4.2 Creating the Role and Resource Service Driver in iManager

To create and configure the Role and Resource Service driver in iManager:

  1. Open iManager in a Web browser.

  2. Go to Roles and Tasks > Identity Manager Utilities and select Import Configuration.

    Install the User Application driver before installing the Role and Resource Service driver. Use Version 3.7.0 of the User Application driver (UserApplication_3_7_0-IDM3_6_0-V1.xml) with the Role and Resource Service driver. If you use a different version of the User Application driver, the Roles and Resources Catalogs might not be available.

  3. In the wizard, keep the default of In an existing driver set. Browse to your Driver Set created in Section 4.1, Creating the User Application Driver in iManager. Click Next.

    NOTE:The User Application Driver and the Role and Resource Driver should be in the same Driver Set.

  4. Select RoleResourceService_3_7_0-IDM3_6_0-V1.xml from the drop-down list. This is the Role and Resource Service driver configuration file that supports the Roles Based Provisioning Module.

    If this file is not in the list, the Roles Based Provisioning Module installer might be installed correctly.

    Click Next.

  5. Fill out the requested information in the Import Information Requested page. The following table describes the requested information.

    Option

    Description

    Driver Name

    Specify the driver name or keep the default name, Role and Resource Service, of the Role and Resource Service driver. If you install a new driver with the same name as an existing driver, the new driver overwrites the existing driver’s configuration.

    Use the Browse button to see the existing drivers on the selected driver set. This is a required field.

    User-Group base container DN

    The driver acts only on users, containers, and groups in this base container. If there are group role or resource assignments, the Role and Resource Service Driver only grants/revokes roles or resources on members within the domain of the container.

    User Application Driver DN

    The distinguished name of the User Application driver object that is hosting the role or resource system. Use the eDirectory format, such as UserApplication.driverset.org, or browse to find the driver object. This is a required field.

    User Application URL

    The URL used to connect to the User Application in order to start approval workflows. The example URL given is http://host:port/IDM. This is a required field.

    User Application Identity

    The distinguished name of the object used to authenticate to the User Application in order to start Approval Workflows. This can be a User Application Administrator to whom you are giving rights to administer the User Application portal. Use the eDirectory format, such as admin.department.org, or browse to find the user. This is a required field.

    User Application Password

    Password of the User Application Administrator specified in the Authentication ID. The password is used to authenticate to the User Application in order to start Approval Workflows. This is a required field.

    Reenter the Password

    Re-enter the password of the User Application Administrator.

  6. After the information is filled in, click Next.

  7. Click Define Security Equivalences to open the Security Equals window. Browse to and select an administrator or other Supervisor object, then click Add.

    This step gives the driver the security permissions it needs. Details about the significance of this step can be found in your Identity Manager documentation.

  8. (Optional, but recommended) Click Exclude Administrative Roles.

  9. Click Add, select users you want to exclude for driver actions (such as administrative roles), click OK.

  10. Click OK to close the Security Equals window, then click Next to display the summary page.

  11. If the information is correct, click Finish.