<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ILM2 RC0 Part 2 &#8211; Migrating configuration from ILM 2007</title>
	<atom:link href="http://www.wapshere.com/missmiis/ilm2-rc0-part-2-migrating-configuration-from-ilm-2007/feed" rel="self" type="application/rss+xml" />
	<link>http://www.wapshere.com/missmiis/ilm2-rc0-part-2-migrating-configuration-from-ilm-2007</link>
	<description>Adventures in identity management</description>
	<lastBuildDate>Tue, 07 Feb 2012 08:24:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Carol</title>
		<link>http://www.wapshere.com/missmiis/ilm2-rc0-part-2-migrating-configuration-from-ilm-2007/comment-page-1#comment-108</link>
		<dc:creator>Carol</dc:creator>
		<pubDate>Fri, 05 Jun 2009 08:33:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=289#comment-108</guid>
		<description>Thanks for posting this Bob - this looks like it may trip many people!</description>
		<content:encoded><![CDATA[<p>Thanks for posting this Bob &#8211; this looks like it may trip many people!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bob.bradley@unifysolutions.net</title>
		<link>http://www.wapshere.com/missmiis/ilm2-rc0-part-2-migrating-configuration-from-ilm-2007/comment-page-1#comment-107</link>
		<dc:creator>bob.bradley@unifysolutions.net</dc:creator>
		<pubDate>Fri, 05 Jun 2009 06:30:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=289#comment-107</guid>
		<description>Carol - I&#039;ve managed to solve my problem, and I expect there will be a lot more folks running into this one ...
The MIIS SP2 metaverse schema turned out to already have an attribute with the name objectSID, and when the ILM2 MA tries to update the metaverse schema with its own &quot;objectSid&quot; (lower case id) it throws the above (slightly misleading) error message.  What lead me to discover this was the BAIL error text which pointed to a &quot;Join: Invalid mv object type mv-object-type for element&quot;, which according to the MSDN doco (http://msdn.microsoft.com/en-us/library/ms698391(VS.85).aspx) indicated a schema mismatch.  I discovered the problem when I attempted to manually import the MV schema from a clean ILM2 image and got an error pointing to the existing (legacy) objectSID attribute.
There will be a lot of sites which use ILM/MIIS to populate ADLDS/ADAM instances with userProxyFull objects, as is the case here, which necessitates adding the objectSid to the metaverse.  If the ILM implementor happens to spell the attribute name in any way other than &quot;objectSid&quot; (i.e. matching case) it will fail with this error.</description>
		<content:encoded><![CDATA[<p>Carol &#8211; I&#8217;ve managed to solve my problem, and I expect there will be a lot more folks running into this one &#8230;<br />
The MIIS SP2 metaverse schema turned out to already have an attribute with the name objectSID, and when the ILM2 MA tries to update the metaverse schema with its own &#8220;objectSid&#8221; (lower case id) it throws the above (slightly misleading) error message.  What lead me to discover this was the BAIL error text which pointed to a &#8220;Join: Invalid mv object type mv-object-type for element&#8221;, which according to the MSDN doco (<a href="http://msdn.microsoft.com/en-us/library/ms698391(VS.85" rel="nofollow">http://msdn.microsoft.com/en-us/library/ms698391(VS.85</a>).aspx) indicated a schema mismatch.  I discovered the problem when I attempted to manually import the MV schema from a clean ILM2 image and got an error pointing to the existing (legacy) objectSID attribute.<br />
There will be a lot of sites which use ILM/MIIS to populate ADLDS/ADAM instances with userProxyFull objects, as is the case here, which necessitates adding the objectSid to the metaverse.  If the ILM implementor happens to spell the attribute name in any way other than &#8220;objectSid&#8221; (i.e. matching case) it will fail with this error.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bob.bradley@unifysolutions.net</title>
		<link>http://www.wapshere.com/missmiis/ilm2-rc0-part-2-migrating-configuration-from-ilm-2007/comment-page-1#comment-106</link>
		<dc:creator>bob.bradley@unifysolutions.net</dc:creator>
		<pubDate>Thu, 04 Jun 2009 08:09:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=289#comment-106</guid>
		<description>Carol
I&#039;m also at a site and getting the same error - but there are no &quot;Any&quot; join rules in this case.  However there are 2 instances of the OpenLDAP xMA on this server where the xMA itself has not been installed (and hence the Properties tab for this MA is greyed out).  I expect that as soon as I install the xMA it will allow me to create the ILM2 MA ...</description>
		<content:encoded><![CDATA[<p>Carol<br />
I&#8217;m also at a site and getting the same error &#8211; but there are no &#8220;Any&#8221; join rules in this case.  However there are 2 instances of the OpenLDAP xMA on this server where the xMA itself has not been installed (and hence the Properties tab for this MA is greyed out).  I expect that as soon as I install the xMA it will allow me to create the ILM2 MA &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carol</title>
		<link>http://www.wapshere.com/missmiis/ilm2-rc0-part-2-migrating-configuration-from-ilm-2007/comment-page-1#comment-78</link>
		<dc:creator>Carol</dc:creator>
		<pubDate>Tue, 20 Jan 2009 07:39:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=289#comment-78</guid>
		<description>An update on that postscript - I posted this to Microsoft Connect, and what an excellent service! I got a response back within hours. It turns out that RC0 does not support join rules to &quot;Any&quot;, but that this has been corrected in the final release version.

Apparently this was covered in the release notes ... I tried to read &#039;em, honest...</description>
		<content:encoded><![CDATA[<p>An update on that postscript &#8211; I posted this to Microsoft Connect, and what an excellent service! I got a response back within hours. It turns out that RC0 does not support join rules to &#8220;Any&#8221;, but that this has been corrected in the final release version.</p>
<p>Apparently this was covered in the release notes &#8230; I tried to read &#8216;em, honest&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

