<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IMC UAM 7.2 LDAP sync issue in IMC</title>
    <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6853873#M2890</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;So far I have not logged a case with HP but will do so.&lt;/P&gt;&lt;P&gt;Regarding the downgrade my problem is that although I have the 7.1 database backup however now 4 weeks passed and a lots of new users registered. If I downgrade I have to make sure that all newly registered users and their device mac addresses are transferred to 7.1. Now this seems to be a challenge because of several reasons:&lt;/P&gt;&lt;P&gt;1. Although IMC has a batch user export menu, in 7.2 GUI it has disappeared&lt;/P&gt;&lt;P&gt;2. Even if I can export new users, their device mac addresses cannot be exported/imported&lt;/P&gt;&lt;P&gt;I think here only a good SQL script could help that exports access and platform user accounts and their registered device mac addresses... If someone knows which tables to export/import please let me know.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Istvan&lt;/P&gt;</description>
    <pubDate>Tue, 26 Apr 2016 07:09:21 GMT</pubDate>
    <dc:creator>Istvan Hegedus</dc:creator>
    <dc:date>2016-04-26T07:09:21Z</dc:date>
    <item>
      <title>IMC UAM 7.2 LDAP sync issue</title>
      <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6853120#M2878</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After upgrading from IMC 7.0 to 7.2 (via 7.1 of course) I have faced a strange issue. Sometimes during the nightly LDAP synchronization IMC starts to remove users from Access User database like they are expired/non-existent users. It cancels the accounts. It doesn't happen always but when it happens I have to restore the database from previous backup. The same can be reproduced by manual syncing. Most of the times IMC synchronizes user attributes well, removes only those users which are inactivated in LDAP however rarely it happens that it removes most of the users (thousands of users). This causes BYOD users to re-register their devices.&lt;/P&gt;&lt;P&gt;Our LDAP server is&amp;nbsp;Solaris 10 (Sparc), directory proxy and Directory itself is ODSEE (Oracle Directory Server Enterprise Edition) 11.1.3.0.&lt;/P&gt;&lt;P&gt;Has anyone noticed this kind of problem? I do know that it did not exist with IMC 7.1 base version (no patches) however I don't know whether it was introduced by later 7.1 patches or by 7.2 version.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Istvan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 16:15:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6853120#M2878</guid>
      <dc:creator>Istvan Hegedus</dc:creator>
      <dc:date>2016-04-22T16:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: IMC UAM 7.2 LDAP sync issue</title>
      <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6853255#M2879</link>
      <description>&lt;P&gt;Not having that particular problem but a different (maybe related?) issue with&amp;nbsp;iMC_UAM_7.2_E0405 that forced &amp;nbsp;me to roll back to 7.1&lt;/P&gt;&lt;P&gt;Some 802 users would fail to authenticate with&amp;nbsp;E63117:&amp;nbsp;system&amp;nbsp;unknown&amp;nbsp;error. I noticed this within a short time of upgrading, so did not get to the autosync time for the LDAP db.&lt;/P&gt;&lt;P&gt;But could imagine a possible mode where user record is corrupted so that authentication would not occur and subesequent sync might remove the user, like canceleing or blacklisting perhaps?&lt;/P&gt;&lt;P&gt;A case was opened and escalated as other customers were preorted to be having "similar" issues - do not know which ones. That was about a month ago.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you logged a case with HPE?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 23:35:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6853255#M2879</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2016-04-22T23:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: IMC UAM 7.2 LDAP sync issue</title>
      <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6853873#M2890</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;So far I have not logged a case with HP but will do so.&lt;/P&gt;&lt;P&gt;Regarding the downgrade my problem is that although I have the 7.1 database backup however now 4 weeks passed and a lots of new users registered. If I downgrade I have to make sure that all newly registered users and their device mac addresses are transferred to 7.1. Now this seems to be a challenge because of several reasons:&lt;/P&gt;&lt;P&gt;1. Although IMC has a batch user export menu, in 7.2 GUI it has disappeared&lt;/P&gt;&lt;P&gt;2. Even if I can export new users, their device mac addresses cannot be exported/imported&lt;/P&gt;&lt;P&gt;I think here only a good SQL script could help that exports access and platform user accounts and their registered device mac addresses... If someone knows which tables to export/import please let me know.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Istvan&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 07:09:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6853873#M2890</guid>
      <dc:creator>Istvan Hegedus</dc:creator>
      <dc:date>2016-04-26T07:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: IMC UAM 7.2 LDAP sync issue</title>
      <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6854689#M2899</link>
      <description>&lt;P&gt;The&amp;nbsp;table &amp;nbsp;ead.tbl_acm_user seems to have some of what you want, for&amp;nbsp;the user, both ldap and MAC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;you might&amp;nbsp;also want to look at the&amp;nbsp;ead.tbl_acm_service table - looks like thats where the services the user is linked to are stored.&lt;/P&gt;&lt;P&gt;BTW if you haven't setup a backup server using the same license I'd recommend it. It can continue to do authentication when the main server is offline being upgraded&lt;/P&gt;&lt;P&gt;PS - I have not done an extract then restore using SQL so&amp;nbsp;my info is based on browsing the tables -&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 22:17:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6854689#M2899</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2016-04-27T22:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: IMC UAM 7.2 LDAP sync issue</title>
      <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6858873#M2941</link>
      <description>&lt;P&gt;Thanks for the hints. I will check it.&amp;nbsp;&lt;BR /&gt;Of course we have a stateless failover setup so the standby server takes over authentications however new users cannot register their devices for BYOD.&lt;/P&gt;&lt;P&gt;I have installed the latest UAM 7.2 E405P02 patch but the following day UAM process has been frozen so I had to restart it. I was expecting this patch cures at least this freezing (at least the release notes mention that too many transparent authentication request could cause database connectivity break and this has been fixed). I don't know whether LDAP sync will be any better with it, now I set the sync period to 7 days and cross my fingers each week that it goes well... but I have to downgrade to 7.1&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 14:23:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6858873#M2941</guid>
      <dc:creator>Istvan Hegedus</dc:creator>
      <dc:date>2016-05-12T14:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: IMC UAM 7.2 LDAP sync issue</title>
      <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6858916#M2943</link>
      <description>&lt;P&gt;&lt;SPAN&gt;UAM 7.2 E405P03 has been posted. However this has not fixed my problem.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does mention a fix for large LDAP syncs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 16:23:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6858916#M2943</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2016-05-12T16:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: IMC UAM 7.2 LDAP sync issue</title>
      <link>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6859350#M2950</link>
      <description>&lt;P&gt;Spent time with HP regarding the 802.1x issue I was having. This is a problem for me with mixed MAC and 802.1x on the same port.&lt;/P&gt;&lt;P&gt;User would authenticate once succesfully using 802.1x, register the MAC address as the account ID and then subsequently no longer authenticate with 802.1x&lt;/P&gt;&lt;P&gt;Problem is with mschapserverV2. There was lab code that seems to fix this issue that we tested. However next patch is probably a couple of months out.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 22:35:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-uam-7-2-ldap-sync-issue/m-p/6859350#M2950</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2016-05-13T22:35:53Z</dc:date>
    </item>
  </channel>
</rss>

