Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [03/20/12 07:49:45.582]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.582]:Active Directory PT: (if-class-name equal "$current-node$") = FALSE.
- [03/20/12 07:49:45.583]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.583]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.583]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.583]:Active Directory PT: (if-local-variable 'pass' not-available) = TRUE.
- [03/20/12 07:49:45.583]:Active Directory PT: Performing if actions.
- [03/20/12 07:49:45.583]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:45.583]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.584]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="report status" level="success"></status>
- <status event-id="write state" level="success"><application>DirXML</application>
- <module>Active Directory</module>
- <object-dn></object-dn>
- <component>Publisher</component>
- </status>
- </output>
- </nds>
- [03/20/12 07:49:45.584]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="report status" level="success"></status>
- <status event-id="write state" level="success"><application>DirXML</application>
- <module>Active Directory</module>
- <object-dn></object-dn>
- <component>Publisher</component>
- </status>
- </output>
- </nds>
- [03/20/12 07:49:45.933]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:49:45.933]:Active Directory :
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.934]:Active Directory :Remote Interface Driver: Received document for publisher channel
- [03/20/12 07:49:45.934]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:49:45.934]:Active Directory PT:Receiving DOM document from application.
- [03/20/12 07:49:45.934]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.935]:Active Directory PT:Applying input transformation policies.
- [03/20/12 07:49:45.935]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Publish-itp-V1%-C.
- [03/20/12 07:49:45.935]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.935]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:45.935]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.935]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:45.936]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.936]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.936]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:45.936]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.936]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.936]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.936]:Active Directory PT: (if-class-name available) = FALSE.
- [03/20/12 07:49:45.936]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.937]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add-association sync the operation-properties to status operations'.
- [03/20/12 07:49:45.937]:Active Directory PT: (if-operation equal "add-association") = FALSE.
- [03/20/12 07:49:45.937]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.937]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Query for destination DN using Association'.
- [03/20/12 07:49:45.937]:Active Directory PT: (if-operation match "modify|delete|move|rename") = FALSE.
- [03/20/12 07:49:45.938]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.938]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:49:45.938]:Active Directory PT: (if-operation match "add|modify|delete|rename|move|status") = TRUE.
- [03/20/12 07:49:45.938]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.938]:Active Directory PT: Applying rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:49:45.938]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.identifiers"))).
- [03/20/12 07:49:45.939]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.identifiers"))
- [03/20/12 07:49:45.939]:Active Directory PT: token-global-variable("drv.acctTrk.identifiers")
- [03/20/12 07:49:45.939]:Active Directory PT: Token Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:49:45.939]:Active Directory PT: Arg Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:49:45.939]:Active Directory PT: Performing actions for local-variable(current-node) = "sAMAccountName".
- [03/20/12 07:49:45.939]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.940]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.940]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:49:45.940]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.940]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.940]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.940]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:49:45.940]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.941]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.941]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.941]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:49:45.941]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:45.941]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:49:45.941]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:45.942]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.942]:Active Directory PT: Performing actions for local-variable(current-node) = "userPrincipalName".
- [03/20/12 07:49:45.942]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.942]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.942]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:49:45.942]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.942]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.943]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.943]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:49:45.943]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.943]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.943]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.943]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:49:45.943]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:45.944]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:49:45.944]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:45.944]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.944]:Active Directory PT: Performing actions for local-variable(current-node) = "LDAPDN".
- [03/20/12 07:49:45.944]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.944]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.945]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = TRUE.
- [03/20/12 07:49:45.945]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:49:45.945]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:45.945]:Active Directory PT: (if-src-dn available) = FALSE.
- [03/20/12 07:49:45.945]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.945]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.946]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.946]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:49:45.946]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.946]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.946]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.946]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:49:45.946]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:45.947]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:49:45.947]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:45.947]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.947]:Active Directory PT: Performing actions for local-variable(current-node) = "association".
- [03/20/12 07:49:45.947]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.947]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.948]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:49:45.948]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.948]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.948]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.948]:Active Directory PT: (if-local-variable 'current-node' equal "association") = TRUE.
- [03/20/12 07:49:45.949]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:49:45.949]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:45.949]:Active Directory PT: (if-association available) = FALSE.
- [03/20/12 07:49:45.949]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.949]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.949]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.949]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:49:45.950]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:45.950]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:49:45.950]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:45.950]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:45.950]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Initialize status properties on published events'.
- [03/20/12 07:49:45.951]:Active Directory PT: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:49:45.951]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.951]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.951]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.951]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccounts-itp-V1%-C.
- [03/20/12 07:49:45.952]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.952]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled'.
- [03/20/12 07:49:45.952]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:45.952]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.952]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - query DirXML-Accounts Attribute'.
- [03/20/12 07:49:45.952]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:49:45.952]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.953]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - remove Dirxml-Account values on delete operation'.
- [03/20/12 07:49:45.953]:Active Directory PT: (if-operation match "delete|remove-association") = FALSE.
- [03/20/12 07:49:45.953]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.953]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:49:45.953]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.953]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - update DirXMLAccounts attribute'.
- [03/20/12 07:49:45.954]:Active Directory PT: (if-op-property 'AccountTracking-Operation' not-available) = TRUE.
- [03/20/12 07:49:45.954]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:49:45.954]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.954]:Active Directory PT: (if-xpath true "./@level='success'") = TRUE.
- [03/20/12 07:49:45.954]:Active Directory PT: (if-op-property 'AccountTracking-Operation' available) = FALSE.
- [03/20/12 07:49:45.954]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.955]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.955]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.955]:Active Directory PT:Applying policy: %+C%14Citp%-C.
- [03/20/12 07:49:45.955]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.955]:Active Directory PT: Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:49:45.955]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.956]:Active Directory PT: Applying rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:49:45.956]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
- [03/20/12 07:49:45.956]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:49:45.956]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.956]:Active Directory PT: Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:49:45.956]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
- [03/20/12 07:49:45.957]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:49:45.957]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.957]:Active Directory PT: Applying rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:49:45.957]:Active Directory PT: Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:49:45.957]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:49:45.958]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.958]:Active Directory PT: Applying rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:49:45.958]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:49:45.958]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.958]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.959]:Active Directory PT:Applying policy: %+C%14Citp-EntitlementsImpl%-C.
- [03/20/12 07:49:45.959]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.959]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
- [03/20/12 07:49:45.959]:Active Directory PT: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:49:45.959]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.959]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
- [03/20/12 07:49:45.960]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:49:45.960]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.960]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.960]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.960]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Sub Email Notifications%-C.
- [03/20/12 07:49:45.961]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.961]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
- [03/20/12 07:49:45.961]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:49:45.961]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.961]:Active Directory PT: (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
- [03/20/12 07:49:45.962]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.962]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Manager data store password'.
- [03/20/12 07:49:45.962]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:49:45.962]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.962]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
- [03/20/12 07:49:45.963]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.963]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.963]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.963]:Active Directory PT:Applying policy: %+C%14Clib-Audit-SendEntitlementsEvents-itp-V1%-C.
- [03/20/12 07:49:45.963]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.963]:Active Directory PT: Evaluating selection criteria for rule '00031200 - Account Create By Entitlement Grant'.
- [03/20/12 07:49:45.964]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.964]:Active Directory PT: (if-op-property 'accountAction' equal "accountCreateByEntitlementGrant") = FALSE.
- [03/20/12 07:49:45.964]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.964]:Active Directory PT: Evaluating selection criteria for rule '00031201 - Account Delete By Entitlement Revoke'.
- [03/20/12 07:49:45.964]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.964]:Active Directory PT: (if-xpath true "./operation-data/entitlement-impl/@state = '0'") = FALSE.
- [03/20/12 07:49:45.965]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.965]:Active Directory PT: (if-op-property 'accountAction' equal "accountDeleteByEntitlementRevoke") = FALSE.
- [03/20/12 07:49:45.965]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.965]:Active Directory PT: Evaluating selection criteria for rule '00031202 - Account Disable By Entitlement Revoke'.
- [03/20/12 07:49:45.965]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.965]:Active Directory PT: (if-op-property 'accountAction' equal "accountDisableByEntitlementRevoke") = FALSE.
- [03/20/12 07:49:45.966]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.966]:Active Directory PT: Evaluating selection criteria for rule '00031203 - Account Enable By Entitlement Grant'.
- [03/20/12 07:49:45.966]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.966]:Active Directory PT: (if-op-property 'accountAction' equal "accountEnableByEntitlementGrant") = FALSE.
- [03/20/12 07:49:45.966]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.966]:Active Directory PT: Evaluating selection criteria for rule 'Generate Audit Event'.
- [03/20/12 07:49:45.966]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.967]:Active Directory PT: (if-local-variable 'auditEventID' available) = FALSE.
- [03/20/12 07:49:45.967]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.967]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.967]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.967]:Active Directory PT:Applying schema mapping policies to input.
- [03/20/12 07:49:45.967]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:49:45.968]:Active Directory PT:Resolving association references.
- [03/20/12 07:49:45.968]:Active Directory PT:Applying event transformation policies.
- [03/20/12 07:49:45.968]:Active Directory PT:Applying policy: %+C%14Cpub-etp-EntitlementsImpl%-C.
- [03/20/12 07:49:45.968]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.968]:Active Directory PT: Evaluating selection criteria for rule 'Disallow user account delete when using entitlements'.
- [03/20/12 07:49:45.968]:Active Directory PT: (if-operation equal "delete") = FALSE.
- [03/20/12 07:49:45.969]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.969]:Active Directory PT: Evaluating selection criteria for rule 'Strip Login Disabled from operation (Disable Option)'.
- [03/20/12 07:49:45.969]:Active Directory PT: (if-global-variable 'drv.entitlement.UserAccount' equal "true") = FALSE.
- [03/20/12 07:49:45.969]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.969]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.969]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.970]:Active Directory PT:Applying policy: %+C%14Cpub-etp-HandleMovesAndRenames%-C.
- [03/20/12 07:49:45.970]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.970]:Active Directory PT: Evaluating selection criteria for rule 'break if not a move or rename'.
- [03/20/12 07:49:45.970]:Active Directory PT: (if-operation not-match "move|rename") = TRUE.
- [03/20/12 07:49:45.970]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.970]:Active Directory PT: Applying rule 'break if not a move or rename'.
- [03/20/12 07:49:45.971]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:45.971]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.971]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.971]:Active Directory PT:Applying publisher filter.
- [03/20/12 07:49:45.971]:Active Directory PT:Publisher processing status for .
- [03/20/12 07:49:45.971]:Active Directory PT:Applying command transformation policies.
- [03/20/12 07:49:45.972]:Active Directory PT:Applying policy: %+C%14Cpub-ctp-UserNameMap%-C.
- [03/20/12 07:49:45.972]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.972]:Active Directory PT: Evaluating selection criteria for rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:49:45.972]:Active Directory PT: (if-class-name not-equal "User") = TRUE.
- [03/20/12 07:49:45.972]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.972]:Active Directory PT: Applying rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:49:45.972]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:45.973]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.973]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.973]:Active Directory PT:Applying policy: %+C%14Cpub-ctp%-C.
- [03/20/12 07:49:45.973]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.973]:Active Directory PT: Evaluating selection criteria for rule 'set cached context value on merge'.
- [03/20/12 07:49:45.974]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:45.974]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.974]:Active Directory PT: Evaluating selection criteria for rule 'Set Equivalent To Me when adding object to a group'.
- [03/20/12 07:49:45.975]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:49:45.975]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.975]:Active Directory PT: Evaluating selection criteria for rule 'Remove Equivalent To Me when removing object from a group'.
- [03/20/12 07:49:45.975]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:49:45.975]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.975]:Active Directory PT: Evaluating selection criteria for rule 'remove managed attributes when object disassociated'.
- [03/20/12 07:49:45.975]:Active Directory PT: (if-operation equal "remove-association") = FALSE.
- [03/20/12 07:49:45.976]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.976]:Active Directory PT: Evaluating selection criteria for rule 'Prevent unassociated users from being removed from groups'.
- [03/20/12 07:49:45.976]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:45.976]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.976]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.976]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.977]:Active Directory PT:Applying XSLT policy: %+C%14Cpub-cts%-C.
- [03/20/12 07:49:45.977]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.977]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.978]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Default Password Policy%-C.
- [03/20/12 07:49:45.978]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.978]:Active Directory PT: Evaluating selection criteria for rule 'On User add, provide default password of @Dirxml1 if no password exists'.
- [03/20/12 07:49:45.978]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:45.978]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.979]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.979]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.979]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Check Password GCV%-C.
- [03/20/12 07:49:45.979]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.979]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to Identity Manager data store when adding a object'.
- [03/20/12 07:49:45.980]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:49:45.980]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.980]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the Identity Manager data store'.
- [03/20/12 07:49:45.980]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:49:45.980]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.980]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.980]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.981]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish Distribution Password%-C.
- [03/20/12 07:49:45.981]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.981]:Active Directory PT: Evaluating selection criteria for rule 'Add nspmDistributionAttribute attribute to add operation'.
- [03/20/12 07:49:45.981]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:49:45.982]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.982]:Active Directory PT: Evaluating selection criteria for rule 'Change modify-password operations to a modify'.
- [03/20/12 07:49:45.982]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:49:45.982]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.982]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.982]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.983]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish NDS Password%-C.
- [03/20/12 07:49:45.983]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.983]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to NDS password'.
- [03/20/12 07:49:45.983]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:49:45.983]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.983]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the NDS password'.
- [03/20/12 07:49:45.984]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:49:45.984]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.984]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.984]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.984]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Add Password Payload%-C.
- [03/20/12 07:49:45.984]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.985]:Active Directory PT: Evaluating selection criteria for rule 'Add operation-data element to password operations'.
- [03/20/12 07:49:45.985]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:45.985]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:45.985]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:49:45.985]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:45.985]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.985]:Active Directory PT: Evaluating selection criteria for rule 'Add payload data to password operations'.
- [03/20/12 07:49:45.986]:Active Directory PT: (if-operation equal "addPayloadToPassword") = FALSE.
- [03/20/12 07:49:45.986]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:45.986]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:49:45.986]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:45.986]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.986]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.986]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.987]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccountsOnAdds-pub-ctp-V1%-C.
- [03/20/12 07:49:45.987]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.987]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard policy if disabled'.
- [03/20/12 07:49:45.987]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:45.987]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.988]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add operation add Dirxml-Accounts'.
- [03/20/12 07:49:45.988]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:45.988]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.988]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.988]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:45.989]:Active Directory PT:Filtering out notification-only attributes.
- [03/20/12 07:49:45.989]:Active Directory PT:Pumping XDS to eDirectory.
- [03/20/12 07:49:45.989]:Active Directory PT:Performing operation status for .
- [03/20/12 07:49:45.989]:Active Directory PT:
- DirXML Log Event -------------------
- Driver: \EDIR2ADLAB\fdny\AD-TEST\Active Directory
- Channel: Publisher
- Status: Success
- [03/20/12 07:49:45.989]:Active Directory PT:Fixing up association references.
- [03/20/12 07:49:45.990]:Active Directory PT:Applying schema mapping policies to output.
- [03/20/12 07:49:45.990]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:49:45.990]:Active Directory PT:Applying output transformation policies.
- [03/20/12 07:49:45.990]:Active Directory PT:Applying policy: %+C%14Cotp%-C.
- [03/20/12 07:49:45.990]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.990]:Active Directory PT: Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:49:45.991]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.991]:Active Directory PT: Applying rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:49:45.991]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
- [03/20/12 07:49:45.991]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:49:45.991]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.991]:Active Directory PT: Applying rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:49:45.992]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
- [03/20/12 07:49:45.992]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
- [03/20/12 07:49:45.992]:Active Directory PT: (if-op-attr 'accountExpires' changing) = FALSE.
- [03/20/12 07:49:45.992]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.992]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:49:45.992]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.993]:Active Directory PT: Applying rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:49:45.993]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
- [03/20/12 07:49:45.993]:Active Directory PT: Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
- [03/20/12 07:49:45.993]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:45.993]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.993]:Active Directory PT: Evaluating selection criteria for rule 'update Active Directory logon name'.
- [03/20/12 07:49:45.994]:Active Directory PT: (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
- [03/20/12 07:49:45.994]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.994]:Active Directory PT: Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:49:45.994]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = TRUE.
- [03/20/12 07:49:45.994]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.994]:Active Directory PT: Applying rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:49:45.995]:Active Directory PT: Action: do-strip-op-attr("homeMDB").
- [03/20/12 07:49:45.995]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.995]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:45.995]:Active Directory PT:Applying policy: %+C%14CPassword(Sub)-Pub Email Notifications%-C.
- [03/20/12 07:49:45.995]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.996]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
- [03/20/12 07:49:45.996]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:49:45.996]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:45.996]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-publish-status") = FALSE.
- [03/20/12 07:49:45.996]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:45.996]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.996]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:45.997]:Active Directory PT:Applying policy: %+C%14Clib-CredProv-ConvertPayload-otp-V1%-C.
- [03/20/12 07:49:45.997]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.997]:Active Directory PT: Evaluating selection criteria for rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:49:45.997]:Active Directory PT: Rule selected.
- [03/20/12 07:49:45.998]:Active Directory PT: Applying rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:49:45.998]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:45.998]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:45.998]:Active Directory PT: (if-global-variable 'credprov.enable' not-equal "true") = TRUE.
- [03/20/12 07:49:45.998]:Active Directory PT: Performing if actions.
- [03/20/12 07:49:45.998]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:45.998]:Active Directory PT:Policy returned:
- [03/20/12 07:49:45.999]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:45.999]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Subscribe-otp-V1%-C.
- [03/20/12 07:49:45.999]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:45.999]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:45.999]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.000]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:46.000]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.000]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.000]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:46.000]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.000]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
- [03/20/12 07:49:46.000]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
- [03/20/12 07:49:46.001]:Active Directory PT: token-global-variable("drv.acctTrk.objectClass")
- [03/20/12 07:49:46.001]:Active Directory PT: Token Value: {"user"}.
- [03/20/12 07:49:46.001]:Active Directory PT: Arg Value: {"user"}.
- [03/20/12 07:49:46.001]:Active Directory PT: Performing actions for local-variable(current-node) = "user".
- [03/20/12 07:49:46.001]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.001]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.002]:Active Directory PT: (if-class-name equal "$current-node$") = FALSE.
- [03/20/12 07:49:46.002]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.002]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.002]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.002]:Active Directory PT: (if-local-variable 'pass' not-available) = TRUE.
- [03/20/12 07:49:46.002]:Active Directory PT: Performing if actions.
- [03/20/12 07:49:46.002]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:46.002]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.003]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.003]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.003]:Active Directory PT:Remote Interface Driver: Sending...
- [03/20/12 07:49:46.004]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.004]:Active Directory PT:Remote Interface Driver: Document sent.
- [03/20/12 07:49:46.896]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:49:46.897]:Active Directory :
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.897]:Active Directory :Remote Interface Driver: Received document for publisher channel
- [03/20/12 07:49:46.897]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:49:46.897]:Active Directory PT:Receiving DOM document from application.
- [03/20/12 07:49:46.898]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.898]:Active Directory PT:Applying input transformation policies.
- [03/20/12 07:49:46.898]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Publish-itp-V1%-C.
- [03/20/12 07:49:46.898]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.899]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:46.899]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.899]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:46.899]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.899]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.899]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:46.900]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.900]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.900]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.900]:Active Directory PT: (if-class-name available) = FALSE.
- [03/20/12 07:49:46.900]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.900]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add-association sync the operation-properties to status operations'.
- [03/20/12 07:49:46.901]:Active Directory PT: (if-operation equal "add-association") = FALSE.
- [03/20/12 07:49:46.901]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.901]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Query for destination DN using Association'.
- [03/20/12 07:49:46.901]:Active Directory PT: (if-operation match "modify|delete|move|rename") = FALSE.
- [03/20/12 07:49:46.901]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.901]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:49:46.901]:Active Directory PT: (if-operation match "add|modify|delete|rename|move|status") = TRUE.
- [03/20/12 07:49:46.902]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.902]:Active Directory PT: Applying rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:49:46.902]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.identifiers"))).
- [03/20/12 07:49:46.902]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.identifiers"))
- [03/20/12 07:49:46.902]:Active Directory PT: token-global-variable("drv.acctTrk.identifiers")
- [03/20/12 07:49:46.903]:Active Directory PT: Token Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:49:46.903]:Active Directory PT: Arg Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:49:46.903]:Active Directory PT: Performing actions for local-variable(current-node) = "sAMAccountName".
- [03/20/12 07:49:46.903]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.903]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.903]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:49:46.904]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.904]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.904]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.904]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:49:46.904]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.904]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.904]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.905]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:49:46.905]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:46.905]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:49:46.905]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:46.905]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.905]:Active Directory PT: Performing actions for local-variable(current-node) = "userPrincipalName".
- [03/20/12 07:49:46.906]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.906]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.906]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:49:46.906]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.906]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.906]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.906]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:49:46.907]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.907]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.907]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.907]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:49:46.907]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:46.908]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:49:46.908]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:46.908]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.908]:Active Directory PT: Performing actions for local-variable(current-node) = "LDAPDN".
- [03/20/12 07:49:46.908]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.908]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.908]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = TRUE.
- [03/20/12 07:49:46.909]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:49:46.909]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:46.909]:Active Directory PT: (if-src-dn available) = FALSE.
- [03/20/12 07:49:46.909]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.909]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.909]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.910]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:49:46.910]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.910]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.910]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.910]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:49:46.910]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:46.911]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:49:46.911]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:46.911]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.911]:Active Directory PT: Performing actions for local-variable(current-node) = "association".
- [03/20/12 07:49:46.911]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.911]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.912]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:49:46.912]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.912]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.912]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.912]:Active Directory PT: (if-local-variable 'current-node' equal "association") = TRUE.
- [03/20/12 07:49:46.912]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:49:46.913]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:46.913]:Active Directory PT: (if-association available) = FALSE.
- [03/20/12 07:49:46.913]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.913]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.913]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.913]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:49:46.913]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:49:46.914]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:49:46.914]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:49:46.914]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.914]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Initialize status properties on published events'.
- [03/20/12 07:49:46.914]:Active Directory PT: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:49:46.915]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.915]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.915]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.915]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccounts-itp-V1%-C.
- [03/20/12 07:49:46.915]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.916]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled'.
- [03/20/12 07:49:46.916]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:46.916]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.916]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - query DirXML-Accounts Attribute'.
- [03/20/12 07:49:46.916]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:49:46.916]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.916]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - remove Dirxml-Account values on delete operation'.
- [03/20/12 07:49:46.917]:Active Directory PT: (if-operation match "delete|remove-association") = FALSE.
- [03/20/12 07:49:46.917]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.917]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:49:46.917]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.917]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - update DirXMLAccounts attribute'.
- [03/20/12 07:49:46.917]:Active Directory PT: (if-op-property 'AccountTracking-Operation' not-available) = TRUE.
- [03/20/12 07:49:46.918]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:49:46.918]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.918]:Active Directory PT: (if-xpath true "./@level='success'") = TRUE.
- [03/20/12 07:49:46.918]:Active Directory PT: (if-op-property 'AccountTracking-Operation' available) = FALSE.
- [03/20/12 07:49:46.918]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.918]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.919]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.919]:Active Directory PT:Applying policy: %+C%14Citp%-C.
- [03/20/12 07:49:46.919]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.919]:Active Directory PT: Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:49:46.919]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.920]:Active Directory PT: Applying rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:49:46.920]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
- [03/20/12 07:49:46.920]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:49:46.920]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.920]:Active Directory PT: Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:49:46.920]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
- [03/20/12 07:49:46.921]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:49:46.921]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.921]:Active Directory PT: Applying rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:49:46.921]:Active Directory PT: Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:49:46.921]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:49:46.922]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.922]:Active Directory PT: Applying rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:49:46.922]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:49:46.922]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.922]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.923]:Active Directory PT:Applying policy: %+C%14Citp-EntitlementsImpl%-C.
- [03/20/12 07:49:46.923]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.923]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
- [03/20/12 07:49:46.923]:Active Directory PT: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:49:46.923]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.923]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
- [03/20/12 07:49:46.924]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:49:46.924]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.924]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.924]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.924]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Sub Email Notifications%-C.
- [03/20/12 07:49:46.924]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.925]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
- [03/20/12 07:49:46.925]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:49:46.925]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.925]:Active Directory PT: (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
- [03/20/12 07:49:46.925]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.926]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Manager data store password'.
- [03/20/12 07:49:46.926]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:49:46.926]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.926]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
- [03/20/12 07:49:46.926]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.927]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.927]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.927]:Active Directory PT:Applying policy: %+C%14Clib-Audit-SendEntitlementsEvents-itp-V1%-C.
- [03/20/12 07:49:46.927]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.927]:Active Directory PT: Evaluating selection criteria for rule '00031200 - Account Create By Entitlement Grant'.
- [03/20/12 07:49:46.928]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.928]:Active Directory PT: (if-op-property 'accountAction' equal "accountCreateByEntitlementGrant") = FALSE.
- [03/20/12 07:49:46.928]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.928]:Active Directory PT: Evaluating selection criteria for rule '00031201 - Account Delete By Entitlement Revoke'.
- [03/20/12 07:49:46.928]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.928]:Active Directory PT: (if-xpath true "./operation-data/entitlement-impl/@state = '0'") = FALSE.
- [03/20/12 07:49:46.929]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.929]:Active Directory PT: (if-op-property 'accountAction' equal "accountDeleteByEntitlementRevoke") = FALSE.
- [03/20/12 07:49:46.929]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.929]:Active Directory PT: Evaluating selection criteria for rule '00031202 - Account Disable By Entitlement Revoke'.
- [03/20/12 07:49:46.929]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.929]:Active Directory PT: (if-op-property 'accountAction' equal "accountDisableByEntitlementRevoke") = FALSE.
- [03/20/12 07:49:46.929]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.930]:Active Directory PT: Evaluating selection criteria for rule '00031203 - Account Enable By Entitlement Grant'.
- [03/20/12 07:49:46.930]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.930]:Active Directory PT: (if-op-property 'accountAction' equal "accountEnableByEntitlementGrant") = FALSE.
- [03/20/12 07:49:46.930]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.930]:Active Directory PT: Evaluating selection criteria for rule 'Generate Audit Event'.
- [03/20/12 07:49:46.930]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.931]:Active Directory PT: (if-local-variable 'auditEventID' available) = FALSE.
- [03/20/12 07:49:46.931]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.931]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.931]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.931]:Active Directory PT:Applying schema mapping policies to input.
- [03/20/12 07:49:46.932]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:49:46.932]:Active Directory PT:Resolving association references.
- [03/20/12 07:49:46.932]:Active Directory PT:Applying event transformation policies.
- [03/20/12 07:49:46.932]:Active Directory PT:Applying policy: %+C%14Cpub-etp-EntitlementsImpl%-C.
- [03/20/12 07:49:46.932]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.932]:Active Directory PT: Evaluating selection criteria for rule 'Disallow user account delete when using entitlements'.
- [03/20/12 07:49:46.933]:Active Directory PT: (if-operation equal "delete") = FALSE.
- [03/20/12 07:49:46.933]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.933]:Active Directory PT: Evaluating selection criteria for rule 'Strip Login Disabled from operation (Disable Option)'.
- [03/20/12 07:49:46.933]:Active Directory PT: (if-global-variable 'drv.entitlement.UserAccount' equal "true") = FALSE.
- [03/20/12 07:49:46.933]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.933]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.933]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.934]:Active Directory PT:Applying policy: %+C%14Cpub-etp-HandleMovesAndRenames%-C.
- [03/20/12 07:49:46.934]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.934]:Active Directory PT: Evaluating selection criteria for rule 'break if not a move or rename'.
- [03/20/12 07:49:46.934]:Active Directory PT: (if-operation not-match "move|rename") = TRUE.
- [03/20/12 07:49:46.934]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.934]:Active Directory PT: Applying rule 'break if not a move or rename'.
- [03/20/12 07:49:46.935]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:46.935]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.935]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.935]:Active Directory PT:Applying publisher filter.
- [03/20/12 07:49:46.935]:Active Directory PT:Publisher processing status for .
- [03/20/12 07:49:46.936]:Active Directory PT:Applying command transformation policies.
- [03/20/12 07:49:46.936]:Active Directory PT:Applying policy: %+C%14Cpub-ctp-UserNameMap%-C.
- [03/20/12 07:49:46.936]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.936]:Active Directory PT: Evaluating selection criteria for rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:49:46.936]:Active Directory PT: (if-class-name not-equal "User") = TRUE.
- [03/20/12 07:49:46.936]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.936]:Active Directory PT: Applying rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:49:46.937]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:46.937]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.937]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.937]:Active Directory PT:Applying policy: %+C%14Cpub-ctp%-C.
- [03/20/12 07:49:46.937]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.937]:Active Directory PT: Evaluating selection criteria for rule 'set cached context value on merge'.
- [03/20/12 07:49:46.938]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:46.938]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.938]:Active Directory PT: Evaluating selection criteria for rule 'Set Equivalent To Me when adding object to a group'.
- [03/20/12 07:49:46.938]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:49:46.938]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.938]:Active Directory PT: Evaluating selection criteria for rule 'Remove Equivalent To Me when removing object from a group'.
- [03/20/12 07:49:46.938]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:49:46.939]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.939]:Active Directory PT: Evaluating selection criteria for rule 'remove managed attributes when object disassociated'.
- [03/20/12 07:49:46.939]:Active Directory PT: (if-operation equal "remove-association") = FALSE.
- [03/20/12 07:49:46.939]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.939]:Active Directory PT: Evaluating selection criteria for rule 'Prevent unassociated users from being removed from groups'.
- [03/20/12 07:49:46.939]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:46.940]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.940]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.940]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.940]:Active Directory PT:Applying XSLT policy: %+C%14Cpub-cts%-C.
- [03/20/12 07:49:46.941]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.941]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.941]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Default Password Policy%-C.
- [03/20/12 07:49:46.941]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.942]:Active Directory PT: Evaluating selection criteria for rule 'On User add, provide default password of @Dirxml1 if no password exists'.
- [03/20/12 07:49:46.942]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:46.942]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.942]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.942]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.942]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Check Password GCV%-C.
- [03/20/12 07:49:46.943]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.943]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to Identity Manager data store when adding a object'.
- [03/20/12 07:49:46.943]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:49:46.943]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.943]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the Identity Manager data store'.
- [03/20/12 07:49:46.944]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:49:46.944]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.944]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.944]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.944]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish Distribution Password%-C.
- [03/20/12 07:49:46.945]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.945]:Active Directory PT: Evaluating selection criteria for rule 'Add nspmDistributionAttribute attribute to add operation'.
- [03/20/12 07:49:46.945]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:49:46.945]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.945]:Active Directory PT: Evaluating selection criteria for rule 'Change modify-password operations to a modify'.
- [03/20/12 07:49:46.945]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:49:46.945]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.946]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.946]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.946]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish NDS Password%-C.
- [03/20/12 07:49:46.946]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.946]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to NDS password'.
- [03/20/12 07:49:46.947]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:49:46.947]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.947]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the NDS password'.
- [03/20/12 07:49:46.947]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:49:46.947]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.947]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.947]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.948]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Add Password Payload%-C.
- [03/20/12 07:49:46.948]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.948]:Active Directory PT: Evaluating selection criteria for rule 'Add operation-data element to password operations'.
- [03/20/12 07:49:46.948]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:46.948]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:46.949]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:49:46.949]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:46.949]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.949]:Active Directory PT: Evaluating selection criteria for rule 'Add payload data to password operations'.
- [03/20/12 07:49:46.949]:Active Directory PT: (if-operation equal "addPayloadToPassword") = FALSE.
- [03/20/12 07:49:46.949]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:46.949]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:49:46.950]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:49:46.950]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.950]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.950]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.950]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccountsOnAdds-pub-ctp-V1%-C.
- [03/20/12 07:49:46.950]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.951]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard policy if disabled'.
- [03/20/12 07:49:46.951]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:46.951]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.951]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add operation add Dirxml-Accounts'.
- [03/20/12 07:49:46.951]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:46.951]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.952]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.952]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:49:46.952]:Active Directory PT:Filtering out notification-only attributes.
- [03/20/12 07:49:46.952]:Active Directory PT:Pumping XDS to eDirectory.
- [03/20/12 07:49:46.952]:Active Directory PT:Performing operation status for .
- [03/20/12 07:49:46.953]:Active Directory PT:
- DirXML Log Event -------------------
- Driver: \EDIR2ADLAB\fdny\AD-TEST\Active Directory
- Channel: Publisher
- Status: Success
- [03/20/12 07:49:46.953]:Active Directory PT:Fixing up association references.
- [03/20/12 07:49:46.953]:Active Directory PT:Applying schema mapping policies to output.
- [03/20/12 07:49:46.953]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:49:46.953]:Active Directory PT:Applying output transformation policies.
- [03/20/12 07:49:46.953]:Active Directory PT:Applying policy: %+C%14Cotp%-C.
- [03/20/12 07:49:46.954]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.954]:Active Directory PT: Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:49:46.954]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.954]:Active Directory PT: Applying rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:49:46.954]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
- [03/20/12 07:49:46.954]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:49:46.955]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.955]:Active Directory PT: Applying rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:49:46.955]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
- [03/20/12 07:49:46.955]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
- [03/20/12 07:49:46.955]:Active Directory PT: (if-op-attr 'accountExpires' changing) = FALSE.
- [03/20/12 07:49:46.956]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.956]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:49:46.956]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.956]:Active Directory PT: Applying rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:49:46.956]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
- [03/20/12 07:49:46.956]:Active Directory PT: Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
- [03/20/12 07:49:46.957]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:49:46.957]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.957]:Active Directory PT: Evaluating selection criteria for rule 'update Active Directory logon name'.
- [03/20/12 07:49:46.957]:Active Directory PT: (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
- [03/20/12 07:49:46.957]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.957]:Active Directory PT: Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:49:46.958]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = TRUE.
- [03/20/12 07:49:46.958]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.958]:Active Directory PT: Applying rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:49:46.958]:Active Directory PT: Action: do-strip-op-attr("homeMDB").
- [03/20/12 07:49:46.958]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.958]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.959]:Active Directory PT:Applying policy: %+C%14CPassword(Sub)-Pub Email Notifications%-C.
- [03/20/12 07:49:46.959]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.959]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
- [03/20/12 07:49:46.959]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:49:46.960]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:49:46.960]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-publish-status") = FALSE.
- [03/20/12 07:49:46.960]:Active Directory PT: Rule rejected.
- [03/20/12 07:49:46.960]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.960]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.961]:Active Directory PT:Applying policy: %+C%14Clib-CredProv-ConvertPayload-otp-V1%-C.
- [03/20/12 07:49:46.961]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.961]:Active Directory PT: Evaluating selection criteria for rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:49:46.961]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.961]:Active Directory PT: Applying rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:49:46.961]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.961]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.962]:Active Directory PT: (if-global-variable 'credprov.enable' not-equal "true") = TRUE.
- [03/20/12 07:49:46.962]:Active Directory PT: Performing if actions.
- [03/20/12 07:49:46.962]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:46.962]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.962]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.962]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Subscribe-otp-V1%-C.
- [03/20/12 07:49:46.963]:Active Directory PT: Applying to status #1.
- [03/20/12 07:49:46.963]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:46.963]:Active Directory PT: Rule selected.
- [03/20/12 07:49:46.963]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:49:46.963]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.963]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.964]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:49:46.964]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.964]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
- [03/20/12 07:49:46.964]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
- [03/20/12 07:49:46.964]:Active Directory PT: token-global-variable("drv.acctTrk.objectClass")
- [03/20/12 07:49:46.964]:Active Directory PT: Token Value: {"user"}.
- [03/20/12 07:49:46.965]:Active Directory PT: Arg Value: {"user"}.
- [03/20/12 07:49:46.965]:Active Directory PT: Performing actions for local-variable(current-node) = "user".
- [03/20/12 07:49:46.965]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.965]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.965]:Active Directory PT: (if-class-name equal "$current-node$") = FALSE.
- [03/20/12 07:49:46.965]:Active Directory PT: Performing else actions.
- [03/20/12 07:49:46.965]:Active Directory PT: Action: do-if().
- [03/20/12 07:49:46.966]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:49:46.966]:Active Directory PT: (if-local-variable 'pass' not-available) = TRUE.
- [03/20/12 07:49:46.966]:Active Directory PT: Performing if actions.
- [03/20/12 07:49:46.966]:Active Directory PT: Action: do-break().
- [03/20/12 07:49:46.966]:Active Directory PT:Policy returned:
- [03/20/12 07:49:46.966]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.967]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.967]:Active Directory PT:Remote Interface Driver: Sending...
- [03/20/12 07:49:46.967]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:49:46.968]:Active Directory PT:Remote Interface Driver: Document sent.
- [03/20/12 07:50:01.371]:Active Directory ST:Submitting identification query to subscriber shim:
- [03/20/12 07:50:01.372]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query event-id="query-driver-ident" scope="entry">
- <search-class class-name="__driver_identification_class__"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:01.372]:Active Directory ST:Remote Interface Driver: Sending...
- [03/20/12 07:50:01.372]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query event-id="query-driver-ident" scope="entry">
- <search-class class-name="__driver_identification_class__"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:01.373]:Active Directory ST:Remote Interface Driver: Document sent.
- [03/20/12 07:50:01.394]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:50:01.394]:Active Directory :
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <instance class-name="__driver_identification_class__">
- <attr attr-name="driver-id">
- <value type="string">AD</value>
- </attr>
- <attr attr-name="driver-version">
- <value type="string">3.5.5</value>
- </attr>
- <attr attr-name="min-activation-version">
- <value type="string">5</value>
- </attr>
- <attr attr-name="query-ex-supported">
- <value type="state">true</value>
- </attr>
- </instance>
- <status event-id="query-driver-ident" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:01.395]:Active Directory :Remote Interface Driver: Received document for subscriber channel
- [03/20/12 07:50:01.395]:Active Directory ST:SubscriptionShim.execute() returned:
- [03/20/12 07:50:01.395]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <instance class-name="__driver_identification_class__">
- <attr attr-name="driver-id">
- <value type="string">AD</value>
- </attr>
- <attr attr-name="driver-version">
- <value type="string">3.5.5</value>
- </attr>
- <attr attr-name="min-activation-version">
- <value type="string">5</value>
- </attr>
- <attr attr-name="query-ex-supported">
- <value type="state">true</value>
- </attr>
- </instance>
- <status event-id="query-driver-ident" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:01.398]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:50:27.740]:Active Directory ST:Start transaction.
- [03/20/12 07:50:27.740]:Active Directory ST:Processing events for transaction.
- [03/20/12 07:50:27.741]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <sync cached-time="20120320115027.684Z" class-name="User" event-id="edir2adlab-idm361#20120320115027#1#1" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938" timestamp="0#0">
- <association state="manual"></association>
- </sync>
- </input>
- </nds>
- [03/20/12 07:50:27.741]:Active Directory ST:No event transformation policies.
- [03/20/12 07:50:27.741]:Active Directory ST:Subscriber processing sync for \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap.
- [03/20/12 07:50:27.742]:Active Directory ST:Reading relevant attributes from \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap.
- [03/20/12 07:50:27.742]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="User" dest-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" dest-entry-id="32938" scope="entry">
- <read-attr attr-name="Description"/>
- <read-attr attr-name="DirXML-EntitlementRef"/>
- <read-attr attr-name="Facsimile Telephone Number"/>
- <read-attr attr-name="Full Name"/>
- <read-attr attr-name="Given Name"/>
- <read-attr attr-name="Initials"/>
- <read-attr attr-name="Internet EMail Address"/>
- <read-attr attr-name="L"/>
- <read-attr attr-name="Login Allowed Time Map"/>
- <read-attr attr-name="Login Disabled"/>
- <read-attr attr-name="Login Expiration Time"/>
- <read-attr attr-name="nspmDistributionPassword"/>
- <read-attr attr-name="Physical Delivery Office Name"/>
- <read-attr attr-name="Postal Code"/>
- <read-attr attr-name="Postal Office Box"/>
- <read-attr attr-name="S"/>
- <read-attr attr-name="SA"/>
- <read-attr attr-name="Surname"/>
- <read-attr attr-name="Telephone Number"/>
- <read-attr attr-name="Title"/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.743]:Active Directory ST:Pumping XDS to eDirectory.
- [03/20/12 07:50:27.743]:Active Directory ST:Performing operation query for \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap.
- [03/20/12 07:50:27.744]:Active Directory ST:Driver object has insufficient rights to read \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap#Full Name.
- [03/20/12 07:50:27.745]:Active Directory ST:Read result:
- [03/20/12 07:50:27.745]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <instance class-name="User" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938">
- <association state="manual"></association>
- <attr attr-name="Given Name">
- <value timestamp="1332166853#1" type="string">Philip</value>
- </attr>
- <attr attr-name="Surname">
- <value timestamp="1332164807#3" type="string">Goldwasser</value>
- </attr>
- </instance>
- <status level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:27.746]:Active Directory ST:Synthetic add:
- [03/20/12 07:50:27.746]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <add class-name="User" event-id="edir2adlab-idm361#20120320115027#1#1" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938">
- <association state="manual"></association>
- <add-attr attr-name="Given Name">
- <value timestamp="1332166853#1" type="string">Philip</value>
- </add-attr>
- <add-attr attr-name="Surname">
- <value timestamp="1332164807#3" type="string">Goldwasser</value>
- </add-attr>
- </add>
- <status level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:27.747]:Active Directory ST:Applying object matching policies.
- [03/20/12 07:50:27.747]:Active Directory ST:Applying policy: %+C%14Csub-mp-Scoping%-C.
- [03/20/12 07:50:27.747]:Active Directory ST: Applying to add #1.
- [03/20/12 07:50:27.747]:Active Directory ST: Evaluating selection criteria for rule 'remember relative position in hierarchy'.
- [03/20/12 07:50:27.747]:Active Directory ST: (if-src-dn in-subtree "fdny") = TRUE.
- [03/20/12 07:50:27.747]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.747]:Active Directory ST: Applying rule 'remember relative position in hierarchy'.
- [03/20/12 07:50:27.747]:Active Directory ST: Action: do-set-op-property("unmatched-src-dn",token-unmatched-src-dn(convert="true")).
- [03/20/12 07:50:27.748]:Active Directory ST: arg-string(token-unmatched-src-dn(convert="true"))
- [03/20/12 07:50:27.748]:Active Directory ST: token-unmatched-src-dn(convert="true")
- [03/20/12 07:50:27.748]:Active Directory ST: Token Value: "CN=goldwap,OU=LAN,OU=BTDS,OU=Support".
- [03/20/12 07:50:27.748]:Active Directory ST: Arg Value: "CN=goldwap,OU=LAN,OU=BTDS,OU=Support".
- [03/20/12 07:50:27.748]:Active Directory ST: Action: do-set-op-property("attempt-to-match","true").
- [03/20/12 07:50:27.748]:Active Directory ST: arg-string("true")
- [03/20/12 07:50:27.748]:Active Directory ST: token-text("true")
- [03/20/12 07:50:27.748]:Active Directory ST: Arg Value: "true".
- [03/20/12 07:50:27.748]:Active Directory ST:Policy returned:
- [03/20/12 07:50:27.748]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <add class-name="User" event-id="edir2adlab-idm361#20120320115027#1#1" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938">
- <add-attr attr-name="Given Name">
- <value timestamp="1332166853#1" type="string">Philip</value>
- </add-attr>
- <add-attr attr-name="Surname">
- <value timestamp="1332164807#3" type="string">Goldwasser</value>
- </add-attr>
- <operation-data attempt-to-match="true" unmatched-src-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support"/>
- </add>
- </input>
- </nds>
- [03/20/12 07:50:27.749]:Active Directory ST:Applying policy: %+C%14Csub-mp-EntitlementsImpl%-C.
- [03/20/12 07:50:27.749]:Active Directory ST: Applying to add #1.
- [03/20/12 07:50:27.749]:Active Directory ST: Evaluating selection criteria for rule 'UserAccount entitlement: do not match existing accounts'.
- [03/20/12 07:50:27.750]:Active Directory ST: (if-class-name equal "User") = TRUE.
- [03/20/12 07:50:27.750]:Active Directory ST: (if-global-variable 'drv.entitlement.UserAccount' equal "true") = FALSE.
- [03/20/12 07:50:27.750]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.750]:Active Directory ST:Policy returned:
- [03/20/12 07:50:27.750]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <add class-name="User" event-id="edir2adlab-idm361#20120320115027#1#1" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938">
- <add-attr attr-name="Given Name">
- <value timestamp="1332166853#1" type="string">Philip</value>
- </add-attr>
- <add-attr attr-name="Surname">
- <value timestamp="1332164807#3" type="string">Goldwasser</value>
- </add-attr>
- <operation-data attempt-to-match="true" unmatched-src-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support"/>
- </add>
- </input>
- </nds>
- [03/20/12 07:50:27.751]:Active Directory ST:Applying policy: %+C%14Csub-mp%-C.
- [03/20/12 07:50:27.751]:Active Directory ST: Applying to add #1.
- [03/20/12 07:50:27.751]:Active Directory ST: Evaluating selection criteria for rule 'veto out-of-scope events'.
- [03/20/12 07:50:27.751]:Active Directory ST: (if-op-property 'attempt-to-match' not-available) = FALSE.
- [03/20/12 07:50:27.751]:Active Directory ST: (if-op-property 'attempt-to-match' equal "false") = FALSE.
- [03/20/12 07:50:27.751]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.751]:Active Directory ST: Evaluating selection criteria for rule 'generate full name if not in Identity Vault'.
- [03/20/12 07:50:27.751]:Active Directory ST: (if-class-name equal "User") = TRUE.
- [03/20/12 07:50:27.752]:Active Directory ST: (if-global-variable 'FullNameMap' equal "true") = TRUE.
- [03/20/12 07:50:27.752]:Active Directory ST: Query from policy
- [03/20/12 07:50:27.752]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="User" dest-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" dest-entry-id="32938" scope="entry">
- <read-attr attr-name="Full Name"/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.752]:Active Directory ST: Pumping XDS to eDirectory.
- [03/20/12 07:50:27.752]:Active Directory ST: Performing operation query for \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap.
- [03/20/12 07:50:27.753]:Active Directory ST: Driver object has insufficient rights to read \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap#Full Name.
- [03/20/12 07:50:27.753]:Active Directory ST: Query from policy result
- [03/20/12 07:50:27.753]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <instance class-name="User" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938">
- <association state="manual"></association>
- </instance>
- <status level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:27.754]:Active Directory ST: (if-attr 'Full Name' not-available) = TRUE.
- [03/20/12 07:50:27.754]:Active Directory ST: (if-attr 'Given Name' available) = TRUE.
- [03/20/12 07:50:27.754]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.754]:Active Directory ST: Applying rule 'generate full name if not in Identity Vault'.
- [03/20/12 07:50:27.755]:Active Directory ST: Action: do-set-local-variable("gen-full-name",token-attr("Given Name")+" "+token-attr("Surname")).
- [03/20/12 07:50:27.755]:Active Directory ST: arg-string(token-attr("Given Name")+" "+token-attr("Surname"))
- [03/20/12 07:50:27.755]:Active Directory ST: token-attr("Given Name")
- [03/20/12 07:50:27.755]:Active Directory ST: Token Value: "Philip".
- [03/20/12 07:50:27.755]:Active Directory ST: token-text(" ")
- [03/20/12 07:50:27.755]:Active Directory ST: token-attr("Surname")
- [03/20/12 07:50:27.755]:Active Directory ST: Token Value: "Goldwasser".
- [03/20/12 07:50:27.755]:Active Directory ST: Arg Value: "Philip Goldwasser".
- [03/20/12 07:50:27.755]:Active Directory ST: Action: do-set-src-attr-value("Full Name",token-xpath("normalize-space($gen-full-name)")).
- [03/20/12 07:50:27.756]:Active Directory ST: arg-string(token-xpath("normalize-space($gen-full-name)"))
- [03/20/12 07:50:27.756]:Active Directory ST: token-xpath("normalize-space($gen-full-name)")
- [03/20/12 07:50:27.756]:Active Directory ST: Token Value: "Philip Goldwasser".
- [03/20/12 07:50:27.756]:Active Directory ST: Arg Value: "Philip Goldwasser".
- [03/20/12 07:50:27.756]:Active Directory ST: Action: do-set-dest-attr-value("Full Name",token-xpath("normalize-space($gen-full-name)")).
- [03/20/12 07:50:27.756]:Active Directory ST: arg-string(token-xpath("normalize-space($gen-full-name)"))
- [03/20/12 07:50:27.756]:Active Directory ST: token-xpath("normalize-space($gen-full-name)")
- [03/20/12 07:50:27.756]:Active Directory ST: Token Value: "Philip Goldwasser".
- [03/20/12 07:50:27.757]:Active Directory ST: Arg Value: "Philip Goldwasser".
- [03/20/12 07:50:27.757]:Active Directory ST: Evaluating selection criteria for rule 'match users based on NT logon name'.
- [03/20/12 07:50:27.757]:Active Directory ST: (if-class-name equal "User") = TRUE.
- [03/20/12 07:50:27.757]:Active Directory ST: (if-global-variable 'LogonNameMap' equal "true") = TRUE.
- [03/20/12 07:50:27.757]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.757]:Active Directory ST: Applying rule 'match users based on NT logon name'.
- [03/20/12 07:50:27.757]:Active Directory ST: Action: do-find-matching-object(scope="subtree",arg-dn(token-global-variable("drv.user.container")),arg-match-attr("DirXML-ADAliasName",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))).
- [03/20/12 07:50:27.757]:Active Directory ST: arg-dn(token-global-variable("drv.user.container"))
- [03/20/12 07:50:27.758]:Active Directory ST: token-global-variable("drv.user.container")
- [03/20/12 07:50:27.758]:Active Directory ST: Token Value: "OU=FDNY,dc=edir2adlab,dc=local".
- [03/20/12 07:50:27.758]:Active Directory ST: Arg Value: "OU=FDNY,dc=edir2adlab,dc=local".
- [03/20/12 07:50:27.758]:Active Directory ST: arg-match-attr("DirXML-ADAliasName",token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
- [03/20/12 07:50:27.758]:Active Directory ST: arg-string(token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name()))
- [03/20/12 07:50:27.758]:Active Directory ST: token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
- [03/20/12 07:50:27.759]:Active Directory ST: token-replace-all("^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\x410-\x44f","",token-src-name())
- [03/20/12 07:50:27.759]:Active Directory ST: token-src-name()
- [03/20/12 07:50:27.759]:Active Directory ST: Token Value: "goldwap".
- [03/20/12 07:50:27.759]:Active Directory ST: Arg Value: "goldwap".
- [03/20/12 07:50:27.759]:Active Directory ST: Token Value: "goldwap".
- [03/20/12 07:50:27.759]:Active Directory ST: Arg Value: "goldwap".
- [03/20/12 07:50:27.759]:Active Directory ST: Query from policy
- [03/20/12 07:50:27.760]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="User" dest-dn="OU=FDNY,dc=edir2adlab,dc=local" scope="subtree">
- <search-class class-name="User"/>
- <search-attr attr-name="DirXML-ADAliasName">
- <value type="string">goldwap</value>
- </search-attr>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.760]:Active Directory ST: Fixing up association references.
- [03/20/12 07:50:27.760]:Active Directory ST: Applying schema mapping policies to output.
- [03/20/12 07:50:27.760]:Active Directory ST: Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:27.761]:Active Directory ST: Mapping attr-name 'DirXML-ADAliasName' to 'userPrincipalName'.
- [03/20/12 07:50:27.761]:Active Directory ST: Mapping class-name 'User' to 'user'.
- [03/20/12 07:50:27.761]:Active Directory ST: Mapping class-name 'User' to 'user'.
- [03/20/12 07:50:27.761]:Active Directory ST: Applying output transformation policies.
- [03/20/12 07:50:27.761]:Active Directory ST: Applying policy: %+C%14Cotp%-C.
- [03/20/12 07:50:27.761]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.761]:Active Directory ST: Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:27.761]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.762]:Active Directory ST: Applying rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:27.762]:Active Directory ST: Action: do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
- [03/20/12 07:50:27.762]:Active Directory ST: Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:27.762]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.762]:Active Directory ST: Applying rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:27.762]:Active Directory ST: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
- [03/20/12 07:50:27.762]:Active Directory ST: Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
- [03/20/12 07:50:27.763]:Active Directory ST: (if-op-attr 'accountExpires' changing) = FALSE.
- [03/20/12 07:50:27.763]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.763]:Active Directory ST: Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:27.763]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.763]:Active Directory ST: Applying rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:27.763]:Active Directory ST: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
- [03/20/12 07:50:27.763]:Active Directory ST: Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
- [03/20/12 07:50:27.764]:Active Directory ST: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:27.764]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.764]:Active Directory ST: Evaluating selection criteria for rule 'update Active Directory logon name'.
- [03/20/12 07:50:27.764]:Active Directory ST: (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
- [03/20/12 07:50:27.764]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.764]:Active Directory ST: Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:27.764]:Active Directory ST: (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = TRUE.
- [03/20/12 07:50:27.764]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.764]:Active Directory ST: Applying rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:27.765]:Active Directory ST: Action: do-strip-op-attr("homeMDB").
- [03/20/12 07:50:27.765]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.765]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="subtree">
- <search-class class-name="user"/>
- <search-attr attr-name="userPrincipalName">
- <value type="string">goldwap</value>
- </search-attr>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.765]:Active Directory ST: Applying policy: %+C%14CPassword(Sub)-Pub Email Notifications%-C.
- [03/20/12 07:50:27.765]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.766]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
- [03/20/12 07:50:27.766]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.766]:Active Directory ST: (if-operation equal "status") = FALSE.
- [03/20/12 07:50:27.766]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.766]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.766]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="subtree">
- <search-class class-name="user"/>
- <search-attr attr-name="userPrincipalName">
- <value type="string">goldwap</value>
- </search-attr>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.767]:Active Directory ST: Applying policy: %+C%14Clib-CredProv-ConvertPayload-otp-V1%-C.
- [03/20/12 07:50:27.767]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.767]:Active Directory ST: Evaluating selection criteria for rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:27.767]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.767]:Active Directory ST: Applying rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:27.767]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.768]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.768]:Active Directory ST: (if-global-variable 'credprov.enable' not-equal "true") = TRUE.
- [03/20/12 07:50:27.768]:Active Directory ST: Performing if actions.
- [03/20/12 07:50:27.768]:Active Directory ST: Action: do-break().
- [03/20/12 07:50:27.768]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.768]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="subtree">
- <search-class class-name="user"/>
- <search-attr attr-name="userPrincipalName">
- <value type="string">goldwap</value>
- </search-attr>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.769]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-Subscribe-otp-V1%-C.
- [03/20/12 07:50:27.769]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.769]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.769]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.769]:Active Directory ST: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.769]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.769]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.769]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.769]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.770]:Active Directory ST: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
- [03/20/12 07:50:27.770]:Active Directory ST: arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
- [03/20/12 07:50:27.770]:Active Directory ST: token-global-variable("drv.acctTrk.objectClass")
- [03/20/12 07:50:27.770]:Active Directory ST: Token Value: {"user"}.
- [03/20/12 07:50:27.770]:Active Directory ST: Arg Value: {"user"}.
- [03/20/12 07:50:27.770]:Active Directory ST: Performing actions for local-variable(current-node) = "user".
- [03/20/12 07:50:27.770]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.770]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.771]:Active Directory ST: Expanded variable reference '$current-node$' to 'user'.
- [03/20/12 07:50:27.771]:Active Directory ST: (if-class-name equal "$current-node$") = TRUE.
- [03/20/12 07:50:27.771]:Active Directory ST: Performing if actions.
- [03/20/12 07:50:27.771]:Active Directory ST: Action: do-set-local-variable("pass",scope="policy","true").
- [03/20/12 07:50:27.771]:Active Directory ST: arg-string("true")
- [03/20/12 07:50:27.771]:Active Directory ST: token-text("true")
- [03/20/12 07:50:27.771]:Active Directory ST: Arg Value: "true".
- [03/20/12 07:50:27.771]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.771]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.772]:Active Directory ST: (if-local-variable 'pass' not-available) = FALSE.
- [03/20/12 07:50:27.772]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.772]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - include desired attribute values in operation-data'.
- [03/20/12 07:50:27.772]:Active Directory ST: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:50:27.772]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.772]:Active Directory ST: Evaluating selection criteria for rule 'Account-Tracking-StripAccountTrackingAccountStatus Attribute'.
- [03/20/12 07:50:27.772]:Active Directory ST: (if-op-attr 'AccountTrackingAccountStatus' available) = FALSE.
- [03/20/12 07:50:27.772]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.774]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.774]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="subtree">
- <search-class class-name="user"/>
- <search-attr attr-name="userPrincipalName">
- <value type="string">goldwap</value>
- </search-attr>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.774]:Active Directory ST: Submitting document to subscriber shim:
- [03/20/12 07:50:27.774]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="subtree">
- <search-class class-name="user"/>
- <search-attr attr-name="userPrincipalName">
- <value type="string">goldwap</value>
- </search-attr>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.775]:Active Directory ST: Remote Interface Driver: Sending...
- [03/20/12 07:50:27.775]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="subtree">
- <search-class class-name="user"/>
- <search-attr attr-name="userPrincipalName">
- <value type="string">goldwap</value>
- </search-attr>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.776]:Active Directory ST: Remote Interface Driver: Document sent.
- [03/20/12 07:50:27.817]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:50:27.818]:Active Directory :
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.818]:Active Directory :Remote Interface Driver: Received document for subscriber channel
- [03/20/12 07:50:27.818]:Active Directory ST: SubscriptionShim.execute() returned:
- [03/20/12 07:50:27.818]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.819]:Active Directory ST: Applying input transformation policies.
- [03/20/12 07:50:27.819]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-Publish-itp-V1%-C.
- [03/20/12 07:50:27.819]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.819]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.819]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.819]:Active Directory ST: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.819]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.820]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.820]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.820]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.820]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.820]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.820]:Active Directory ST: (if-class-name available) = FALSE.
- [03/20/12 07:50:27.820]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.820]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - on add-association sync the operation-properties to status operations'.
- [03/20/12 07:50:27.820]:Active Directory ST: (if-operation equal "add-association") = FALSE.
- [03/20/12 07:50:27.821]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.821]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - Query for destination DN using Association'.
- [03/20/12 07:50:27.821]:Active Directory ST: (if-operation match "modify|delete|move|rename") = FALSE.
- [03/20/12 07:50:27.821]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.821]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:27.821]:Active Directory ST: (if-operation match "add|modify|delete|rename|move|status") = TRUE.
- [03/20/12 07:50:27.821]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.821]:Active Directory ST: Applying rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:27.822]:Active Directory ST: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.identifiers"))).
- [03/20/12 07:50:27.822]:Active Directory ST: arg-node-set(token-global-variable("drv.acctTrk.identifiers"))
- [03/20/12 07:50:27.822]:Active Directory ST: token-global-variable("drv.acctTrk.identifiers")
- [03/20/12 07:50:27.822]:Active Directory ST: Token Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:27.822]:Active Directory ST: Arg Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:27.822]:Active Directory ST: Performing actions for local-variable(current-node) = "sAMAccountName".
- [03/20/12 07:50:27.822]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.822]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.823]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.823]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.823]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.823]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.823]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.823]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.823]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.823]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.824]:Active Directory ST: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:27.824]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.824]:Active Directory ST: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:27.824]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.824]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.824]:Active Directory ST: Performing actions for local-variable(current-node) = "userPrincipalName".
- [03/20/12 07:50:27.824]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.824]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.825]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.825]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.825]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.825]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.825]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.825]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.825]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.825]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.825]:Active Directory ST: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:27.826]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.826]:Active Directory ST: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:27.826]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.826]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.826]:Active Directory ST: Performing actions for local-variable(current-node) = "LDAPDN".
- [03/20/12 07:50:27.826]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.826]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.826]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = TRUE.
- [03/20/12 07:50:27.827]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.827]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.827]:Active Directory ST: (if-src-dn available) = FALSE.
- [03/20/12 07:50:27.827]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.827]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.827]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.827]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.827]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.827]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.828]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.828]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.828]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.828]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.828]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.828]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.828]:Active Directory ST: Performing actions for local-variable(current-node) = "association".
- [03/20/12 07:50:27.828]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.828]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.829]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.829]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.829]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.829]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.829]:Active Directory ST: (if-local-variable 'current-node' equal "association") = TRUE.
- [03/20/12 07:50:27.829]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.829]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.829]:Active Directory ST: (if-association available) = FALSE.
- [03/20/12 07:50:27.829]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.830]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.830]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.830]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.830]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.830]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.830]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.830]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.830]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - Initialize status properties on published events'.
- [03/20/12 07:50:27.831]:Active Directory ST: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:50:27.831]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.831]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.831]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.831]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-WriteAccounts-itp-V1%-C.
- [03/20/12 07:50:27.832]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.832]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled'.
- [03/20/12 07:50:27.832]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.832]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.832]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - query DirXML-Accounts Attribute'.
- [03/20/12 07:50:27.832]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.832]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.832]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - remove Dirxml-Account values on delete operation'.
- [03/20/12 07:50:27.832]:Active Directory ST: (if-operation match "delete|remove-association") = FALSE.
- [03/20/12 07:50:27.833]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.833]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.833]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.833]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - update DirXMLAccounts attribute'.
- [03/20/12 07:50:27.833]:Active Directory ST: (if-op-property 'AccountTracking-Operation' not-available) = TRUE.
- [03/20/12 07:50:27.833]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.833]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.833]:Active Directory ST: (if-xpath true "./@level='success'") = TRUE.
- [03/20/12 07:50:27.834]:Active Directory ST: (if-op-property 'AccountTracking-Operation' available) = FALSE.
- [03/20/12 07:50:27.834]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.834]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.834]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.834]:Active Directory ST: Applying policy: %+C%14Citp%-C.
- [03/20/12 07:50:27.834]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.834]:Active Directory ST: Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:27.835]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.835]:Active Directory ST: Applying rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:27.835]:Active Directory ST: Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
- [03/20/12 07:50:27.835]:Active Directory ST: Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:27.835]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.835]:Active Directory ST: Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:27.835]:Active Directory ST: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
- [03/20/12 07:50:27.835]:Active Directory ST: Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.836]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.836]:Active Directory ST: Applying rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.836]:Active Directory ST: Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:27.836]:Active Directory ST: Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.836]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.836]:Active Directory ST: Applying rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.836]:Active Directory ST: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:27.836]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.837]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.837]:Active Directory ST: Applying policy: %+C%14Citp-EntitlementsImpl%-C.
- [03/20/12 07:50:27.837]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.837]:Active Directory ST: Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
- [03/20/12 07:50:27.837]:Active Directory ST: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:50:27.837]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.837]:Active Directory ST: Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
- [03/20/12 07:50:27.838]:Active Directory ST: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:50:27.838]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.838]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.838]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.838]:Active Directory ST: Applying policy: %+C%14CPassword(Pub)-Sub Email Notifications%-C.
- [03/20/12 07:50:27.838]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.838]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
- [03/20/12 07:50:27.839]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.839]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.839]:Active Directory ST: (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
- [03/20/12 07:50:27.839]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.839]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Manager data store password'.
- [03/20/12 07:50:27.840]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.840]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.840]:Active Directory ST: (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
- [03/20/12 07:50:27.840]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.840]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.840]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.841]:Active Directory ST: Applying policy: %+C%14Clib-Audit-SendEntitlementsEvents-itp-V1%-C.
- [03/20/12 07:50:27.841]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.841]:Active Directory ST: Evaluating selection criteria for rule '00031200 - Account Create By Entitlement Grant'.
- [03/20/12 07:50:27.841]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.841]:Active Directory ST: (if-op-property 'accountAction' equal "accountCreateByEntitlementGrant") = FALSE.
- [03/20/12 07:50:27.841]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.841]:Active Directory ST: Evaluating selection criteria for rule '00031201 - Account Delete By Entitlement Revoke'.
- [03/20/12 07:50:27.841]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.841]:Active Directory ST: (if-xpath true "./operation-data/entitlement-impl/@state = '0'") = FALSE.
- [03/20/12 07:50:27.842]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.842]:Active Directory ST: (if-op-property 'accountAction' equal "accountDeleteByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:27.842]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.842]:Active Directory ST: Evaluating selection criteria for rule '00031202 - Account Disable By Entitlement Revoke'.
- [03/20/12 07:50:27.842]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.842]:Active Directory ST: (if-op-property 'accountAction' equal "accountDisableByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:27.842]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.842]:Active Directory ST: Evaluating selection criteria for rule '00031203 - Account Enable By Entitlement Grant'.
- [03/20/12 07:50:27.843]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.843]:Active Directory ST: (if-op-property 'accountAction' equal "accountEnableByEntitlementGrant") = FALSE.
- [03/20/12 07:50:27.843]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.843]:Active Directory ST: Evaluating selection criteria for rule 'Generate Audit Event'.
- [03/20/12 07:50:27.843]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.843]:Active Directory ST: (if-local-variable 'auditEventID' available) = FALSE.
- [03/20/12 07:50:27.843]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.843]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.844]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.844]:Active Directory ST: Applying schema mapping policies to input.
- [03/20/12 07:50:27.844]:Active Directory ST: Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:27.844]:Active Directory ST: Resolving association references.
- [03/20/12 07:50:27.845]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:50:27.845]:Active Directory ST: Query from policy result
- [03/20/12 07:50:27.845]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.845]:Active Directory ST: No matches found.
- [03/20/12 07:50:27.845]:Active Directory ST: Evaluating selection criteria for rule 'match users based on full name'.
- [03/20/12 07:50:27.845]:Active Directory ST: (if-class-name equal "User") = TRUE.
- [03/20/12 07:50:27.846]:Active Directory ST: (if-global-variable 'FullNameMap' equal "true") = TRUE.
- [03/20/12 07:50:27.846]:Active Directory ST: (if-op-attr 'Full Name' available) = TRUE.
- [03/20/12 07:50:27.846]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.846]:Active Directory ST: Applying rule 'match users based on full name'.
- [03/20/12 07:50:27.846]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.846]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.846]:Active Directory ST: (if-global-variable 'drv.subPlacementType' equal "flat") = FALSE.
- [03/20/12 07:50:27.846]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.846]:Active Directory ST: Action: do-find-matching-object(scope="entry",arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full Name"))+","+token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))+token-global-variable("drv.user.container"))).
- [03/20/12 07:50:27.847]:Active Directory ST: arg-dn("CN="+token-escape-for-dest-dn(token-attr("Full Name"))+","+token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))+token-global-variable("drv.user.container"))
- [03/20/12 07:50:27.847]:Active Directory ST: token-text("CN=")
- [03/20/12 07:50:27.847]:Active Directory ST: token-escape-for-dest-dn(token-attr("Full Name"))
- [03/20/12 07:50:27.847]:Active Directory ST: token-escape-for-dest-dn(token-attr("Full Name"))
- [03/20/12 07:50:27.847]:Active Directory ST: token-attr("Full Name")
- [03/20/12 07:50:27.847]:Active Directory ST: Token Value: "Philip Goldwasser".
- [03/20/12 07:50:27.847]:Active Directory ST: Arg Value: "Philip Goldwasser".
- [03/20/12 07:50:27.848]:Active Directory ST: Token Value: "Philip Goldwasser".
- [03/20/12 07:50:27.848]:Active Directory ST: token-text(",")
- [03/20/12 07:50:27.848]:Active Directory ST: token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))
- [03/20/12 07:50:27.848]:Active Directory ST: token-replace-first("(.+)","$1,",token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn")))
- [03/20/12 07:50:27.848]:Active Directory ST: token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn"))
- [03/20/12 07:50:27.848]:Active Directory ST: token-parse-dn(length="-2",src-dn-format="dest-dn",token-op-property("unmatched-src-dn"))
- [03/20/12 07:50:27.848]:Active Directory ST: token-op-property("unmatched-src-dn")
- [03/20/12 07:50:27.848]:Active Directory ST: Token Value: "CN=goldwap,OU=LAN,OU=BTDS,OU=Support".
- [03/20/12 07:50:27.849]:Active Directory ST: Arg Value: "CN=goldwap,OU=LAN,OU=BTDS,OU=Support".
- [03/20/12 07:50:27.849]:Active Directory ST: Token Value: "OU=LAN,OU=BTDS,OU=Support".
- [03/20/12 07:50:27.849]:Active Directory ST: Arg Value: "OU=LAN,OU=BTDS,OU=Support".
- [03/20/12 07:50:27.849]:Active Directory ST: Token Value: "OU=LAN,OU=BTDS,OU=Support,".
- [03/20/12 07:50:27.849]:Active Directory ST: token-global-variable("drv.user.container")
- [03/20/12 07:50:27.849]:Active Directory ST: Token Value: "OU=FDNY,dc=edir2adlab,dc=local".
- [03/20/12 07:50:27.849]:Active Directory ST: Arg Value: "CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local".
- [03/20/12 07:50:27.849]:Active Directory ST: Query from policy
- [03/20/12 07:50:27.850]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="User" dest-dn="CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" scope="entry">
- <search-class class-name="User"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.850]:Active Directory ST: Fixing up association references.
- [03/20/12 07:50:27.850]:Active Directory ST: Applying schema mapping policies to output.
- [03/20/12 07:50:27.850]:Active Directory ST: Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:27.850]:Active Directory ST: Mapping class-name 'User' to 'user'.
- [03/20/12 07:50:27.850]:Active Directory ST: Mapping class-name 'User' to 'user'.
- [03/20/12 07:50:27.851]:Active Directory ST: Applying output transformation policies.
- [03/20/12 07:50:27.851]:Active Directory ST: Applying policy: %+C%14Cotp%-C.
- [03/20/12 07:50:27.851]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.851]:Active Directory ST: Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:27.851]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.851]:Active Directory ST: Applying rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:27.851]:Active Directory ST: Action: do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
- [03/20/12 07:50:27.852]:Active Directory ST: Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:27.852]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.852]:Active Directory ST: Applying rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:27.852]:Active Directory ST: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
- [03/20/12 07:50:27.852]:Active Directory ST: Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
- [03/20/12 07:50:27.852]:Active Directory ST: (if-op-attr 'accountExpires' changing) = FALSE.
- [03/20/12 07:50:27.852]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.853]:Active Directory ST: Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:27.853]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.853]:Active Directory ST: Applying rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:27.853]:Active Directory ST: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
- [03/20/12 07:50:27.853]:Active Directory ST: Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
- [03/20/12 07:50:27.853]:Active Directory ST: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:27.853]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.853]:Active Directory ST: Evaluating selection criteria for rule 'update Active Directory logon name'.
- [03/20/12 07:50:27.854]:Active Directory ST: (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
- [03/20/12 07:50:27.854]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.854]:Active Directory ST: Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:27.854]:Active Directory ST: (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = TRUE.
- [03/20/12 07:50:27.854]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.854]:Active Directory ST: Applying rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:27.854]:Active Directory ST: Action: do-strip-op-attr("homeMDB").
- [03/20/12 07:50:27.854]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.855]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.855]:Active Directory ST: Applying policy: %+C%14CPassword(Sub)-Pub Email Notifications%-C.
- [03/20/12 07:50:27.855]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.855]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
- [03/20/12 07:50:27.855]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.856]:Active Directory ST: (if-operation equal "status") = FALSE.
- [03/20/12 07:50:27.856]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.856]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.856]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.856]:Active Directory ST: Applying policy: %+C%14Clib-CredProv-ConvertPayload-otp-V1%-C.
- [03/20/12 07:50:27.856]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.857]:Active Directory ST: Evaluating selection criteria for rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:27.857]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.857]:Active Directory ST: Applying rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:27.857]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.857]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.857]:Active Directory ST: (if-global-variable 'credprov.enable' not-equal "true") = TRUE.
- [03/20/12 07:50:27.857]:Active Directory ST: Performing if actions.
- [03/20/12 07:50:27.857]:Active Directory ST: Action: do-break().
- [03/20/12 07:50:27.857]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.858]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.858]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-Subscribe-otp-V1%-C.
- [03/20/12 07:50:27.858]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.858]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.858]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.858]:Active Directory ST: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.859]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.859]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.859]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.859]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.859]:Active Directory ST: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
- [03/20/12 07:50:27.859]:Active Directory ST: arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
- [03/20/12 07:50:27.859]:Active Directory ST: token-global-variable("drv.acctTrk.objectClass")
- [03/20/12 07:50:27.860]:Active Directory ST: Token Value: {"user"}.
- [03/20/12 07:50:27.860]:Active Directory ST: Arg Value: {"user"}.
- [03/20/12 07:50:27.860]:Active Directory ST: Performing actions for local-variable(current-node) = "user".
- [03/20/12 07:50:27.860]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.860]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.860]:Active Directory ST: Expanded variable reference '$current-node$' to 'user'.
- [03/20/12 07:50:27.860]:Active Directory ST: (if-class-name equal "$current-node$") = TRUE.
- [03/20/12 07:50:27.860]:Active Directory ST: Performing if actions.
- [03/20/12 07:50:27.860]:Active Directory ST: Action: do-set-local-variable("pass",scope="policy","true").
- [03/20/12 07:50:27.861]:Active Directory ST: arg-string("true")
- [03/20/12 07:50:27.861]:Active Directory ST: token-text("true")
- [03/20/12 07:50:27.861]:Active Directory ST: Arg Value: "true".
- [03/20/12 07:50:27.861]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.861]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.861]:Active Directory ST: (if-local-variable 'pass' not-available) = FALSE.
- [03/20/12 07:50:27.861]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.861]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - include desired attribute values in operation-data'.
- [03/20/12 07:50:27.861]:Active Directory ST: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:50:27.862]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.862]:Active Directory ST: Evaluating selection criteria for rule 'Account-Tracking-StripAccountTrackingAccountStatus Attribute'.
- [03/20/12 07:50:27.862]:Active Directory ST: (if-op-attr 'AccountTrackingAccountStatus' available) = FALSE.
- [03/20/12 07:50:27.862]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.862]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.862]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.863]:Active Directory ST: Submitting document to subscriber shim:
- [03/20/12 07:50:27.863]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.863]:Active Directory ST: Remote Interface Driver: Sending...
- [03/20/12 07:50:27.863]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=Philip Goldwasser,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.864]:Active Directory ST: Remote Interface Driver: Document sent.
- [03/20/12 07:50:27.894]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:50:27.894]:Active Directory :
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.895]:Active Directory :Remote Interface Driver: Received document for subscriber channel
- [03/20/12 07:50:27.895]:Active Directory ST: SubscriptionShim.execute() returned:
- [03/20/12 07:50:27.895]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.895]:Active Directory ST: Applying input transformation policies.
- [03/20/12 07:50:27.896]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-Publish-itp-V1%-C.
- [03/20/12 07:50:27.896]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.896]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.896]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.896]:Active Directory ST: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.896]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.896]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.896]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.896]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.897]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.897]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.897]:Active Directory ST: (if-class-name available) = FALSE.
- [03/20/12 07:50:27.897]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.897]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - on add-association sync the operation-properties to status operations'.
- [03/20/12 07:50:27.897]:Active Directory ST: (if-operation equal "add-association") = FALSE.
- [03/20/12 07:50:27.897]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.897]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - Query for destination DN using Association'.
- [03/20/12 07:50:27.898]:Active Directory ST: (if-operation match "modify|delete|move|rename") = FALSE.
- [03/20/12 07:50:27.898]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.898]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:27.898]:Active Directory ST: (if-operation match "add|modify|delete|rename|move|status") = TRUE.
- [03/20/12 07:50:27.898]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.898]:Active Directory ST: Applying rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:27.898]:Active Directory ST: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.identifiers"))).
- [03/20/12 07:50:27.898]:Active Directory ST: arg-node-set(token-global-variable("drv.acctTrk.identifiers"))
- [03/20/12 07:50:27.899]:Active Directory ST: token-global-variable("drv.acctTrk.identifiers")
- [03/20/12 07:50:27.899]:Active Directory ST: Token Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:27.899]:Active Directory ST: Arg Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:27.899]:Active Directory ST: Performing actions for local-variable(current-node) = "sAMAccountName".
- [03/20/12 07:50:27.899]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.900]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.900]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.900]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.900]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.900]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.900]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.900]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.900]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.900]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.901]:Active Directory ST: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:27.901]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.901]:Active Directory ST: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:27.901]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.901]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.901]:Active Directory ST: Performing actions for local-variable(current-node) = "userPrincipalName".
- [03/20/12 07:50:27.901]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.901]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.902]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.902]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.902]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.902]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.902]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.902]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.902]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.902]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.902]:Active Directory ST: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:27.903]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.903]:Active Directory ST: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:27.903]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.903]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.903]:Active Directory ST: Performing actions for local-variable(current-node) = "LDAPDN".
- [03/20/12 07:50:27.903]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.903]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.903]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = TRUE.
- [03/20/12 07:50:27.904]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.904]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.904]:Active Directory ST: (if-src-dn available) = FALSE.
- [03/20/12 07:50:27.904]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.904]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.904]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.904]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.904]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.905]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.905]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.905]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.905]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.905]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.905]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.905]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.905]:Active Directory ST: Performing actions for local-variable(current-node) = "association".
- [03/20/12 07:50:27.906]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.906]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.906]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.906]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.906]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.906]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.906]:Active Directory ST: (if-local-variable 'current-node' equal "association") = TRUE.
- [03/20/12 07:50:27.906]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.906]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.907]:Active Directory ST: (if-association available) = FALSE.
- [03/20/12 07:50:27.907]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.907]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.907]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.907]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.907]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.907]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.908]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.908]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.908]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - Initialize status properties on published events'.
- [03/20/12 07:50:27.908]:Active Directory ST: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:50:27.908]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.908]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.908]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.909]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-WriteAccounts-itp-V1%-C.
- [03/20/12 07:50:27.909]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.909]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled'.
- [03/20/12 07:50:27.909]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.909]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.909]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - query DirXML-Accounts Attribute'.
- [03/20/12 07:50:27.910]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.910]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.910]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - remove Dirxml-Account values on delete operation'.
- [03/20/12 07:50:27.910]:Active Directory ST: (if-operation match "delete|remove-association") = FALSE.
- [03/20/12 07:50:27.910]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.910]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.910]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.910]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - update DirXMLAccounts attribute'.
- [03/20/12 07:50:27.910]:Active Directory ST: (if-op-property 'AccountTracking-Operation' not-available) = TRUE.
- [03/20/12 07:50:27.911]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.911]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.911]:Active Directory ST: (if-xpath true "./@level='success'") = TRUE.
- [03/20/12 07:50:27.911]:Active Directory ST: (if-op-property 'AccountTracking-Operation' available) = FALSE.
- [03/20/12 07:50:27.911]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.911]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.911]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.912]:Active Directory ST: Applying policy: %+C%14Citp%-C.
- [03/20/12 07:50:27.912]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.912]:Active Directory ST: Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:27.912]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.912]:Active Directory ST: Applying rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:27.912]:Active Directory ST: Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
- [03/20/12 07:50:27.913]:Active Directory ST: Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:27.913]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.913]:Active Directory ST: Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:27.913]:Active Directory ST: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
- [03/20/12 07:50:27.913]:Active Directory ST: Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.913]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.913]:Active Directory ST: Applying rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.914]:Active Directory ST: Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:27.914]:Active Directory ST: Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.914]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.914]:Active Directory ST: Applying rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.914]:Active Directory ST: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:27.914]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.914]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.915]:Active Directory ST: Applying policy: %+C%14Citp-EntitlementsImpl%-C.
- [03/20/12 07:50:27.915]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.915]:Active Directory ST: Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
- [03/20/12 07:50:27.915]:Active Directory ST: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:50:27.915]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.915]:Active Directory ST: Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
- [03/20/12 07:50:27.916]:Active Directory ST: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:50:27.916]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.916]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.916]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.916]:Active Directory ST: Applying policy: %+C%14CPassword(Pub)-Sub Email Notifications%-C.
- [03/20/12 07:50:27.916]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.916]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
- [03/20/12 07:50:27.917]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.917]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.917]:Active Directory ST: (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
- [03/20/12 07:50:27.917]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.917]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Manager data store password'.
- [03/20/12 07:50:27.917]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.918]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.918]:Active Directory ST: (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
- [03/20/12 07:50:27.918]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.918]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.918]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.918]:Active Directory ST: Applying policy: %+C%14Clib-Audit-SendEntitlementsEvents-itp-V1%-C.
- [03/20/12 07:50:27.918]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.919]:Active Directory ST: Evaluating selection criteria for rule '00031200 - Account Create By Entitlement Grant'.
- [03/20/12 07:50:27.919]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.919]:Active Directory ST: (if-op-property 'accountAction' equal "accountCreateByEntitlementGrant") = FALSE.
- [03/20/12 07:50:27.919]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.919]:Active Directory ST: Evaluating selection criteria for rule '00031201 - Account Delete By Entitlement Revoke'.
- [03/20/12 07:50:27.919]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.919]:Active Directory ST: (if-xpath true "./operation-data/entitlement-impl/@state = '0'") = FALSE.
- [03/20/12 07:50:27.912]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:50:27.920]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.920]:Active Directory ST: (if-op-property 'accountAction' equal "accountDeleteByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:27.920]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.920]:Active Directory ST: Evaluating selection criteria for rule '00031202 - Account Disable By Entitlement Revoke'.
- [03/20/12 07:50:27.920]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.920]:Active Directory ST: (if-op-property 'accountAction' equal "accountDisableByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:27.920]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.920]:Active Directory ST: Evaluating selection criteria for rule '00031203 - Account Enable By Entitlement Grant'.
- [03/20/12 07:50:27.921]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.921]:Active Directory ST: (if-op-property 'accountAction' equal "accountEnableByEntitlementGrant") = FALSE.
- [03/20/12 07:50:27.921]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.921]:Active Directory ST: Evaluating selection criteria for rule 'Generate Audit Event'.
- [03/20/12 07:50:27.921]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.921]:Active Directory ST: (if-local-variable 'auditEventID' available) = FALSE.
- [03/20/12 07:50:27.921]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.921]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.921]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.922]:Active Directory ST: Applying schema mapping policies to input.
- [03/20/12 07:50:27.922]:Active Directory ST: Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:27.922]:Active Directory ST: Resolving association references.
- [03/20/12 07:50:27.922]:Active Directory ST: Query from policy result
- [03/20/12 07:50:27.922]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.923]:Active Directory ST: No matches found.
- [03/20/12 07:50:27.923]:Active Directory ST: Evaluating selection criteria for rule 'match everything else'.
- [03/20/12 07:50:27.923]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.923]:Active Directory ST: Applying rule 'match everything else'.
- [03/20/12 07:50:27.923]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.923]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.923]:Active Directory ST: (if-global-variable 'drv.subPlacementType' equal "flat") = FALSE.
- [03/20/12 07:50:27.923]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.924]:Active Directory ST: Action: do-find-matching-object(scope="entry",arg-dn(token-op-property("unmatched-src-dn")+","+token-global-variable("drv.user.container"))).
- [03/20/12 07:50:27.924]:Active Directory ST: arg-dn(token-op-property("unmatched-src-dn")+","+token-global-variable("drv.user.container"))
- [03/20/12 07:50:27.924]:Active Directory ST: token-op-property("unmatched-src-dn")
- [03/20/12 07:50:27.924]:Active Directory ST: Token Value: "CN=goldwap,OU=LAN,OU=BTDS,OU=Support".
- [03/20/12 07:50:27.924]:Active Directory ST: token-text(",")
- [03/20/12 07:50:27.924]:Active Directory ST: token-global-variable("drv.user.container")
- [03/20/12 07:50:27.924]:Active Directory ST: Token Value: "OU=FDNY,dc=edir2adlab,dc=local".
- [03/20/12 07:50:27.924]:Active Directory ST: Arg Value: "CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local".
- [03/20/12 07:50:27.925]:Active Directory ST: Query from policy
- [03/20/12 07:50:27.925]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="User" dest-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" scope="entry">
- <search-class class-name="User"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.925]:Active Directory ST: Fixing up association references.
- [03/20/12 07:50:27.925]:Active Directory ST: Applying schema mapping policies to output.
- [03/20/12 07:50:27.925]:Active Directory ST: Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:27.925]:Active Directory ST: Mapping class-name 'User' to 'user'.
- [03/20/12 07:50:27.926]:Active Directory ST: Mapping class-name 'User' to 'user'.
- [03/20/12 07:50:27.926]:Active Directory ST: Applying output transformation policies.
- [03/20/12 07:50:27.926]:Active Directory ST: Applying policy: %+C%14Cotp%-C.
- [03/20/12 07:50:27.926]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.926]:Active Directory ST: Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:27.926]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.926]:Active Directory ST: Applying rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:27.926]:Active Directory ST: Action: do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
- [03/20/12 07:50:27.927]:Active Directory ST: Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:27.927]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.927]:Active Directory ST: Applying rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:27.927]:Active Directory ST: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
- [03/20/12 07:50:27.927]:Active Directory ST: Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
- [03/20/12 07:50:27.927]:Active Directory ST: (if-op-attr 'accountExpires' changing) = FALSE.
- [03/20/12 07:50:27.927]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.927]:Active Directory ST: Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:27.928]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.928]:Active Directory ST: Applying rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:27.928]:Active Directory ST: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
- [03/20/12 07:50:27.928]:Active Directory ST: Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
- [03/20/12 07:50:27.928]:Active Directory ST: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:27.928]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.928]:Active Directory ST: Evaluating selection criteria for rule 'update Active Directory logon name'.
- [03/20/12 07:50:27.928]:Active Directory ST: (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
- [03/20/12 07:50:27.929]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.929]:Active Directory ST: Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:27.929]:Active Directory ST: (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = TRUE.
- [03/20/12 07:50:27.929]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.929]:Active Directory ST: Applying rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:27.929]:Active Directory ST: Action: do-strip-op-attr("homeMDB").
- [03/20/12 07:50:27.929]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.929]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.930]:Active Directory ST: Applying policy: %+C%14CPassword(Sub)-Pub Email Notifications%-C.
- [03/20/12 07:50:27.930]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.930]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
- [03/20/12 07:50:27.930]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.930]:Active Directory ST: (if-operation equal "status") = FALSE.
- [03/20/12 07:50:27.930]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.931]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.931]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.931]:Active Directory ST: Applying policy: %+C%14Clib-CredProv-ConvertPayload-otp-V1%-C.
- [03/20/12 07:50:27.931]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.931]:Active Directory ST: Evaluating selection criteria for rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:27.932]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.932]:Active Directory ST: Applying rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:27.932]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.932]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.932]:Active Directory ST: (if-global-variable 'credprov.enable' not-equal "true") = TRUE.
- [03/20/12 07:50:27.932]:Active Directory ST: Performing if actions.
- [03/20/12 07:50:27.932]:Active Directory ST: Action: do-break().
- [03/20/12 07:50:27.932]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.932]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.933]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-Subscribe-otp-V1%-C.
- [03/20/12 07:50:27.933]:Active Directory ST: Applying to query #1.
- [03/20/12 07:50:27.933]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.933]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.933]:Active Directory ST: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.933]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.934]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.934]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.934]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.934]:Active Directory ST: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
- [03/20/12 07:50:27.934]:Active Directory ST: arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
- [03/20/12 07:50:27.934]:Active Directory ST: token-global-variable("drv.acctTrk.objectClass")
- [03/20/12 07:50:27.934]:Active Directory ST: Token Value: {"user"}.
- [03/20/12 07:50:27.934]:Active Directory ST: Arg Value: {"user"}.
- [03/20/12 07:50:27.934]:Active Directory ST: Performing actions for local-variable(current-node) = "user".
- [03/20/12 07:50:27.935]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.935]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.935]:Active Directory ST: Expanded variable reference '$current-node$' to 'user'.
- [03/20/12 07:50:27.935]:Active Directory ST: (if-class-name equal "$current-node$") = TRUE.
- [03/20/12 07:50:27.935]:Active Directory ST: Performing if actions.
- [03/20/12 07:50:27.935]:Active Directory ST: Action: do-set-local-variable("pass",scope="policy","true").
- [03/20/12 07:50:27.935]:Active Directory ST: arg-string("true")
- [03/20/12 07:50:27.935]:Active Directory ST: token-text("true")
- [03/20/12 07:50:27.936]:Active Directory ST: Arg Value: "true".
- [03/20/12 07:50:27.936]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.936]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.936]:Active Directory ST: (if-local-variable 'pass' not-available) = FALSE.
- [03/20/12 07:50:27.936]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.936]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - include desired attribute values in operation-data'.
- [03/20/12 07:50:27.936]:Active Directory ST: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:50:27.936]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.936]:Active Directory ST: Evaluating selection criteria for rule 'Account-Tracking-StripAccountTrackingAccountStatus Attribute'.
- [03/20/12 07:50:27.937]:Active Directory ST: (if-op-attr 'AccountTrackingAccountStatus' available) = FALSE.
- [03/20/12 07:50:27.937]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.937]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.937]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.937]:Active Directory ST: Submitting document to subscriber shim:
- [03/20/12 07:50:27.938]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.938]:Active Directory ST: Remote Interface Driver: Sending...
- [03/20/12 07:50:27.938]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <query class-name="user" dest-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support,OU=FDNY,dc=edir2adlab,dc=local" event-id="0" scope="entry">
- <search-class class-name="user"/>
- <read-attr/>
- </query>
- </input>
- </nds>
- [03/20/12 07:50:27.939]:Active Directory ST: Remote Interface Driver: Document sent.
- [03/20/12 07:50:27.971]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:50:27.972]:Active Directory :
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.972]:Active Directory :Remote Interface Driver: Received document for subscriber channel
- [03/20/12 07:50:27.973]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:50:27.973]:Active Directory ST: SubscriptionShim.execute() returned:
- [03/20/12 07:50:27.973]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.973]:Active Directory ST: Applying input transformation policies.
- [03/20/12 07:50:27.973]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-Publish-itp-V1%-C.
- [03/20/12 07:50:27.974]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.974]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.974]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.974]:Active Directory ST: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:27.974]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.974]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.974]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.975]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.975]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.975]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.975]:Active Directory ST: (if-class-name available) = FALSE.
- [03/20/12 07:50:27.975]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.975]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - on add-association sync the operation-properties to status operations'.
- [03/20/12 07:50:27.975]:Active Directory ST: (if-operation equal "add-association") = FALSE.
- [03/20/12 07:50:27.975]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.975]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - Query for destination DN using Association'.
- [03/20/12 07:50:27.976]:Active Directory ST: (if-operation match "modify|delete|move|rename") = FALSE.
- [03/20/12 07:50:27.976]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.976]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:27.976]:Active Directory ST: (if-operation match "add|modify|delete|rename|move|status") = TRUE.
- [03/20/12 07:50:27.976]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.976]:Active Directory ST: Applying rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:27.976]:Active Directory ST: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.identifiers"))).
- [03/20/12 07:50:27.976]:Active Directory ST: arg-node-set(token-global-variable("drv.acctTrk.identifiers"))
- [03/20/12 07:50:27.977]:Active Directory ST: token-global-variable("drv.acctTrk.identifiers")
- [03/20/12 07:50:27.977]:Active Directory ST: Token Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:27.977]:Active Directory ST: Arg Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:27.977]:Active Directory ST: Performing actions for local-variable(current-node) = "sAMAccountName".
- [03/20/12 07:50:27.977]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.977]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.977]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.978]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.978]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.978]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.978]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.978]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.978]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.978]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.978]:Active Directory ST: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:27.978]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.979]:Active Directory ST: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:27.979]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.979]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.979]:Active Directory ST: Performing actions for local-variable(current-node) = "userPrincipalName".
- [03/20/12 07:50:27.979]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.979]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.979]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.979]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.980]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.980]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.980]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.980]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.980]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.980]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.980]:Active Directory ST: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:27.980]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.981]:Active Directory ST: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:27.981]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.981]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.981]:Active Directory ST: Performing actions for local-variable(current-node) = "LDAPDN".
- [03/20/12 07:50:27.981]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.981]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.981]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = TRUE.
- [03/20/12 07:50:27.981]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.981]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.982]:Active Directory ST: (if-src-dn available) = FALSE.
- [03/20/12 07:50:27.982]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.982]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.982]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.982]:Active Directory ST: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:27.982]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.982]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.982]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.982]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.983]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.983]:Active Directory ST: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:27.983]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.983]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.983]:Active Directory ST: Performing actions for local-variable(current-node) = "association".
- [03/20/12 07:50:27.983]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.983]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.984]:Active Directory ST: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:27.984]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.984]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.984]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.984]:Active Directory ST: (if-local-variable 'current-node' equal "association") = TRUE.
- [03/20/12 07:50:27.984]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.984]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.984]:Active Directory ST: (if-association available) = FALSE.
- [03/20/12 07:50:27.985]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.985]:Active Directory ST: Action: do-if().
- [03/20/12 07:50:27.985]:Active Directory ST: Evaluating conditions.
- [03/20/12 07:50:27.985]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.985]:Active Directory ST: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:27.985]:Active Directory ST: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:27.985]:Active Directory ST: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:27.985]:Active Directory ST: Performing else actions.
- [03/20/12 07:50:27.986]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - Initialize status properties on published events'.
- [03/20/12 07:50:27.986]:Active Directory ST: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:50:27.986]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.986]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.986]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.986]:Active Directory ST: Applying policy: %+C%14Clib-AccountTracking-WriteAccounts-itp-V1%-C.
- [03/20/12 07:50:27.987]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.987]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled'.
- [03/20/12 07:50:27.987]:Active Directory ST: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:27.987]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.987]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - query DirXML-Accounts Attribute'.
- [03/20/12 07:50:27.987]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.987]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.987]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - remove Dirxml-Account values on delete operation'.
- [03/20/12 07:50:27.988]:Active Directory ST: (if-operation match "delete|remove-association") = FALSE.
- [03/20/12 07:50:27.988]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.988]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.988]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.988]:Active Directory ST: Evaluating selection criteria for rule 'AccountTracking - update DirXMLAccounts attribute'.
- [03/20/12 07:50:27.988]:Active Directory ST: (if-op-property 'AccountTracking-Operation' not-available) = TRUE.
- [03/20/12 07:50:27.988]:Active Directory ST: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:27.988]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.989]:Active Directory ST: (if-xpath true "./@level='success'") = TRUE.
- [03/20/12 07:50:27.989]:Active Directory ST: (if-op-property 'AccountTracking-Operation' available) = FALSE.
- [03/20/12 07:50:27.989]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.989]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.989]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.989]:Active Directory ST: Applying policy: %+C%14Citp%-C.
- [03/20/12 07:50:27.989]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.990]:Active Directory ST: Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:27.990]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.990]:Active Directory ST: Applying rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:27.990]:Active Directory ST: Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
- [03/20/12 07:50:27.990]:Active Directory ST: Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:27.990]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.990]:Active Directory ST: Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:27.990]:Active Directory ST: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
- [03/20/12 07:50:27.991]:Active Directory ST: Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.991]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.991]:Active Directory ST: Applying rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.991]:Active Directory ST: Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:27.991]:Active Directory ST: Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.991]:Active Directory ST: Rule selected.
- [03/20/12 07:50:27.991]:Active Directory ST: Applying rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:27.992]:Active Directory ST: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:27.992]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.992]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.992]:Active Directory ST: Applying policy: %+C%14Citp-EntitlementsImpl%-C.
- [03/20/12 07:50:27.992]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.992]:Active Directory ST: Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
- [03/20/12 07:50:27.993]:Active Directory ST: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:50:27.993]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.993]:Active Directory ST: Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
- [03/20/12 07:50:27.993]:Active Directory ST: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:50:27.993]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.993]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.993]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.994]:Active Directory ST: Applying policy: %+C%14CPassword(Pub)-Sub Email Notifications%-C.
- [03/20/12 07:50:27.994]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.994]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
- [03/20/12 07:50:27.994]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.994]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.994]:Active Directory ST: (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
- [03/20/12 07:50:27.994]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.995]:Active Directory ST: Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Manager data store password'.
- [03/20/12 07:50:27.995]:Active Directory ST: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:27.995]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.995]:Active Directory ST: (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
- [03/20/12 07:50:27.995]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.995]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.995]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.996]:Active Directory ST: Applying policy: %+C%14Clib-Audit-SendEntitlementsEvents-itp-V1%-C.
- [03/20/12 07:50:27.996]:Active Directory ST: Applying to status #1.
- [03/20/12 07:50:27.996]:Active Directory ST: Evaluating selection criteria for rule '00031200 - Account Create By Entitlement Grant'.
- [03/20/12 07:50:27.996]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.996]:Active Directory ST: (if-op-property 'accountAction' equal "accountCreateByEntitlementGrant") = FALSE.
- [03/20/12 07:50:27.996]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.997]:Active Directory ST: Evaluating selection criteria for rule '00031201 - Account Delete By Entitlement Revoke'.
- [03/20/12 07:50:27.997]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.997]:Active Directory ST: (if-xpath true "./operation-data/entitlement-impl/@state = '0'") = FALSE.
- [03/20/12 07:50:27.997]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.997]:Active Directory ST: (if-op-property 'accountAction' equal "accountDeleteByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:27.997]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.997]:Active Directory ST: Evaluating selection criteria for rule '00031202 - Account Disable By Entitlement Revoke'.
- [03/20/12 07:50:27.997]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.998]:Active Directory ST: (if-op-property 'accountAction' equal "accountDisableByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:27.998]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.998]:Active Directory ST: Evaluating selection criteria for rule '00031203 - Account Enable By Entitlement Grant'.
- [03/20/12 07:50:27.998]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.998]:Active Directory ST: (if-op-property 'accountAction' equal "accountEnableByEntitlementGrant") = FALSE.
- [03/20/12 07:50:27.998]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.998]:Active Directory ST: Evaluating selection criteria for rule 'Generate Audit Event'.
- [03/20/12 07:50:27.998]:Active Directory ST: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:27.999]:Active Directory ST: (if-local-variable 'auditEventID' available) = FALSE.
- [03/20/12 07:50:27.999]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:27.999]:Active Directory ST: Policy returned:
- [03/20/12 07:50:27.999]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:27.999]:Active Directory ST: Applying schema mapping policies to input.
- [03/20/12 07:50:27.999]:Active Directory ST: Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:27.999]:Active Directory ST: Resolving association references.
- [03/20/12 07:50:28.000]:Active Directory ST: Query from policy result
- [03/20/12 07:50:28.000]:Active Directory ST:
- <nds dtdversion="1.1" ndsversion="8.7">
- <source>
- <product asn1id="" build="20090313_120000" instance="\EDIR2ADLAB\fdny\AD-TEST\Active Directory" version="3.5.5">AD</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"/>
- </output>
- </nds>
- [03/20/12 07:50:28.000]:Active Directory ST: No matches found.
- [03/20/12 07:50:28.000]:Active Directory ST: Direct command from policy
- [03/20/12 07:50:28.000]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <modify class-name="User" dest-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" dest-entry-id="32938" event-id="edir2adlab-idm361#20120320115027#1#1">
- <modify-attr attr-name="Full Name">
- <remove-all-values/>
- <add-value>
- <value>Philip Goldwasser</value>
- </add-value>
- </modify-attr>
- </modify>
- </input>
- </nds>
- [03/20/12 07:50:28.001]:Active Directory ST: Pumping XDS to eDirectory.
- [03/20/12 07:50:28.001]:Active Directory ST: Performing operation modify for \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap.
- [03/20/12 07:50:28.014]:Active Directory ST: Processing returned document.
- [03/20/12 07:50:28.014]:Active Directory ST: Processing operation <status> for .
- [03/20/12 07:50:28.014]:Active Directory ST:
- DirXML Log Event -------------------
- Driver: \EDIR2ADLAB\fdny\AD-TEST\Active Directory
- Channel: Subscriber
- Object: \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap
- Status: Error
- Message: Code(-9010) An exception occurred: novell.jclient.JCException: modifyEntry -672 ERR_NO_ACCESS
- [03/20/12 07:50:28.020]:Active Directory ST: Direct command from policy result
- [03/20/12 07:50:28.020]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="edir2adlab-idm361#20120320115027#1#1" level="error">Code(-9010) An exception occurred: novell.jclient.JCException: modifyEntry -672 ERR_NO_ACCESS<application>DirXML</application>
- <module>Active Directory</module>
- <object-dn>\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap</object-dn>
- <component>Subscriber</component>
- </status>
- </output>
- </nds>
- [03/20/12 07:50:28.021]:Active Directory ST:Policy returned:
- [03/20/12 07:50:28.021]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <add class-name="User" event-id="edir2adlab-idm361#20120320115027#1#1" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938">
- <add-attr attr-name="Given Name">
- <value timestamp="1332166853#1" type="string">Philip</value>
- </add-attr>
- <add-attr attr-name="Surname">
- <value timestamp="1332164807#3" type="string">Goldwasser</value>
- </add-attr>
- <add-attr attr-name="Full Name">
- <value>Philip Goldwasser</value>
- </add-attr>
- <operation-data attempt-to-match="true" unmatched-src-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support"/>
- </add>
- </input>
- </nds>
- [03/20/12 07:50:28.022]:Active Directory ST:No match found.
- [03/20/12 07:50:28.022]:Active Directory ST:Applying object creation policies.
- [03/20/12 07:50:28.022]:Active Directory ST:Applying policy: %+C%14Csub-cp-EntitlementsImpl%-C.
- [03/20/12 07:50:28.022]:Active Directory ST: Applying to add #1.
- [03/20/12 07:50:28.022]:Active Directory ST: Evaluating selection criteria for rule 'UserAccount entitlement: Veto account creation when entitlement not granted'.
- [03/20/12 07:50:28.022]:Active Directory ST: (if-global-variable 'drv.entitlement.UserAccount' equal "true") = FALSE.
- [03/20/12 07:50:28.023]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:28.023]:Active Directory ST: Evaluating selection criteria for rule 'Prepare to check group entitlements after add'.
- [03/20/12 07:50:28.023]:Active Directory ST: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:50:28.023]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:28.023]:Active Directory ST: Evaluating selection criteria for rule 'Prepare to check Exchange entitlements after the add'.
- [03/20/12 07:50:28.023]:Active Directory ST: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:50:28.023]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:28.023]:Active Directory ST:Policy returned:
- [03/20/12 07:50:28.024]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <add class-name="User" event-id="edir2adlab-idm361#20120320115027#1#1" qualified-src-dn="O=fdny\OU=Support\OU=BTDS\OU=LAN\CN=goldwap" src-dn="\EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap" src-entry-id="32938">
- <add-attr attr-name="Given Name">
- <value timestamp="1332166853#1" type="string">Philip</value>
- </add-attr>
- <add-attr attr-name="Surname">
- <value timestamp="1332164807#3" type="string">Goldwasser</value>
- </add-attr>
- <add-attr attr-name="Full Name">
- <value>Philip Goldwasser</value>
- </add-attr>
- <operation-data attempt-to-match="true" unmatched-src-dn="CN=goldwap,OU=LAN,OU=BTDS,OU=Support"/>
- </add>
- </input>
- </nds>
- [03/20/12 07:50:28.025]:Active Directory ST:Applying policy: %+C%14Csub-cp-Users%-C.
- [03/20/12 07:50:28.025]:Active Directory ST: Applying to add #1.
- [03/20/12 07:50:28.025]:Active Directory ST: Evaluating selection criteria for rule 'Break if not a User'.
- [03/20/12 07:50:28.025]:Active Directory ST: (if-class-name not-equal "User") = FALSE.
- [03/20/12 07:50:28.025]:Active Directory ST: Rule rejected.
- [03/20/12 07:50:28.025]:Active Directory ST: Evaluating selection criteria for rule 'Veto if nspmDistributionPassword is not available'.
- [03/20/12 07:50:28.025]:Active Directory ST: Rule selected.
- [03/20/12 07:50:28.025]:Active Directory ST: Applying rule 'Veto if nspmDistributionPassword is not available'.
- [03/20/12 07:50:28.025]:Active Directory ST: Action: do-veto-if-op-attr-not-available("nspmDistributionPassword").
- [03/20/12 07:50:28.026]:Active Directory ST:Policy returned:
- [03/20/12 07:50:28.026]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input/>
- </nds>
- [03/20/12 07:50:28.026]:Active Directory ST:Applying policy: %+C%14Csub-cp-ExchMailboxPolicy%-C.
- [03/20/12 07:50:28.026]:Active Directory ST:Policy returned:
- [03/20/12 07:50:28.026]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input/>
- </nds>
- [03/20/12 07:50:28.026]:Active Directory ST:Applying policy: %+C%14Clib-CredProv-RequiredAttributes-sub-cp-V1%-C.
- [03/20/12 07:50:28.026]:Active Directory ST:Policy returned:
- [03/20/12 07:50:28.026]:Active Directory ST:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input/>
- </nds>
- [03/20/12 07:50:28.027]:Active Directory ST:Processing returned document.
- [03/20/12 07:50:28.027]:Active Directory ST:Processing operation <status> for .
- [03/20/12 07:50:28.027]:Active Directory ST:
- DirXML Log Event -------------------
- Driver: \EDIR2ADLAB\fdny\AD-TEST\Active Directory
- Channel: Subscriber
- Object: \EDIR2ADLAB\fdny\Support\BTDS\LAN\goldwap
- Status: Warning
- Message: Code(-8017) Operation vetoed by object creation policy.
- [03/20/12 07:50:28.027]:Active Directory ST:End transaction.
- [03/20/12 07:50:46.892]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:50:46.892]:Active Directory :
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.893]:Active Directory :Remote Interface Driver: Received document for publisher channel
- [03/20/12 07:50:46.893]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:50:46.893]:Active Directory PT:Receiving DOM document from application.
- [03/20/12 07:50:46.893]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.894]:Active Directory PT:Applying input transformation policies.
- [03/20/12 07:50:46.894]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Publish-itp-V1%-C.
- [03/20/12 07:50:46.894]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.894]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:46.895]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.895]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:46.895]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.895]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.895]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:46.895]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.896]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.896]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.896]:Active Directory PT: (if-class-name available) = FALSE.
- [03/20/12 07:50:46.896]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.896]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add-association sync the operation-properties to status operations'.
- [03/20/12 07:50:46.896]:Active Directory PT: (if-operation equal "add-association") = FALSE.
- [03/20/12 07:50:46.897]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.897]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Query for destination DN using Association'.
- [03/20/12 07:50:46.897]:Active Directory PT: (if-operation match "modify|delete|move|rename") = FALSE.
- [03/20/12 07:50:46.898]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.898]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:46.898]:Active Directory PT: (if-operation match "add|modify|delete|rename|move|status") = TRUE.
- [03/20/12 07:50:46.898]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.898]:Active Directory PT: Applying rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:50:46.898]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.identifiers"))).
- [03/20/12 07:50:46.899]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.identifiers"))
- [03/20/12 07:50:46.899]:Active Directory PT: token-global-variable("drv.acctTrk.identifiers")
- [03/20/12 07:50:46.899]:Active Directory PT: Token Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:46.899]:Active Directory PT: Arg Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:50:46.900]:Active Directory PT: Performing actions for local-variable(current-node) = "sAMAccountName".
- [03/20/12 07:50:46.900]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.900]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.900]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:46.900]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.900]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.900]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.901]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:46.901]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.901]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.901]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.901]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:46.902]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:46.902]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:50:46.902]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:46.902]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.902]:Active Directory PT: Performing actions for local-variable(current-node) = "userPrincipalName".
- [03/20/12 07:50:46.903]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.903]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.903]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:46.903]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.903]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.903]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.903]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:46.904]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.904]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.904]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.904]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:46.904]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:46.905]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:50:46.905]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:46.905]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.905]:Active Directory PT: Performing actions for local-variable(current-node) = "LDAPDN".
- [03/20/12 07:50:46.905]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.906]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.906]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = TRUE.
- [03/20/12 07:50:46.906]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:46.906]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:46.906]:Active Directory PT: (if-src-dn available) = FALSE.
- [03/20/12 07:50:46.906]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.907]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.907]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.907]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:50:46.907]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.907]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.907]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.907]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:46.908]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:46.908]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:50:46.908]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:46.908]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.908]:Active Directory PT: Performing actions for local-variable(current-node) = "association".
- [03/20/12 07:50:46.909]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.909]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.909]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:50:46.909]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.909]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.909]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.910]:Active Directory PT: (if-local-variable 'current-node' equal "association") = TRUE.
- [03/20/12 07:50:46.910]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:46.910]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:46.910]:Active Directory PT: (if-association available) = FALSE.
- [03/20/12 07:50:46.910]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.911]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.911]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.911]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:46.911]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:50:46.911]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:50:46.911]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:50:46.912]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.912]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Initialize status properties on published events'.
- [03/20/12 07:50:46.912]:Active Directory PT: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:50:46.912]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.912]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.912]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.913]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccounts-itp-V1%-C.
- [03/20/12 07:50:46.913]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.913]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled'.
- [03/20/12 07:50:46.914]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:46.914]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.914]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - query DirXML-Accounts Attribute'.
- [03/20/12 07:50:46.914]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:46.914]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.914]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - remove Dirxml-Account values on delete operation'.
- [03/20/12 07:50:46.915]:Active Directory PT: (if-operation match "delete|remove-association") = FALSE.
- [03/20/12 07:50:46.915]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.915]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:46.915]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.915]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - update DirXMLAccounts attribute'.
- [03/20/12 07:50:46.916]:Active Directory PT: (if-op-property 'AccountTracking-Operation' not-available) = TRUE.
- [03/20/12 07:50:46.916]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:50:46.916]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.916]:Active Directory PT: (if-xpath true "./@level='success'") = TRUE.
- [03/20/12 07:50:46.916]:Active Directory PT: (if-op-property 'AccountTracking-Operation' available) = FALSE.
- [03/20/12 07:50:46.916]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.917]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.917]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.917]:Active Directory PT:Applying policy: %+C%14Citp%-C.
- [03/20/12 07:50:46.917]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.917]:Active Directory PT: Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:46.918]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.918]:Active Directory PT: Applying rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:50:46.918]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
- [03/20/12 07:50:46.918]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:46.918]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.918]:Active Directory PT: Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:50:46.919]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
- [03/20/12 07:50:46.919]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:46.919]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.919]:Active Directory PT: Applying rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:50:46.919]:Active Directory PT: Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:46.920]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:46.920]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.920]:Active Directory PT: Applying rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:50:46.920]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:50:46.920]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.921]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.921]:Active Directory PT:Applying policy: %+C%14Citp-EntitlementsImpl%-C.
- [03/20/12 07:50:46.921]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.921]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
- [03/20/12 07:50:46.922]:Active Directory PT: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:50:46.922]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.922]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
- [03/20/12 07:50:46.922]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:50:46.922]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.923]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.923]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.923]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Sub Email Notifications%-C.
- [03/20/12 07:50:46.923]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.925]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
- [03/20/12 07:50:46.925]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:46.925]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.926]:Active Directory PT: (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
- [03/20/12 07:50:46.926]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.926]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Manager data store password'.
- [03/20/12 07:50:46.926]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:46.927]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.927]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
- [03/20/12 07:50:46.927]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.927]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.927]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.928]:Active Directory PT:Applying policy: %+C%14Clib-Audit-SendEntitlementsEvents-itp-V1%-C.
- [03/20/12 07:50:46.928]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.928]:Active Directory PT: Evaluating selection criteria for rule '00031200 - Account Create By Entitlement Grant'.
- [03/20/12 07:50:46.928]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.928]:Active Directory PT: (if-op-property 'accountAction' equal "accountCreateByEntitlementGrant") = FALSE.
- [03/20/12 07:50:46.928]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.929]:Active Directory PT: Evaluating selection criteria for rule '00031201 - Account Delete By Entitlement Revoke'.
- [03/20/12 07:50:46.929]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.929]:Active Directory PT: (if-xpath true "./operation-data/entitlement-impl/@state = '0'") = FALSE.
- [03/20/12 07:50:46.929]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.930]:Active Directory PT: (if-op-property 'accountAction' equal "accountDeleteByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:46.930]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.930]:Active Directory PT: Evaluating selection criteria for rule '00031202 - Account Disable By Entitlement Revoke'.
- [03/20/12 07:50:46.930]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.930]:Active Directory PT: (if-op-property 'accountAction' equal "accountDisableByEntitlementRevoke") = FALSE.
- [03/20/12 07:50:46.930]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.931]:Active Directory PT: Evaluating selection criteria for rule '00031203 - Account Enable By Entitlement Grant'.
- [03/20/12 07:50:46.931]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.931]:Active Directory PT: (if-op-property 'accountAction' equal "accountEnableByEntitlementGrant") = FALSE.
- [03/20/12 07:50:46.931]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.931]:Active Directory PT: Evaluating selection criteria for rule 'Generate Audit Event'.
- [03/20/12 07:50:46.931]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.932]:Active Directory PT: (if-local-variable 'auditEventID' available) = FALSE.
- [03/20/12 07:50:46.932]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.932]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.932]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.932]:Active Directory PT:Applying schema mapping policies to input.
- [03/20/12 07:50:46.933]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:46.933]:Active Directory PT:Resolving association references.
- [03/20/12 07:50:46.933]:Active Directory PT:Applying event transformation policies.
- [03/20/12 07:50:46.933]:Active Directory PT:Applying policy: %+C%14Cpub-etp-EntitlementsImpl%-C.
- [03/20/12 07:50:46.934]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.934]:Active Directory PT: Evaluating selection criteria for rule 'Disallow user account delete when using entitlements'.
- [03/20/12 07:50:46.934]:Active Directory PT: (if-operation equal "delete") = FALSE.
- [03/20/12 07:50:46.934]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.934]:Active Directory PT: Evaluating selection criteria for rule 'Strip Login Disabled from operation (Disable Option)'.
- [03/20/12 07:50:46.935]:Active Directory PT: (if-global-variable 'drv.entitlement.UserAccount' equal "true") = FALSE.
- [03/20/12 07:50:46.935]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.935]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.935]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.935]:Active Directory PT:Applying policy: %+C%14Cpub-etp-HandleMovesAndRenames%-C.
- [03/20/12 07:50:46.936]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.936]:Active Directory PT: Evaluating selection criteria for rule 'break if not a move or rename'.
- [03/20/12 07:50:46.936]:Active Directory PT: (if-operation not-match "move|rename") = TRUE.
- [03/20/12 07:50:46.936]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.936]:Active Directory PT: Applying rule 'break if not a move or rename'.
- [03/20/12 07:50:46.936]:Active Directory PT: Action: do-break().
- [03/20/12 07:50:46.936]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.937]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.937]:Active Directory PT:Applying publisher filter.
- [03/20/12 07:50:46.937]:Active Directory PT:Publisher processing status for .
- [03/20/12 07:50:46.938]:Active Directory PT:Applying command transformation policies.
- [03/20/12 07:50:46.938]:Active Directory PT:Applying policy: %+C%14Cpub-ctp-UserNameMap%-C.
- [03/20/12 07:50:46.938]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.938]:Active Directory PT: Evaluating selection criteria for rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:50:46.938]:Active Directory PT: (if-class-name not-equal "User") = TRUE.
- [03/20/12 07:50:46.938]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.939]:Active Directory PT: Applying rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:50:46.939]:Active Directory PT: Action: do-break().
- [03/20/12 07:50:46.939]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.939]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.939]:Active Directory PT:Applying policy: %+C%14Cpub-ctp%-C.
- [03/20/12 07:50:46.940]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.940]:Active Directory PT: Evaluating selection criteria for rule 'set cached context value on merge'.
- [03/20/12 07:50:46.940]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:50:46.940]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.940]:Active Directory PT: Evaluating selection criteria for rule 'Set Equivalent To Me when adding object to a group'.
- [03/20/12 07:50:46.940]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:50:46.941]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.941]:Active Directory PT: Evaluating selection criteria for rule 'Remove Equivalent To Me when removing object from a group'.
- [03/20/12 07:50:46.941]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:50:46.941]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.941]:Active Directory PT: Evaluating selection criteria for rule 'remove managed attributes when object disassociated'.
- [03/20/12 07:50:46.942]:Active Directory PT: (if-operation equal "remove-association") = FALSE.
- [03/20/12 07:50:46.942]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.942]:Active Directory PT: Evaluating selection criteria for rule 'Prevent unassociated users from being removed from groups'.
- [03/20/12 07:50:46.942]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:50:46.942]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.942]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.943]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.943]:Active Directory PT:Applying XSLT policy: %+C%14Cpub-cts%-C.
- [03/20/12 07:50:46.944]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.944]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.944]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Default Password Policy%-C.
- [03/20/12 07:50:46.945]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.945]:Active Directory PT: Evaluating selection criteria for rule 'On User add, provide default password of @Dirxml1 if no password exists'.
- [03/20/12 07:50:46.945]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:46.945]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.945]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.945]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.946]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Check Password GCV%-C.
- [03/20/12 07:50:46.946]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.946]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to Identity Manager data store when adding a object'.
- [03/20/12 07:50:46.946]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:50:46.947]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.947]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the Identity Manager data store'.
- [03/20/12 07:50:46.947]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:50:46.947]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.947]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.947]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.948]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish Distribution Password%-C.
- [03/20/12 07:50:46.948]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.948]:Active Directory PT: Evaluating selection criteria for rule 'Add nspmDistributionAttribute attribute to add operation'.
- [03/20/12 07:50:46.948]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:50:46.949]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.949]:Active Directory PT: Evaluating selection criteria for rule 'Change modify-password operations to a modify'.
- [03/20/12 07:50:46.949]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:50:46.949]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.949]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.949]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.950]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish NDS Password%-C.
- [03/20/12 07:50:46.950]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.950]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to NDS password'.
- [03/20/12 07:50:46.950]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:50:46.950]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.951]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the NDS password'.
- [03/20/12 07:50:46.951]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:50:46.951]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.951]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.951]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.952]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Add Password Payload%-C.
- [03/20/12 07:50:46.952]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.952]:Active Directory PT: Evaluating selection criteria for rule 'Add operation-data element to password operations'.
- [03/20/12 07:50:46.952]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:46.952]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:46.952]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:50:46.953]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:50:46.953]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.953]:Active Directory PT: Evaluating selection criteria for rule 'Add payload data to password operations'.
- [03/20/12 07:50:46.953]:Active Directory PT: (if-operation equal "addPayloadToPassword") = FALSE.
- [03/20/12 07:50:46.954]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:46.954]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:50:46.954]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:50:46.954]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.954]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.954]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.955]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccountsOnAdds-pub-ctp-V1%-C.
- [03/20/12 07:50:46.955]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.955]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard policy if disabled'.
- [03/20/12 07:50:46.955]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:46.955]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.955]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add operation add Dirxml-Accounts'.
- [03/20/12 07:50:46.956]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:46.956]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.956]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.956]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:50:46.956]:Active Directory PT:Filtering out notification-only attributes.
- [03/20/12 07:50:46.957]:Active Directory PT:Pumping XDS to eDirectory.
- [03/20/12 07:50:46.957]:Active Directory PT:Performing operation status for .
- [03/20/12 07:50:46.957]:Active Directory PT:
- DirXML Log Event -------------------
- Driver: \EDIR2ADLAB\fdny\AD-TEST\Active Directory
- Channel: Publisher
- Status: Success
- [03/20/12 07:50:46.957]:Active Directory PT:Fixing up association references.
- [03/20/12 07:50:46.958]:Active Directory PT:Applying schema mapping policies to output.
- [03/20/12 07:50:46.958]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:50:46.958]:Active Directory PT:Applying output transformation policies.
- [03/20/12 07:50:46.958]:Active Directory PT:Applying policy: %+C%14Cotp%-C.
- [03/20/12 07:50:46.958]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.958]:Active Directory PT: Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:46.959]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.959]:Active Directory PT: Applying rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:50:46.959]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
- [03/20/12 07:50:46.959]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:46.959]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.959]:Active Directory PT: Applying rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:50:46.960]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
- [03/20/12 07:50:46.960]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
- [03/20/12 07:50:46.960]:Active Directory PT: (if-op-attr 'accountExpires' changing) = FALSE.
- [03/20/12 07:50:46.960]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.960]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:46.961]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.961]:Active Directory PT: Applying rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:50:46.961]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
- [03/20/12 07:50:46.961]:Active Directory PT: Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
- [03/20/12 07:50:46.961]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:50:46.962]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.962]:Active Directory PT: Evaluating selection criteria for rule 'update Active Directory logon name'.
- [03/20/12 07:50:46.962]:Active Directory PT: (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
- [03/20/12 07:50:46.962]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.962]:Active Directory PT: Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:46.962]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = TRUE.
- [03/20/12 07:50:46.963]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.963]:Active Directory PT: Applying rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:50:46.963]:Active Directory PT: Action: do-strip-op-attr("homeMDB").
- [03/20/12 07:50:46.963]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.963]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:46.964]:Active Directory PT:Applying policy: %+C%14CPassword(Sub)-Pub Email Notifications%-C.
- [03/20/12 07:50:46.964]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.964]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
- [03/20/12 07:50:46.964]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:50:46.964]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:50:46.965]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-publish-status") = FALSE.
- [03/20/12 07:50:46.965]:Active Directory PT: Rule rejected.
- [03/20/12 07:50:46.965]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.965]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:46.966]:Active Directory PT:Applying policy: %+C%14Clib-CredProv-ConvertPayload-otp-V1%-C.
- [03/20/12 07:50:46.966]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.966]:Active Directory PT: Evaluating selection criteria for rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:46.966]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.966]:Active Directory PT: Applying rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:50:46.966]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.967]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.967]:Active Directory PT: (if-global-variable 'credprov.enable' not-equal "true") = TRUE.
- [03/20/12 07:50:46.967]:Active Directory PT: Performing if actions.
- [03/20/12 07:50:46.967]:Active Directory PT: Action: do-break().
- [03/20/12 07:50:46.967]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.967]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:46.968]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Subscribe-otp-V1%-C.
- [03/20/12 07:50:46.968]:Active Directory PT: Applying to status #1.
- [03/20/12 07:50:46.968]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:46.968]:Active Directory PT: Rule selected.
- [03/20/12 07:50:46.968]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:50:46.969]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.969]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.969]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:50:46.969]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.969]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
- [03/20/12 07:50:46.970]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
- [03/20/12 07:50:46.970]:Active Directory PT: token-global-variable("drv.acctTrk.objectClass")
- [03/20/12 07:50:46.970]:Active Directory PT: Token Value: {"user"}.
- [03/20/12 07:50:46.970]:Active Directory PT: Arg Value: {"user"}.
- [03/20/12 07:50:46.970]:Active Directory PT: Performing actions for local-variable(current-node) = "user".
- [03/20/12 07:50:46.970]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.971]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.971]:Active Directory PT: (if-class-name equal "$current-node$") = FALSE.
- [03/20/12 07:50:46.971]:Active Directory PT: Performing else actions.
- [03/20/12 07:50:46.971]:Active Directory PT: Action: do-if().
- [03/20/12 07:50:46.971]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:50:46.971]:Active Directory PT: (if-local-variable 'pass' not-available) = TRUE.
- [03/20/12 07:50:46.971]:Active Directory PT: Performing if actions.
- [03/20/12 07:50:46.972]:Active Directory PT: Action: do-break().
- [03/20/12 07:50:46.972]:Active Directory PT:Policy returned:
- [03/20/12 07:50:46.972]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:46.972]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:46.973]:Active Directory PT:Remote Interface Driver: Sending...
- [03/20/12 07:50:46.973]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:50:46.973]:Active Directory PT:Remote Interface Driver: Document sent.
- [03/20/12 07:51:46.886]:Active Directory :Remote Interface Driver: Received.
- [03/20/12 07:51:46.886]:Active Directory :
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.887]:Active Directory :Remote Interface Driver: Received document for publisher channel
- [03/20/12 07:51:46.887]:Active Directory :Remote Interface Driver: Waiting for receive...
- [03/20/12 07:51:46.887]:Active Directory PT:Receiving DOM document from application.
- [03/20/12 07:51:46.887]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.888]:Active Directory PT:Applying input transformation policies.
- [03/20/12 07:51:46.888]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Publish-itp-V1%-C.
- [03/20/12 07:51:46.888]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.888]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:51:46.888]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.889]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:51:46.889]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.889]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.889]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:51:46.889]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.889]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.889]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.890]:Active Directory PT: (if-class-name available) = FALSE.
- [03/20/12 07:51:46.890]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.890]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add-association sync the operation-properties to status operations'.
- [03/20/12 07:51:46.890]:Active Directory PT: (if-operation equal "add-association") = FALSE.
- [03/20/12 07:51:46.890]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.890]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Query for destination DN using Association'.
- [03/20/12 07:51:46.891]:Active Directory PT: (if-operation match "modify|delete|move|rename") = FALSE.
- [03/20/12 07:51:46.891]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.891]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:51:46.891]:Active Directory PT: (if-operation match "add|modify|delete|rename|move|status") = TRUE.
- [03/20/12 07:51:46.891]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.891]:Active Directory PT: Applying rule 'AccountTracking - add interested properties to current doc for future use.'.
- [03/20/12 07:51:46.892]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.identifiers"))).
- [03/20/12 07:51:46.892]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.identifiers"))
- [03/20/12 07:51:46.892]:Active Directory PT: token-global-variable("drv.acctTrk.identifiers")
- [03/20/12 07:51:46.892]:Active Directory PT: Token Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:51:46.892]:Active Directory PT: Arg Value: {"sAMAccountName","userPrincipalName","LDAPDN","association"}.
- [03/20/12 07:51:46.893]:Active Directory PT: Performing actions for local-variable(current-node) = "sAMAccountName".
- [03/20/12 07:51:46.893]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.893]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.893]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:51:46.893]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.893]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.893]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.894]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:51:46.894]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.894]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.894]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.894]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:51:46.894]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:51:46.895]:Active Directory PT: Expanded variable reference '$current-node$' to 'sAMAccountName'.
- [03/20/12 07:51:46.895]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:51:46.895]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.895]:Active Directory PT: Performing actions for local-variable(current-node) = "userPrincipalName".
- [03/20/12 07:51:46.895]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.895]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.896]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:51:46.896]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.896]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.896]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.896]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:51:46.896]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.896]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.897]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.897]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:51:46.897]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:51:46.897]:Active Directory PT: Expanded variable reference '$current-node$' to 'userPrincipalName'.
- [03/20/12 07:51:46.897]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:51:46.897]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.898]:Active Directory PT: Performing actions for local-variable(current-node) = "LDAPDN".
- [03/20/12 07:51:46.898]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.898]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.898]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = TRUE.
- [03/20/12 07:51:46.898]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:51:46.898]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:51:46.899]:Active Directory PT: (if-src-dn available) = FALSE.
- [03/20/12 07:51:46.899]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.899]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.899]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.899]:Active Directory PT: (if-local-variable 'current-node' equal "association") = FALSE.
- [03/20/12 07:51:46.899]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.899]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.900]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.900]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:51:46.900]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:51:46.900]:Active Directory PT: Expanded variable reference '$current-node$' to 'LDAPDN'.
- [03/20/12 07:51:46.900]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:51:46.901]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.901]:Active Directory PT: Performing actions for local-variable(current-node) = "association".
- [03/20/12 07:51:46.901]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.901]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.901]:Active Directory PT: (if-local-variable 'current-node' equal "LDAPDN") = FALSE.
- [03/20/12 07:51:46.901]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.901]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.902]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.902]:Active Directory PT: (if-local-variable 'current-node' equal "association") = TRUE.
- [03/20/12 07:51:46.902]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:51:46.902]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:51:46.902]:Active Directory PT: (if-association available) = FALSE.
- [03/20/12 07:51:46.902]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.903]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.903]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.903]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:51:46.903]:Active Directory PT: (if-op-property 'AccountTracking-$current-node$' not-available) = TRUE.
- [03/20/12 07:51:46.903]:Active Directory PT: Expanded variable reference '$current-node$' to 'association'.
- [03/20/12 07:51:46.903]:Active Directory PT: (if-op-attr '$current-node$' available) = FALSE.
- [03/20/12 07:51:46.904]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.904]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - Initialize status properties on published events'.
- [03/20/12 07:51:46.904]:Active Directory PT: (if-operation match "add|modify|delete|rename|move") = FALSE.
- [03/20/12 07:51:46.904]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.904]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.904]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.905]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccounts-itp-V1%-C.
- [03/20/12 07:51:46.905]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.905]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled'.
- [03/20/12 07:51:46.905]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:51:46.905]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.906]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - query DirXML-Accounts Attribute'.
- [03/20/12 07:51:46.906]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:51:46.906]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.906]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - remove Dirxml-Account values on delete operation'.
- [03/20/12 07:51:46.906]:Active Directory PT: (if-operation match "delete|remove-association") = FALSE.
- [03/20/12 07:51:46.906]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.907]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:51:46.907]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.907]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - update DirXMLAccounts attribute'.
- [03/20/12 07:51:46.907]:Active Directory PT: (if-op-property 'AccountTracking-Operation' not-available) = TRUE.
- [03/20/12 07:51:46.907]:Active Directory PT: (if-op-property 'AccountTracking-ObjectDN' available) = FALSE.
- [03/20/12 07:51:46.907]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.908]:Active Directory PT: (if-xpath true "./@level='success'") = TRUE.
- [03/20/12 07:51:46.908]:Active Directory PT: (if-op-property 'AccountTracking-Operation' available) = FALSE.
- [03/20/12 07:51:46.908]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.908]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.908]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.908]:Active Directory PT:Applying policy: %+C%14Citp%-C.
- [03/20/12 07:51:46.909]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.909]:Active Directory PT: Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:51:46.909]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.909]:Active Directory PT: Applying rule 'streetAddress: Convert CR-LF to LF'.
- [03/20/12 07:51:46.909]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
- [03/20/12 07:51:46.909]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:51:46.910]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.910]:Active Directory PT: Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
- [03/20/12 07:51:46.910]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
- [03/20/12 07:51:46.910]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:51:46.910]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.910]:Active Directory PT: Applying rule 'accountExpires: Convert to Identity Vault time format'.
- [03/20/12 07:51:46.911]:Active Directory PT: Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:51:46.911]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:51:46.911]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.911]:Active Directory PT: Applying rule 'lockoutTime: Convert to Identity Vault time format'.
- [03/20/12 07:51:46.911]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
- [03/20/12 07:51:46.912]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.912]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.912]:Active Directory PT:Applying policy: %+C%14Citp-EntitlementsImpl%-C.
- [03/20/12 07:51:46.912]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.912]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
- [03/20/12 07:51:46.913]:Active Directory PT: (if-global-variable 'drv.entitlement.Group' equal "true") = FALSE.
- [03/20/12 07:51:46.913]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.913]:Active Directory PT: Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
- [03/20/12 07:51:46.913]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = FALSE.
- [03/20/12 07:51:46.913]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.913]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.913]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.914]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Sub Email Notifications%-C.
- [03/20/12 07:51:46.914]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.914]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
- [03/20/12 07:51:46.914]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:51:46.915]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.915]:Active Directory PT: (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
- [03/20/12 07:51:46.915]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.915]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Manager data store password'.
- [03/20/12 07:51:46.915]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:51:46.916]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.916]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
- [03/20/12 07:51:46.916]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.916]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.916]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.916]:Active Directory PT:Applying policy: %+C%14Clib-Audit-SendEntitlementsEvents-itp-V1%-C.
- [03/20/12 07:51:46.917]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.917]:Active Directory PT: Evaluating selection criteria for rule '00031200 - Account Create By Entitlement Grant'.
- [03/20/12 07:51:46.917]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.917]:Active Directory PT: (if-op-property 'accountAction' equal "accountCreateByEntitlementGrant") = FALSE.
- [03/20/12 07:51:46.917]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.917]:Active Directory PT: Evaluating selection criteria for rule '00031201 - Account Delete By Entitlement Revoke'.
- [03/20/12 07:51:46.918]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.918]:Active Directory PT: (if-xpath true "./operation-data/entitlement-impl/@state = '0'") = FALSE.
- [03/20/12 07:51:46.918]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.918]:Active Directory PT: (if-op-property 'accountAction' equal "accountDeleteByEntitlementRevoke") = FALSE.
- [03/20/12 07:51:46.918]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.918]:Active Directory PT: Evaluating selection criteria for rule '00031202 - Account Disable By Entitlement Revoke'.
- [03/20/12 07:51:46.919]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.919]:Active Directory PT: (if-op-property 'accountAction' equal "accountDisableByEntitlementRevoke") = FALSE.
- [03/20/12 07:51:46.919]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.919]:Active Directory PT: Evaluating selection criteria for rule '00031203 - Account Enable By Entitlement Grant'.
- [03/20/12 07:51:46.919]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.919]:Active Directory PT: (if-op-property 'accountAction' equal "accountEnableByEntitlementGrant") = FALSE.
- [03/20/12 07:51:46.920]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.920]:Active Directory PT: Evaluating selection criteria for rule 'Generate Audit Event'.
- [03/20/12 07:51:46.920]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.920]:Active Directory PT: (if-local-variable 'auditEventID' available) = FALSE.
- [03/20/12 07:51:46.920]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.920]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.920]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.921]:Active Directory PT:Applying schema mapping policies to input.
- [03/20/12 07:51:46.921]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:51:46.921]:Active Directory PT:Resolving association references.
- [03/20/12 07:51:46.921]:Active Directory PT:Applying event transformation policies.
- [03/20/12 07:51:46.921]:Active Directory PT:Applying policy: %+C%14Cpub-etp-EntitlementsImpl%-C.
- [03/20/12 07:51:46.922]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.922]:Active Directory PT: Evaluating selection criteria for rule 'Disallow user account delete when using entitlements'.
- [03/20/12 07:51:46.922]:Active Directory PT: (if-operation equal "delete") = FALSE.
- [03/20/12 07:51:46.922]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.922]:Active Directory PT: Evaluating selection criteria for rule 'Strip Login Disabled from operation (Disable Option)'.
- [03/20/12 07:51:46.922]:Active Directory PT: (if-global-variable 'drv.entitlement.UserAccount' equal "true") = FALSE.
- [03/20/12 07:51:46.923]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.923]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.923]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.923]:Active Directory PT:Applying policy: %+C%14Cpub-etp-HandleMovesAndRenames%-C.
- [03/20/12 07:51:46.923]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.923]:Active Directory PT: Evaluating selection criteria for rule 'break if not a move or rename'.
- [03/20/12 07:51:46.924]:Active Directory PT: (if-operation not-match "move|rename") = TRUE.
- [03/20/12 07:51:46.924]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.924]:Active Directory PT: Applying rule 'break if not a move or rename'.
- [03/20/12 07:51:46.924]:Active Directory PT: Action: do-break().
- [03/20/12 07:51:46.924]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.924]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.925]:Active Directory PT:Applying publisher filter.
- [03/20/12 07:51:46.925]:Active Directory PT:Publisher processing status for .
- [03/20/12 07:51:46.925]:Active Directory PT:Applying command transformation policies.
- [03/20/12 07:51:46.925]:Active Directory PT:Applying policy: %+C%14Cpub-ctp-UserNameMap%-C.
- [03/20/12 07:51:46.925]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.925]:Active Directory PT: Evaluating selection criteria for rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:51:46.925]:Active Directory PT: (if-class-name not-equal "User") = TRUE.
- [03/20/12 07:51:46.926]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.926]:Active Directory PT: Applying rule 'consider user objects when name mapping is enabled'.
- [03/20/12 07:51:46.926]:Active Directory PT: Action: do-break().
- [03/20/12 07:51:46.926]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.926]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.927]:Active Directory PT:Applying policy: %+C%14Cpub-ctp%-C.
- [03/20/12 07:51:46.927]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.927]:Active Directory PT: Evaluating selection criteria for rule 'set cached context value on merge'.
- [03/20/12 07:51:46.927]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:51:46.927]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.927]:Active Directory PT: Evaluating selection criteria for rule 'Set Equivalent To Me when adding object to a group'.
- [03/20/12 07:51:46.927]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:51:46.928]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.928]:Active Directory PT: Evaluating selection criteria for rule 'Remove Equivalent To Me when removing object from a group'.
- [03/20/12 07:51:46.928]:Active Directory PT: (if-class-name equal "Group") = FALSE.
- [03/20/12 07:51:46.928]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.928]:Active Directory PT: Evaluating selection criteria for rule 'remove managed attributes when object disassociated'.
- [03/20/12 07:51:46.928]:Active Directory PT: (if-operation equal "remove-association") = FALSE.
- [03/20/12 07:51:46.928]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.929]:Active Directory PT: Evaluating selection criteria for rule 'Prevent unassociated users from being removed from groups'.
- [03/20/12 07:51:46.929]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:51:46.929]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.929]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.929]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.930]:Active Directory PT:Applying XSLT policy: %+C%14Cpub-cts%-C.
- [03/20/12 07:51:46.930]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.930]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.931]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Default Password Policy%-C.
- [03/20/12 07:51:46.931]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.931]:Active Directory PT: Evaluating selection criteria for rule 'On User add, provide default password of @Dirxml1 if no password exists'.
- [03/20/12 07:51:46.931]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:51:46.931]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.931]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.932]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.932]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Check Password GCV%-C.
- [03/20/12 07:51:46.932]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.932]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to Identity Manager data store when adding a object'.
- [03/20/12 07:51:46.932]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:51:46.933]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.933]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the Identity Manager data store'.
- [03/20/12 07:51:46.933]:Active Directory PT: (if-global-variable 'enable-password-publish' equal "false") = FALSE.
- [03/20/12 07:51:46.933]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.933]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.933]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.934]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish Distribution Password%-C.
- [03/20/12 07:51:46.934]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.934]:Active Directory PT: Evaluating selection criteria for rule 'Add nspmDistributionAttribute attribute to add operation'.
- [03/20/12 07:51:46.934]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:51:46.935]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.935]:Active Directory PT: Evaluating selection criteria for rule 'Change modify-password operations to a modify'.
- [03/20/12 07:51:46.935]:Active Directory PT: (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
- [03/20/12 07:51:46.935]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.935]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.935]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.936]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Publish NDS Password%-C.
- [03/20/12 07:51:46.936]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.936]:Active Directory PT: Evaluating selection criteria for rule 'Block publishing passwords to NDS password'.
- [03/20/12 07:51:46.936]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:51:46.936]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.936]:Active Directory PT: Evaluating selection criteria for rule 'Block sending modify-password changes to the NDS password'.
- [03/20/12 07:51:46.937]:Active Directory PT: (if-global-variable 'publish-password-to-nds' equal "false") = FALSE.
- [03/20/12 07:51:46.937]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.937]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.937]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.937]:Active Directory PT:Applying policy: %+C%14CPassword(Pub)-Add Password Payload%-C.
- [03/20/12 07:51:46.938]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.938]:Active Directory PT: Evaluating selection criteria for rule 'Add operation-data element to password operations'.
- [03/20/12 07:51:46.938]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:51:46.938]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:51:46.938]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:51:46.938]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:51:46.938]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.939]:Active Directory PT: Evaluating selection criteria for rule 'Add payload data to password operations'.
- [03/20/12 07:51:46.939]:Active Directory PT: (if-operation equal "addPayloadToPassword") = FALSE.
- [03/20/12 07:51:46.939]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:51:46.939]:Active Directory PT: (if-operation equal "modify-password") = FALSE.
- [03/20/12 07:51:46.939]:Active Directory PT: (if-operation equal "modify") = FALSE.
- [03/20/12 07:51:46.939]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.939]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.939]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.940]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-WriteAccountsOnAdds-pub-ctp-V1%-C.
- [03/20/12 07:51:46.940]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.940]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard policy if disabled'.
- [03/20/12 07:51:46.940]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:51:46.941]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.941]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - on add operation add Dirxml-Accounts'.
- [03/20/12 07:51:46.941]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:51:46.941]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.941]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.941]:Active Directory PT:
- <nds dtdversion="2.2">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <input>
- <status level="success" type="heartbeat"/>
- </input>
- </nds>
- [03/20/12 07:51:46.942]:Active Directory PT:Filtering out notification-only attributes.
- [03/20/12 07:51:46.942]:Active Directory PT:Pumping XDS to eDirectory.
- [03/20/12 07:51:46.942]:Active Directory PT:Performing operation status for .
- [03/20/12 07:51:46.942]:Active Directory PT:
- DirXML Log Event -------------------
- Driver: \EDIR2ADLAB\fdny\AD-TEST\Active Directory
- Channel: Publisher
- Status: Success
- [03/20/12 07:51:46.943]:Active Directory PT:Fixing up association references.
- [03/20/12 07:51:46.943]:Active Directory PT:Applying schema mapping policies to output.
- [03/20/12 07:51:46.943]:Active Directory PT:Applying policy: %+C%14Csmp%-C.
- [03/20/12 07:51:46.943]:Active Directory PT:Applying output transformation policies.
- [03/20/12 07:51:46.943]:Active Directory PT:Applying policy: %+C%14Cotp%-C.
- [03/20/12 07:51:46.943]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.944]:Active Directory PT: Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:51:46.944]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.944]:Active Directory PT: Applying rule 'Street Address: Convert LF to CR-LF'.
- [03/20/12 07:51:46.944]:Active Directory PT: Action: do-reformat-op-attr("streetAddress",token-replace-all("[^\r]\n","\r\n",token-local-variable("current-value"))).
- [03/20/12 07:51:46.944]:Active Directory PT: Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:51:46.944]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.945]:Active Directory PT: Applying rule 'logonHours: Convert to Active Directory form'.
- [03/20/12 07:51:46.945]:Active Directory PT: Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
- [03/20/12 07:51:46.945]:Active Directory PT: Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
- [03/20/12 07:51:46.945]:Active Directory PT: (if-op-attr 'accountExpires' changing) = FALSE.
- [03/20/12 07:51:46.945]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.945]:Active Directory PT: Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:51:46.946]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.946]:Active Directory PT: Applying rule 'lockoutTime: Convert to Active Directory form'.
- [03/20/12 07:51:46.946]:Active Directory PT: Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateEpoch2FileTime($current-value)")).
- [03/20/12 07:51:46.946]:Active Directory PT: Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
- [03/20/12 07:51:46.946]:Active Directory PT: (if-operation equal "add") = FALSE.
- [03/20/12 07:51:46.946]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.947]:Active Directory PT: Evaluating selection criteria for rule 'update Active Directory logon name'.
- [03/20/12 07:51:46.947]:Active Directory PT: (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
- [03/20/12 07:51:46.947]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.947]:Active Directory PT: Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:51:46.947]:Active Directory PT: (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = TRUE.
- [03/20/12 07:51:46.947]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.948]:Active Directory PT: Applying rule 'Exchange: Remove HomeMDB when disabled'.
- [03/20/12 07:51:46.948]:Active Directory PT: Action: do-strip-op-attr("homeMDB").
- [03/20/12 07:51:46.948]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.948]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:51:46.948]:Active Directory PT:Applying policy: %+C%14CPassword(Sub)-Pub Email Notifications%-C.
- [03/20/12 07:51:46.949]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.949]:Active Directory PT: Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
- [03/20/12 07:51:46.949]:Active Directory PT: (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
- [03/20/12 07:51:46.949]:Active Directory PT: (if-operation equal "status") = TRUE.
- [03/20/12 07:51:46.949]:Active Directory PT: (if-xpath true "self::status[@level != 'success']/operation-data/password-publish-status") = FALSE.
- [03/20/12 07:51:46.949]:Active Directory PT: Rule rejected.
- [03/20/12 07:51:46.950]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.950]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:51:46.950]:Active Directory PT:Applying policy: %+C%14Clib-CredProv-ConvertPayload-otp-V1%-C.
- [03/20/12 07:51:46.950]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.950]:Active Directory PT: Evaluating selection criteria for rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:51:46.951]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.951]:Active Directory PT: Applying rule 'Is credential provisioning enabled? Are there any custom payloads?'.
- [03/20/12 07:51:46.951]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.951]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.951]:Active Directory PT: (if-global-variable 'credprov.enable' not-equal "true") = TRUE.
- [03/20/12 07:51:46.951]:Active Directory PT: Performing if actions.
- [03/20/12 07:51:46.952]:Active Directory PT: Action: do-break().
- [03/20/12 07:51:46.952]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.952]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:51:46.952]:Active Directory PT:Applying policy: %+C%14Clib-AccountTracking-Subscribe-otp-V1%-C.
- [03/20/12 07:51:46.952]:Active Directory PT: Applying to status #1.
- [03/20/12 07:51:46.952]:Active Directory PT: Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:51:46.953]:Active Directory PT: Rule selected.
- [03/20/12 07:51:46.953]:Active Directory PT: Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
- [03/20/12 07:51:46.953]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.953]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.953]:Active Directory PT: (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
- [03/20/12 07:51:46.953]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.953]:Active Directory PT: Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
- [03/20/12 07:51:46.954]:Active Directory PT: arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
- [03/20/12 07:51:46.954]:Active Directory PT: token-global-variable("drv.acctTrk.objectClass")
- [03/20/12 07:51:46.954]:Active Directory PT: Token Value: {"user"}.
- [03/20/12 07:51:46.954]:Active Directory PT: Arg Value: {"user"}.
- [03/20/12 07:51:46.954]:Active Directory PT: Performing actions for local-variable(current-node) = "user".
- [03/20/12 07:51:46.955]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.955]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.955]:Active Directory PT: (if-class-name equal "$current-node$") = FALSE.
- [03/20/12 07:51:46.955]:Active Directory PT: Performing else actions.
- [03/20/12 07:51:46.955]:Active Directory PT: Action: do-if().
- [03/20/12 07:51:46.955]:Active Directory PT: Evaluating conditions.
- [03/20/12 07:51:46.955]:Active Directory PT: (if-local-variable 'pass' not-available) = TRUE.
- [03/20/12 07:51:46.956]:Active Directory PT: Performing if actions.
- [03/20/12 07:51:46.956]:Active Directory PT: Action: do-break().
- [03/20/12 07:51:46.956]:Active Directory PT:Policy returned:
- [03/20/12 07:51:46.956]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:51:46.956]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:51:46.957]:Active Directory PT:Remote Interface Driver: Sending...
- [03/20/12 07:51:46.957]:Active Directory PT:
- <nds dtdversion="3.5" ndsversion="8.x">
- <source>
- <product version="3.6.10.4747">DirXML</product>
- <contact>Novell, Inc.</contact>
- </source>
- <output>
- <status event-id="0" level="success"></status>
- </output>
- </nds>
- [03/20/12 07:51:46.957]:Active Directory PT:Remote Interface Driver: Document sent.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement