04

2011-10-06 Thread Nathan Aker
Just got a response from BMC Support.  Appears to be a known defect fixed in 
7.6.04 SP2

Thanks.  Nate.

Nathan Aker
ITSM Solution Architect
McAfee, Inc.


From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Danny Kellett
Sent: Thursday, October 06, 2011 4:31 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04

**
Hi,

Have you tried cn instead of samaccountname?

Do you have any filters configured in your ARDBC LDAP configuration?

Kind regards
Danny

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: 06 October 2011 21:41
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Issue with 7.6.04

**
Hello all,

We're running into an issue with our Active Directory LDAP integration after a 
recent upgrade and I'm wondering if anyone else has encountered or is 
encountering:

We have a vendor form leveraging the ARDBC plugin to integrate with Active 
Directory for people data.  The vendor form displays people data, with the 
unique attribute being the samAccountName attribute.  In setting up the Vendor 
form, this attribute was mapped as the Request ID.

When we were on ARS 7.6.00, when I ran a search against the vendor form I would 
see the samAccountName displayed something like "asmith" for example.

After the upgrade to 7.6.04, now when I run a search on this vendor form, the 
samAccountName is prefixed with 1|.  So for example, where I saw "asmith" 
before the upgrade I now see "1|asmith".

This is obviously an issue as we are trying to map the samAccountName to the 
LoginID field in Remedy.


Anyone seen this before or know what feature/configuration is appending the 
1 on front?

Thanks.  Nate.

Nathan Aker
ITSM Solution Architect

McAfee, Inc.
5000 Headquarters Drive
Plano, TX 75024

Direct: 972.963.7611
Mobile: 469.644.7402
Web:www.mcafee.com<http://internal.nai.com/division/marketing/BrandMarketing/templates/www.mcafee.com>

[cid:image001.jpg@01CC844D.D17E8620]

_attend WWRUG11 www.wwrug.com<http://www.wwrug.com> ARSlist: "Where the Answers 
Are"_
_attend WWRUG11 www.wwrug.com<http://www.wwrug.com> ARSlist: "Where the Answers 
Are"_

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"
<>

Re: Active Directory Integration Issue with 7.6.04

2011-10-06 Thread Nathan Aker
CN will not work as it is not guaranteed unique as it is basically Last Name, 
First Name and 2 people can have the same name.

The only workflow on this form is simply push filters to push to a staging form 
where data is scrubbed.

Nathan Aker
ITSM Solution Architect
McAfee, Inc.


From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Danny Kellett
Sent: Thursday, October 06, 2011 4:31 PM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration Issue with 7.6.04

**
Hi,

Have you tried cn instead of samaccountname?

Do you have any filters configured in your ARDBC LDAP configuration?

Kind regards
Danny

From: Action Request System discussion list(ARSList) 
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: 06 October 2011 21:41
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Issue with 7.6.04

**
Hello all,

We're running into an issue with our Active Directory LDAP integration after a 
recent upgrade and I'm wondering if anyone else has encountered or is 
encountering:

We have a vendor form leveraging the ARDBC plugin to integrate with Active 
Directory for people data.  The vendor form displays people data, with the 
unique attribute being the samAccountName attribute.  In setting up the Vendor 
form, this attribute was mapped as the Request ID.

When we were on ARS 7.6.00, when I ran a search against the vendor form I would 
see the samAccountName displayed something like "asmith" for example.

After the upgrade to 7.6.04, now when I run a search on this vendor form, the 
samAccountName is prefixed with 1|.  So for example, where I saw "asmith" 
before the upgrade I now see "1|asmith".

This is obviously an issue as we are trying to map the samAccountName to the 
LoginID field in Remedy.


Anyone seen this before or know what feature/configuration is appending the 
1 on front?

Thanks.  Nate.

Nathan Aker
ITSM Solution Architect

McAfee, Inc.
5000 Headquarters Drive
Plano, TX 75024

Direct: 972.963.7611
Mobile: 469.644.7402
Web:www.mcafee.com<http://internal.nai.com/division/marketing/BrandMarketing/templates/www.mcafee.com>

[cid:image001.jpg@01CC8448.BF8B9750]

_attend WWRUG11 www.wwrug.com<http://www.wwrug.com> ARSlist: "Where the Answers 
Are"_
_attend WWRUG11 www.wwrug.com<http://www.wwrug.com> ARSlist: "Where the Answers 
Are"_

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"
<>

Re: Active Directory Integration Issue with 7.6.04

2011-10-06 Thread Danny Kellett
Hi,

 

Have you tried cn instead of samaccountname?

 

Do you have any filters configured in your ARDBC LDAP configuration?

 

Kind regards

Danny

 

From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: 06 October 2011 21:41
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration Issue with 7.6.04

 

** 

Hello all,

 

We're running into an issue with our Active Directory LDAP integration after
a recent upgrade and I'm wondering if anyone else has encountered or is
encountering:

 

We have a vendor form leveraging the ARDBC plugin to integrate with Active
Directory for people data.  The vendor form displays people data, with the
unique attribute being the samAccountName attribute.  In setting up the
Vendor form, this attribute was mapped as the Request ID.

 

When we were on ARS 7.6.00, when I ran a search against the vendor form I
would see the samAccountName displayed something like "asmith" for example.

 

After the upgrade to 7.6.04, now when I run a search on this vendor form,
the samAccountName is prefixed with 1|.  So for example, where I saw
"asmith" before the upgrade I now see "1|asmith".

 

This is obviously an issue as we are trying to map the samAccountName to the
LoginID field in Remedy.

 

 

Anyone seen this before or know what feature/configuration is appending the
1 on front?

 

Thanks.  Nate.

 

Nathan Aker
ITSM Solution Architect


McAfee, Inc.
5000 Headquarters Drive

Plano, TX 75024

Direct: 972.963.7611 
Mobile: 469.644.7402

Web:
<http://internal.nai.com/division/marketing/BrandMarketing/templates/www.mca
fee.com> www.mcafee.com

 

Description: cid:image002.jpg@01CC30F2.B6B584F0

 

_attend WWRUG11 www.wwrug.com ARSlist: "Where the Answers Are"_ 


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"
<>

Active Directory Integration Issue with 7.6.04

2011-10-06 Thread Nathan Aker
Hello all,

We're running into an issue with our Active Directory LDAP integration after a 
recent upgrade and I'm wondering if anyone else has encountered or is 
encountering:

We have a vendor form leveraging the ARDBC plugin to integrate with Active 
Directory for people data.  The vendor form displays people data, with the 
unique attribute being the samAccountName attribute.  In setting up the Vendor 
form, this attribute was mapped as the Request ID.

When we were on ARS 7.6.00, when I ran a search against the vendor form I would 
see the samAccountName displayed something like "asmith" for example.

After the upgrade to 7.6.04, now when I run a search on this vendor form, the 
samAccountName is prefixed with 1|.  So for example, where I saw "asmith" 
before the upgrade I now see "1|asmith".

This is obviously an issue as we are trying to map the samAccountName to the 
LoginID field in Remedy.


Anyone seen this before or know what feature/configuration is appending the 
1 on front?

Thanks.  Nate.

Nathan Aker
ITSM Solution Architect

McAfee, Inc.
5000 Headquarters Drive
Plano, TX 75024

Direct: 972.963.7611
Mobile: 469.644.7402
Web:www.mcafee.com

[cid:image001.jpg@01CC843C.DC6E6BB0]


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"
<>

Re: Active Directory Integration

2009-07-15 Thread patrick zandi
David,
Another thought comes to mind.
on the server go to the control panel, advanced, local security policy.
Look for LDAP in the Local policy, Security options.
does any of the following exsist?  Domain Controller: ldap server signing
requirements (Require Signing).
neetwork security ldap client signing requirements ..
--- I have the above cause issues -- with CM and LDAP it breaks it.
ALSO check
Network security lan manager authentication level is it set to NTLMV2?
with the Network Security: minimum session security for ntlm ssp based
 -- is the Require NTLMV2 session security required Checked..
--- I have also seen this kill the ldap connection.

--- for whatever it is worth.

-- 
Patrick Zandi

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2009-07-15 Thread Kaiser, Norm E CIV USAF AFMC 96 CS/SCOKT
There have in the past been issues with the thick client in versions 5.x
and 6.x. The issue was that if the user keyed the wrong password ONCE,
his account would get locked out. The issue was corrected in 5.x with a
client patch. When we upgraded to 6.x, however, the problem was
reintroduced and we had to patch all our 6.x clients.

So it's a long shot, but I suppose it may be possible that the same
issue was reintroduced in the 7.x clients? Easy way to find out is to go
to an account of a user who's having trouble, be sure his account is
currently unlocked, then go to that person's machine and attempt to log
on to Remedy with a completely bogus password. If his account locks out
after one failed attempt, you've uncovered part of your problem.

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:arsl...@arslist.org] On Behalf Of Shellman, David
Sent: Wednesday, July 15, 2009 9:42 AM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration

Since we are on Oracle we are aware of case being an issue.  Our AR
System accounts are always created in lower case.  So a user that logins
with yyy will authenticate against Active Directory because they have a
User record.  We have configured the system to Allow Guest Users so if a
user logs in as YYY or tycoelectronics\yyy will be logged in as a Guest
user because of case sensitivity.

Dave

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:arsl...@arslist.org] On Behalf Of Kaiser, Norm E CIV USAF AFMC
96 CS/SCOKT
Sent: Wednesday, July 15, 2009 10:33 AM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration

Check your case sensitivity. Windows is case insensitive but Remedy is
case sensitive. We had instances where a user's username in Remedy was
keyed in as John.Smith but that user would use john.smith to log on to
Windows and got used to typing his username lower case. Then when we
turned on Cross Ref Blank Password in Remedy, the user would attempt to
log on with john.smith, but to Remedy, his username was John.Smith.

Norm

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:arsl...@arslist.org] On Behalf Of Shellman, David
Sent: Wednesday, July 15, 2009 9:14 AM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

** 
We configured our 7.0.1 server (Windows server Oracle instance) to
validate passwords against Active Directory over the weekend.  Monday
morning was a little rough with locking out network accounts.  We also
had a configuration issue where were not able to check one of the OU's.
We changed the configuration but we still had a few users where we are
having login issues.
 
While looking at the user log file I noticed a changed with what is
written out to the log for a login failure.  What I'm seeing is that
sometimes (password) is at the end of the line and sometimes (user) is
at the end of the line. For certain users it's consistently one or the
other.  In some cases it changes from one to another.  In one case it's
about 2 minutes between the change.  In another it's 4 seconds.
 
 /* Mon Jul 13 2009 09:38:22.0820 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 09:40:50.7970 */ LOGIN
FAILED      (password)
 
 /* Mon Jul 13 2009 15:12:12.9630 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 15:12:16.9450 */ LOGIN
FAILED      (password)
 
Any one have an understanding of what the logs are trying to tell me?
 
Thanks,
Dave
 
Dave Shellman
 
Phone:  (717) 810-3687
Fax:(717) 810-2124
email:  dave.shell...@tycoelectronics.com
 
Tyco Electronics
MS 161-043
PO Box 3608
Harrisburg, PA 17105-3607
 
 
 
_Platinum Sponsor: rmisoluti...@verizon.net ARSlist: "Where the Answers
Are"_ 


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers
Are"


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers
Are"

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2009-07-15 Thread Shellman, David
Since we are on Oracle we are aware of case being an issue.  Our AR System 
accounts are always created in lower case.  So a user that logins with yyy will 
authenticate against Active Directory because they have a User record.  We have 
configured the system to Allow Guest Users so if a user logs in as YYY or 
tycoelectronics\yyy will be logged in as a Guest user because of case 
sensitivity.

Dave

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arsl...@arslist.org] On Behalf Of Kaiser, Norm E CIV USAF AFMC 96 
CS/SCOKT
Sent: Wednesday, July 15, 2009 10:33 AM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration

Check your case sensitivity. Windows is case insensitive but Remedy is
case sensitive. We had instances where a user's username in Remedy was
keyed in as John.Smith but that user would use john.smith to log on to
Windows and got used to typing his username lower case. Then when we
turned on Cross Ref Blank Password in Remedy, the user would attempt to
log on with john.smith, but to Remedy, his username was John.Smith.

Norm

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:arsl...@arslist.org] On Behalf Of Shellman, David
Sent: Wednesday, July 15, 2009 9:14 AM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

** 
We configured our 7.0.1 server (Windows server Oracle instance) to
validate passwords against Active Directory over the weekend.  Monday
morning was a little rough with locking out network accounts.  We also
had a configuration issue where were not able to check one of the OU's.
We changed the configuration but we still had a few users where we are
having login issues.
 
While looking at the user log file I noticed a changed with what is
written out to the log for a login failure.  What I'm seeing is that
sometimes (password) is at the end of the line and sometimes (user) is
at the end of the line. For certain users it's consistently one or the
other.  In some cases it changes from one to another.  In one case it's
about 2 minutes between the change.  In another it's 4 seconds.
 
 /* Mon Jul 13 2009 09:38:22.0820 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 09:40:50.7970 */ LOGIN
FAILED      (password)
 
 /* Mon Jul 13 2009 15:12:12.9630 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 15:12:16.9450 */ LOGIN
FAILED      (password)
 
Any one have an understanding of what the logs are trying to tell me?
 
Thanks,
Dave
 
Dave Shellman
 
Phone:  (717) 810-3687
Fax:(717) 810-2124
email:  dave.shell...@tycoelectronics.com
 
Tyco Electronics
MS 161-043
PO Box 3608
Harrisburg, PA 17105-3607
 
 
 
_Platinum Sponsor: rmisoluti...@verizon.net ARSlist: "Where the Answers
Are"_ 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2009-07-15 Thread Shellman, David
Thanks.  We are looking at that for some additional info.

I really hoping that some one can tell me the difference between (user) and 
(password) being tagged on the line in the user log.

Dave

-Original Message-
From: Action Request System discussion list(ARSList) 
[mailto:arsl...@arslist.org] On Behalf Of Nichols, Wesley D CTR USAF AFMC 72 
CS/SCBAF
Sent: Wednesday, July 15, 2009 10:31 AM
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration

You might try looking at the plug-in logs... You can set the
granularity, I believe you have to add Plugin-Log-Level: 100 to you
config file.  This should give a ton of information about the
interaction between AD and the AREA plugin...

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:arsl...@arslist.org] On Behalf Of Shellman, David
Sent: Wednesday, July 15, 2009 9:14 AM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

** 
We configured our 7.0.1 server (Windows server Oracle instance) to
validate passwords against Active Directory over the weekend.  Monday
morning was a little rough with locking out network accounts.  We also
had a configuration issue where were not able to check one of the OU's.
We changed the configuration but we still had a few users where we are
having login issues.
 
While looking at the user log file I noticed a changed with what is
written out to the log for a login failure.  What I'm seeing is that
sometimes (password) is at the end of the line and sometimes (user) is
at the end of the line. For certain users it's consistently one or the
other.  In some cases it changes from one to another.  In one case it's
about 2 minutes between the change.  In another it's 4 seconds.
 
 /* Mon Jul 13 2009 09:38:22.0820 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 09:40:50.7970 */ LOGIN
FAILED      (password)
 
 /* Mon Jul 13 2009 15:12:12.9630 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 15:12:16.9450 */ LOGIN
FAILED      (password)
 
Any one have an understanding of what the logs are trying to tell me?
 
Thanks,
Dave
 
Dave Shellman
 
Phone:  (717) 810-3687
Fax:(717) 810-2124
email:  dave.shell...@tycoelectronics.com
 
Tyco Electronics
MS 161-043
PO Box 3608
Harrisburg, PA 17105-3607
 
 
 
_Platinum Sponsor: rmisoluti...@verizon.net ARSlist: "Where the Answers
Are"_ 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2009-07-15 Thread Kaiser, Norm E CIV USAF AFMC 96 CS/SCOKT
Check your case sensitivity. Windows is case insensitive but Remedy is
case sensitive. We had instances where a user's username in Remedy was
keyed in as John.Smith but that user would use john.smith to log on to
Windows and got used to typing his username lower case. Then when we
turned on Cross Ref Blank Password in Remedy, the user would attempt to
log on with john.smith, but to Remedy, his username was John.Smith.

Norm

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:arsl...@arslist.org] On Behalf Of Shellman, David
Sent: Wednesday, July 15, 2009 9:14 AM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

** 
We configured our 7.0.1 server (Windows server Oracle instance) to
validate passwords against Active Directory over the weekend.  Monday
morning was a little rough with locking out network accounts.  We also
had a configuration issue where were not able to check one of the OU's.
We changed the configuration but we still had a few users where we are
having login issues.
 
While looking at the user log file I noticed a changed with what is
written out to the log for a login failure.  What I'm seeing is that
sometimes (password) is at the end of the line and sometimes (user) is
at the end of the line. For certain users it's consistently one or the
other.  In some cases it changes from one to another.  In one case it's
about 2 minutes between the change.  In another it's 4 seconds.
 
 /* Mon Jul 13 2009 09:38:22.0820 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 09:40:50.7970 */ LOGIN
FAILED      (password)
 
 /* Mon Jul 13 2009 15:12:12.9630 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 15:12:16.9450 */ LOGIN
FAILED      (password)
 
Any one have an understanding of what the logs are trying to tell me?
 
Thanks,
Dave
 
Dave Shellman
 
Phone:  (717) 810-3687
Fax:(717) 810-2124
email:  dave.shell...@tycoelectronics.com
 
Tyco Electronics
MS 161-043
PO Box 3608
Harrisburg, PA 17105-3607
 
 
 
_Platinum Sponsor: rmisoluti...@verizon.net ARSlist: "Where the Answers
Are"_ 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2009-07-15 Thread Nichols, Wesley D CTR USAF AFMC 72 CS/SCBAF
You might try looking at the plug-in logs... You can set the
granularity, I believe you have to add Plugin-Log-Level: 100 to you
config file.  This should give a ton of information about the
interaction between AD and the AREA plugin...

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:arsl...@arslist.org] On Behalf Of Shellman, David
Sent: Wednesday, July 15, 2009 9:14 AM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

** 
We configured our 7.0.1 server (Windows server Oracle instance) to
validate passwords against Active Directory over the weekend.  Monday
morning was a little rough with locking out network accounts.  We also
had a configuration issue where were not able to check one of the OU's.
We changed the configuration but we still had a few users where we are
having login issues.
 
While looking at the user log file I noticed a changed with what is
written out to the log for a login failure.  What I'm seeing is that
sometimes (password) is at the end of the line and sometimes (user) is
at the end of the line. For certain users it's consistently one or the
other.  In some cases it changes from one to another.  In one case it's
about 2 minutes between the change.  In another it's 4 seconds.
 
 /* Mon Jul 13 2009 09:38:22.0820 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 09:40:50.7970 */ LOGIN
FAILED      (password)
 
 /* Mon Jul 13 2009 15:12:12.9630 */ LOGIN
FAILED      (user)
 /* Mon Jul 13 2009 15:12:16.9450 */ LOGIN
FAILED      (password)
 
Any one have an understanding of what the logs are trying to tell me?
 
Thanks,
Dave
 
Dave Shellman
 
Phone:  (717) 810-3687
Fax:(717) 810-2124
email:  dave.shell...@tycoelectronics.com
 
Tyco Electronics
MS 161-043
PO Box 3608
Harrisburg, PA 17105-3607
 
 
 
_Platinum Sponsor: rmisoluti...@verizon.net ARSlist: "Where the Answers
Are"_ 

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"


Active Directory Integration

2009-07-15 Thread Shellman, David
We configured our 7.0.1 server (Windows server Oracle instance) to validate 
passwords against Active Directory over the weekend.  Monday morning was a 
little rough with locking out network accounts.  We also had a configuration 
issue where were not able to check one of the OU's.  We changed the 
configuration but we still had a few users where we are having login issues.

While looking at the user log file I noticed a changed with what is written out 
to the log for a login failure.  What I'm seeing is that sometimes (password) 
is at the end of the line and sometimes (user) is at the end of the line. For 
certain users it's consistently one or the other.  In some cases it changes 
from one to another.  In one case it's about 2 minutes between the change.  In 
another it's 4 seconds.

 /* Mon Jul 13 2009 09:38:22.0820 */ LOGIN FAILED   
   (user)
 /* Mon Jul 13 2009 09:40:50.7970 */ LOGIN FAILED   
   (password)

 /* Mon Jul 13 2009 15:12:12.9630 */ LOGIN FAILED   
   (user)
 /* Mon Jul 13 2009 15:12:16.9450 */ LOGIN FAILED   
   (password)

Any one have an understanding of what the logs are trying to tell me?

Thanks,
Dave

Dave Shellman

Phone:  (717) 810-3687
Fax:(717) 810-2124
email:  dave.shell...@tycoelectronics.com

Tyco Electronics
MS 161-043
PO Box 3608
Harrisburg, PA 17105-3607




___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor:rmisoluti...@verizon.net ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2008-09-08 Thread ITSM SUPPORT
Hi Ajit,

 

 

You can do one thing for the problem regarding LDAP mapping you have.

 

You need to check for which type of permission is required for requester
console.

Create a Group and map that group with the particular Role in Roles Form.
And After that You need to map that Group with LDAP Group from Server
Information External Authentication tab.

 

 

Hope this helps... 

 

Regards, 

 

Sandeep  

Vyom Labs Pvt. Ltd. 

An ISO 2 certified company. 

Consulting | Outsourcing | Training || BMC Remedy BSM | ITIL 

Web: www.vyomlabs.com   

 

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of AR_User
Sent: Saturday, September 06, 2008 2:08 PM
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

 

Hello All,

 

I am on ARS 7.1, ITSM 7.0.0.3 and integrated Active Directory (ARDBC and

AREA) with the system.

 

Now users can login into system by using their Active directory login

information.

 

But while creating new request it gives an error as following:

 

"You must be a registered user to access the  Requester Console.  Please

contact your Administrator to register for the Requester Application. "

 

I want to know that, do I need to populate active directory user data into

People form?

 

Please help me out.

 

Thanks & Regards,

Ajit

 

-- 

View this message in context:
http://www.nabble.com/Active-Directory-Integration-tp19344286p19344286.html

Sent from the ARS (Action Request System) mailing list archive at
Nabble.com.

 


___

UNSUBSCRIBE or access ARSlist Archives at www.arslist.org

Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2008-09-06 Thread Matt Worsdell
The simple answer is that passwords are managed in AD, according to
expiration rules etc. 

However you can further configure the AD integration to map groups in AD to
permissions in Remedy. This means group access is configured purely in AD

In addition, the ARDBC integration will allow you to create custom workflow
that creates and updates users.

All of this is explained in the manual.

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of AR_User
Sent: 06 September 2008 11:25
To: arslist@ARSLIST.ORG
Subject: Re: Active Directory Integration

Hello Matt,

Thank you very much for your quick reply.

If this is so, then what are the advantages of integrating ARS with Active
Directory.

Will you please update me more on this?

I'd be grateful to you.

Thanks & Regards,
Ajit

Matt Worsdell-2 wrote:
> 
> Yes you do. You need to create the users and leave them with a blank
> password to ensure they authenticate against AD.
> 
> -Original Message-
> From: Action Request System discussion list(ARSList)
> [mailto:[EMAIL PROTECTED] On Behalf Of AR_User
> Sent: 06 September 2008 09:38
> To: arslist@ARSLIST.ORG
> Subject: Active Directory Integration
> 
> Hello All,
> 
> I am on ARS 7.1, ITSM 7.0.0.3 and integrated Active Directory (ARDBC and
> AREA) with the system.
> 
> Now users can login into system by using their Active directory login
> information.
> 
> But while creating new request it gives an error as following:
> 
> "You must be a registered user to access the  Requester Console.  Please
> contact your Administrator to register for the Requester Application. "
> 
> I want to know that, do I need to populate active directory user data into
> People form?
> 
> Please help me out.
> 
> Thanks & Regards,
> Ajit
> 
> -- 
> View this message in context:
>
http://www.nabble.com/Active-Directory-Integration-tp19344286p19344286.html
> Sent from the ARS (Action Request System) mailing list archive at
> Nabble.com.
> 
>

> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"
> 
>

___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"
> 
> 

-- 
View this message in context:
http://www.nabble.com/Active-Directory-Integration-tp19344286p19345139.html
Sent from the ARS (Action Request System) mailing list archive at
Nabble.com.


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2008-09-06 Thread AR_User
Hello Matt,

Thank you very much for your quick reply.

If this is so, then what are the advantages of integrating ARS with Active
Directory.

Will you please update me more on this?

I'd be grateful to you.

Thanks & Regards,
Ajit

Matt Worsdell-2 wrote:
> 
> Yes you do. You need to create the users and leave them with a blank
> password to ensure they authenticate against AD.
> 
> -Original Message-
> From: Action Request System discussion list(ARSList)
> [mailto:[EMAIL PROTECTED] On Behalf Of AR_User
> Sent: 06 September 2008 09:38
> To: arslist@ARSLIST.ORG
> Subject: Active Directory Integration
> 
> Hello All,
> 
> I am on ARS 7.1, ITSM 7.0.0.3 and integrated Active Directory (ARDBC and
> AREA) with the system.
> 
> Now users can login into system by using their Active directory login
> information.
> 
> But while creating new request it gives an error as following:
> 
> "You must be a registered user to access the  Requester Console.  Please
> contact your Administrator to register for the Requester Application. "
> 
> I want to know that, do I need to populate active directory user data into
> People form?
> 
> Please help me out.
> 
> Thanks & Regards,
> Ajit
> 
> -- 
> View this message in context:
> http://www.nabble.com/Active-Directory-Integration-tp19344286p19344286.html
> Sent from the ARS (Action Request System) mailing list archive at
> Nabble.com.
> 
> 
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"
> 
> ___
> UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
> Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"
> 
> 

-- 
View this message in context: 
http://www.nabble.com/Active-Directory-Integration-tp19344286p19345139.html
Sent from the ARS (Action Request System) mailing list archive at Nabble.com.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"


Re: Active Directory Integration

2008-09-06 Thread Matt Worsdell
Yes you do. You need to create the users and leave them with a blank
password to ensure they authenticate against AD.

-Original Message-
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of AR_User
Sent: 06 September 2008 09:38
To: arslist@ARSLIST.ORG
Subject: Active Directory Integration

Hello All,

I am on ARS 7.1, ITSM 7.0.0.3 and integrated Active Directory (ARDBC and
AREA) with the system.

Now users can login into system by using their Active directory login
information.

But while creating new request it gives an error as following:

"You must be a registered user to access the  Requester Console.  Please
contact your Administrator to register for the Requester Application. "

I want to know that, do I need to populate active directory user data into
People form?

Please help me out.

Thanks & Regards,
Ajit

-- 
View this message in context:
http://www.nabble.com/Active-Directory-Integration-tp19344286p19344286.html
Sent from the ARS (Action Request System) mailing list archive at
Nabble.com.


___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"


Active Directory Integration

2008-09-06 Thread AR_User
Hello All,

I am on ARS 7.1, ITSM 7.0.0.3 and integrated Active Directory (ARDBC and
AREA) with the system.

Now users can login into system by using their Active directory login
information.

But while creating new request it gives an error as following:

"You must be a registered user to access the  Requester Console.  Please
contact your Administrator to register for the Requester Application. "

I want to know that, do I need to populate active directory user data into
People form?

Please help me out.

Thanks & Regards,
Ajit

-- 
View this message in context: 
http://www.nabble.com/Active-Directory-Integration-tp19344286p19344286.html
Sent from the ARS (Action Request System) mailing list archive at Nabble.com.

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"


Active Directory Integration

2008-05-11 Thread Ramy S. Ayoub
Hi List,



I have issue with integration with Active Directory; we have in the company
two domain one for the Users Data and the second one for the Users
authentications



In this case how we can configure two LDAP connections?



ARS 7.1

ITSM 7.0.3

Windows

SQL 2005



Regards,

Ramy

___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
Platinum Sponsor: www.rmsportal.com ARSlist: "Where the Answers Are"