OIM ldap sync vs ldap connector

OIM LDAP Sync

LDAP sync (LDAP Synchronization) is the bidirectional process of exposing the security principals (users, user groups, and roles). This process copies OIM user changes (add, modify, delete) to Oracle Internet Directory (OID) via Oracle Virtual Directory (OVD). LDAP sync runs behind the scene and uses scheduled jobs or reconciliation engine to pull changes from LDAP and event handlers to push data to LDAP.
Is OVD a mandatory element?
It Depends on OIM version.
  • OIM 11.1.1.3.x version requires external OVD server for LDAP Sync.
  • OIM 11.1.1.5 (PS1) versions support both external OVD server as well as inbuilt libOVD (OVD plugin part of OIM ). This means that OVD is an optional component here.
LDAP Sync Vs LDAP connector:
As some of you might be wondering what the difference is, let me make this clear to you that there are some overlap in functionalities between these options and that you have to consciously choose the appropriate one. Here are some of the deciders:
  •  LDAP sync becomes a mandatory element for OIM-OAM integration in the 11g world. In the integrated scenario LDAP sync provides complete password lifecycle management.
  •  LDAP sync is a feature that allows bidirectional synchronization between LDAP and OIM. Don’t expect OIM to manage the LDAP as a resource or target system.
  •  LDAP connector adds the LDAP instance as a resource or target system in OIM. There are a number of actions you can attach around your target systems such as: Workflows, provisioning operations, approvals, requests etc.
  •  LDAP sync does not synchronize Organizations. Users and Roles are the main elements.
  •  Additional features such as Audit, Reporting can only be done with LDAP connector.
  •  Having said all those, I may assert that there can be such requirements that both LDAP sync and LDAP connector might be required for a typical implementation. So brainstorm on your requirement and weigh fine differences of the scenarios before arriving at a decision.
LDAP sync can be setup while installation of Oracle Identity Manager as well as later.
How to Setup LDAP Sync After Install in OIM 11g?

Note on LDAP sync - 
Any changes to users that are made in Ldap directly, these changes will be synched back to OIM.
We know that the changes made to users in OIM are replicated to OID immediately.
This is because the LDAP Sync is bidirectional and it uses scheduled jobs/reconciliation engine to pull changes from LDAP and uses event handlers to push data to LDAP.

Comments

Post a Comment

Popular posts from this blog

VMware fix for Invalid manifest and ova file import failed errors

Session Timeout in Oracle Access Manager

SOAPUI - import certificate