Limitations in the synchronization of the LDAP directory server

Last Updated : Jun 26, 2018 |

You can expect the following results when you run the directory synchronization job or when the system runs the scheduled job.

Table 1: Synchronization from the LDAP directory server to System Manager

Action

Expected result

Synchronize users from multiple LDAP directory servers.

The system creates different datasources for each directory server.

The system supports the authentication of two directory servers, the RADIUS server and the KERBEROS server, at a given point of time.

Modify the user attributes that the LDAP directory server synchronizes.

If you add the attributes in mappings for the datasource, the system overwrites the attributes from the synchronization job.

Table 2: Synchronization from System Manager to the LDAP directory server

Action

Expected result

Create a user in System Manager from the User Management interface or by using the bulk import operation.

The system does not synchronize the user in the LDAP directory server.

Update the user attributes synchronized from the LDAP directory server in System Manager.

If you add the attributes in mappings for the datasource, the system updates the attributes in the LDAP directory server. You can synchronize only optional attributes from System Manager to the LDAP directory server.

Delete users in System Manager.

The system does not delete the user from the LDAP directory server. The Directory Synchronization feature does not support the soft deletion or permanent deletion of the user from the LDAP directory server.

From System Manager Release 8.0 and later, you can delete the Enterprise/LDAP user from the System Manager web console. However, if the user is still available in the LDAP directory server, the system synchronizes the user in System Manager even after you delete the user from System Manager on next synchronization job.