Previous Topic: New FeaturesNext Topic: 12.6.4


12.6.5

New Certifications

The following new platforms are certified with CA Identity Manager r12.6.5:

Endpoints

Operating Systems

Application Server

Repositories

Enhanced Provisioning using CSV Files with Connector Xpress

This version supports creating data sources and provisioning endpoints with CSV files. The Connector Xpress flat-file functionality can load CSVs locally or with FTP, HTTP, and Samba protocols. CSV files can be exported to support provisioning to endpoints as well. Specifically, administrators can define a location, enter credentials, define a schedule, and output delta changes from CA Identity Manager to endpoints. Administrators can alternatively also configure email notifications of the output delta changes to an endpoint admin who can then use the endpoint management console to fulfil the provisioning requests manually. An Explore and Correlate will subsequently refresh the information in CA Identity Manager with the latest state of the endpoint.

The data exported to CSV can be processed in the two ways described here.

Provisioning to an endpoint with an SDK or API

Endpoint systems for which CA Identity Manager does not provide a connector, but for which the endpoint system does provide a user provisioning SDK or API, could support a third-party development. The delta file CSV output is read from a directory or folder and then the endpoint user provisioning SDK or API is used to modify the endpoint. An explore and correlate is required to refresh the CA Identity Manager environment.

Provisioning to an endpoint without an SDK or API

CA Identity Manager emails the endpoint system admin the delta of changes between two different times. The admin can then manually make the changes to the endpoint. An explore and correlate is required to refresh the CA Identity Manager environment.

Increased Performance Running Tasks

You can now run tasks, such as bulk load, and explore and correlate faster. The performance increase applies to all tasks. CA Identity Manager has been optimized to use one database connection instead of two for processing tasks.

Enhanced Record Collection from SCIM Endpoints with Pagination Support

When connecting SCIM endpoints to Identity Manager, you can configure pagination settings. Pagination allows you to retrieve all the endpoint records during explore and correlate. Previously, the SCIM connector would retrieve only the number of records specified by the endpoint API. Additionally, SCIM endpoints that support pagination are not required to send all the records at one request. Instead, they can be provided page by page for better performance.

For SCIM documentation and downloads, see https://wiki.ca.com/display/IMGC10/SCIM.

Service Desk Integration for CA Identity Manager

Normalized Integration Management Service Management (NIM SM) integration enables you to integrate CA Identity Manager with a number of service desk products through a single normalized RESTful API. NIM provides a fully embedded web service that exposes this RESTful API and internally translates all requests into native service desk format based on a set of configurable mappings.

By using Policy Xpress and its web services actions you can automatically create service desk tickets based on Task and Event state within CA Identity Manager.

For more information, see the Configuration Guide.

Box CA API Gateway Connector

This version includes a Box CA API Gateway Connector. Your connector administrator can download the documentation and attribute list from https://wiki.ca.com/display/IMGC10/Box+CA+API+Gateway. CA Support Credentials are required for access.

Google Apps CA API Gateway Connector

This version includes the Google Apps API Gateway Connector. The attribute list and the documentation are available at https://wiki.ca.com/display/IMGC10/Google+Apps. CA Support Credentials are required for access.

This version of the connector automatically transfers files from deleted users to administrators. See the documentation Introduction for additional information on features and updates.

Support for Managing and Synching Active Directory Users by Custom Active Directory Attributes

Administrators can add custom Active Directory attributes to their account templates allowing them to:

The administrator needs to download the Attribute list from the Downloads Section of the Microsoft Active Directory Connector documentation at https://wiki.ca.com/display/IMGC10/Microsoft+Active+Directory%2C+Microsoft+Exchange%2C+and+Microsoft+Lync .

Following configuration, a Custom tab is available to the administrator.

Manage Universal Active Directory Groups from the User Console

Administrators can build templates to set users in one Active Directory domain as a member of a universal group created in a different Active Directory domain with the option Universal Groups Only.To use this option, save the account template as a Universal Group Only template. A Universal Group Only template is only for Universal Group membership assignment. All other fields on the template are unused and are applied to accounts.

Support for Cross-Reference Roles with ACF2 Java Connector

ACF2 roles are available for account templates to load users and role assignments between CA Identity Manager and a CA ACF2 endpoint. This feature is available by default with this version of CA Identity Manager. It can also be added to previous implementations by installing the connector module and following the configuration steps packaged with the readme. For the ACF2 documentation and downloads, see https://wiki.ca.com/display/IMGC10/CA+ACF2.

Informative Error Messages for CA Single-Sign On Integration

Informative error messages are provided for problematic integrations with CA Single Sign-On. These messages help deployment and integration teams quickly identify problems and complete problematic integrations in less time.

Reduced Exposure to OpenSSL Vulnerabilities

Updated CA Identity Manager to CAPKI 4.x from CAPKI 3.x. This reduces the exposure to known OpenSSL vulnerabilities.

Different Administrator Email Address for Each Environment

Previous versions allowed one administrator email address in the CA Identity Manager Management Console for all environments in the deployment. You can now specify an administrator email address for each environment.

Reduce Permissions to the Oracle Connector

This version supports customizing and reducing permissions for users to the Oracle connector. For information and instructions, please see the the Oracle connector documentation at https://wiki.ca.com/display/IMGC10/Oracle+Applications+Connector.

Consistent Security Validation across the Web User Interface

When using TEWS, security validation was inconsistent across the web user interface. This version adds consistent security validation across the web user interface. This improvement also increases security for CA Single Sign-On integrations.