The following items are the list of group well-known attributes:
Indicates which attribute stores a list of groups that are administrators of the group. For example, when group 1 is an administrator of group A, group 1 is stored in the %GROUP_ADMIN_GROUP% attribute.
Note: If you do not specify a %GROUP_ADMIN_GROUP% attribute, CA IdentityMinder stores administrator groups in the %GROUP_ADMIN% attribute.
Note: To add a group as an administrator of another group, see the Administration Guide.
Indicates which attribute contains the DNs of administrators of a group.
The physical attribute that mapped to %GROUP_ADMIN% must be multivalued.
Indicates which attribute contains description of a group.
(Required)
Indicates which attribute contains a list of the member of a group.
The physical attribute that mapped to %GROUP_MEMBERSHIP% must be multivalued.
The %GROUP_MEMBERSHIP% well-known attribute is not required for Provisioning user directories.
(Required)
Indicates which attribute stores a group name.
(Required)
Indicates which attribute contains the DN of the organization to which the group belongs.
CA IdentityMinder uses this well-known attribute to determine structure of the directory.
This attribute is not required when the user directory does not include organizations.
Indicates which attribute contains the user-friendly name of the organization in which the group exists.
This attribute is not valid for user directories that do not include organizations.
Indicates which attribute determines whether users can subscribe to a group.
Indicates which attribute stores a list of groups that are members of the group. For example, when group 1 is a member of group A, group 1 is stored in the %NESTED_GROUP_MEMBERSHIP% attribute.
If you do not specify a %NESTED_GROUP_MEMBERSHIP% attribute, CA IdentityMinder stores nested groups in the %GROUP_MEMBERSHIP% attribute.
To include groups as members of other groups, configure support for nested groups as described in Configuring Dynamic and Nested Groups for instructions.
Indicates which attribute stores the LDAP query that generates a dynamic group.
Note: To extend the available attributes for the Group object to include %NESTED_GROUP_MEMBERSHIP% and %DYNAMIC_GROUP_MEMBERSHIP% attributes, you can use auxiliary object classes.
Copyright © 2013 CA.
All rights reserved.
|
|