Previous Topic: Ensure that CA IAM Connector Server Is InstalledNext Topic: How to Migrate Data from the Plug-in Connector to the New Java Connector


Import the CA LDAP Server Certificate into the CA IAM Connector Server Keystore

This procedure is for the Identity Management and CA CloudMinder administrator. If CA IAM Connector Server already has the CA LDAP Server certificate, ignore this procedure.

After the mainframe security administrator has confirmed that CA LDAP Server is configured to use SSL, you can import the CA LDAP Server certificate into the CA IAM Connector Server keystore.

Follow these steps:

  1. Identify the certificate which you want to import into the CA IAM Connector Server keystore as a trusted certificate:
  2. Import the chosen certificates:
    1. Log in to CA IAM Connector Server.
    2. At the top, click the Certificates tab.

      The Certificates tab lists all of the certificates in the CA IAM Connector Server keystore. To filter the list of certificates by their names, type in the Certificate Filter box.

    3. To add a certificate, click Add, then enter the details of the certificate:
      • Certificate—Enter the path to the certificate file
      • Alias—Enter an alias for storing the certificate
Map Custom Attributes for Identity Management

This procedure is for the CA CloudMinder or Identity Management administrator.

When you connect to an endpoint, the objects on the endpoint are mapped to objects in CA CloudMinder or Identity Management. The mapping happens automatically. If you want to make custom mappings, use Connector Xpress.

For the instructions about setting up custom mapping with Connector Xpress, search for Managing Accounts and Groups in the CA CloudMinder bookshelf or in the Identity Management bookshelf.

To see a list of the objects on the endpoint, download the attribute list from the following page: Download page for Endpoint Guides.

Any LDAP attribute on the mainframe that has a string representation can be exposed as a custom attribute in the connector. To map custom attributes, use Connector Xpress. For information, search for Managing Accounts and Groups in the Identity Management bookshelf or CA CloudMinder bookshelf.

Relationships Between Objects

The following diagram illustrates the relationships between accounts and other objects in CA Top Secret v2:

Diagram of the relationships between objects in a CA Top Secret endpoint

Note: The association between an ACID and a group or profile may have an expiry date.

Only the Groups and Profile attributes are available for use by CA GovernanceMinder. If you set up custom mapping for CA GovernanceMinder, ensure that you use the "Expire Date" attributes only.