B.1 Policies Required in the Publisher Command Transformation Set

The policies listed in the Password Synchronization Policy Name column must be present in the order listed. Also, they must be the last policies in the Publisher Command Transformation policy set.

Table B-1 Policies Required in the Publisher Command Transformation Set

Location in the Driver Configuration

Password Synchronization Policy Name

What the Policy Does

Publisher Command Transformation

Password(Pub)-Default Password Policy

Adds a default password to an Add object if the Add object does not already contain a password.

This policy and the Password(Sub)-Default Password Policy are the only policies that you can modify or remove. For password synchronization functionality to work properly, the other policies should be used without changes.

Password(Pub)-Check Password GCV

Checks the GCV to determine whether you have specified that Identity Manager accepts passwords from this connected system. If not, it strips out all password elements.

The name of the GCV is enable-password-publish, and the display name is Identity Manager accepts passwords from application.

Password(Pub)-Publish Distribution Password

Transforms the <password> element to the form that allows it to update the Universal password.

This policy references the following GCVs:

  • publish-password-to-dp

  • enforce-password-policy

Password(Pub)-Publish NDS Password

Allows the <password> element to go through if you have specified that the NDS password should be updated. If not, it strips out the <password> element.

This policy references the GCV named publish-password-to-nds.

Password(Pub)-Add Password Payload

Puts in payload data that is passed around in the engine for purposes of e-mail notification.