Ldap Import Filter Does Not Work Correctly

(Doc ID 951323.1)

Last updated on OCTOBER 16, 2009

Applies to:

Oracle Utilities Framework - Version: 2.2.0 to 2.2.0
Information in this document applies to any platform.

Goal

In LDAP Import window, after;user searched by a user: user1, it returned 3 groups. After they clicked
synchronization button, it imported all available groups from LDAP instead of the 3 groups that
user1belonged to.
What is happening is that distinguishedName is being used in the search filter to link the groups to the user. distinguishedName isn't actually an attribute of the schema so the substitution of member=%distinguishedName% is being replaced with member=* so it ends up returning all groups that meet the other criteria and have at least one member.
Previously in the other bugs, we fixed this in the online front end (XAI) by synthesizing a disinguishedName attribute as the distinguishedName is quite easily obtained from the LDAP search results.
MPL doesn't use the exact same code to query the linked results so it was missing the synthesized distinguishedName attribute. That is why the results looked correct in the LDAP Import page but different results were obtained by MPL when it processed the import request.

Solution

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms