Commissioning for lack of Exchange because of the latency in Multi Site domain controllers

Hi all

I use using the OIM 11 g R2 PS2 BP04 with AD-connector version (11.1.1.6.0 & AD 2010) and the Version of the Exchange Connector (11.1.1.6.0 & Exchange 2010) and its installed on RHEL 6.5. We have 20:00 domain controllers and each of them is in a different site. Here is the list of domain controllers:

DC-host1,DC-HOST2,DC-site2-host1,DC-SITE3-host1,DC-SITE4-host1...etc

We use automatic configuration AD access strategies and resources the user Exchange and configured as domain controllers in AD IT resource:

DC-HOST1 - primary

DC-HOST2 - secondary

AD resource provisioning works fine however when IOM tries to configure exchange to the user, its failure due to the latency issue b & w AD different Site of the domain controller. For example, "PRODTESTUSER12" is implemented successfully in AD and when IOM tries to configure exchange for this user, exchange server search for any available domain controller search for the user. It randomly selects an AD domain controller, I say DC-SITE2-HOST1 to search for the user. Since this domain contorller is on another site and it is latency, its not able to find the user of this domain controller, this is why available exchange fails for this user. See the below error:

Target class = oracle.iam.connectors.icfcommon.prov.ICProvisioningManager

< 21 may 2015 23:10:06 CEST > < error > < ORACLE. IAM. CONNECTORS. ICFCOMMON. Prov. ICPROVISIONINGMANAGER > < BEA-000000 > < oracle.iam.connectors.icfcommon.prov.ICProvisioningManager: createObject: error while creating user

java.lang.RuntimeException: the operation could not be performed because the object 'PRODTESTUSER12' could not be found on 'anc-dc2k8 - 01.wssc.ad.root'.

We have not specified this domain either under AD controller or Exchange resources.

n Connector logs, I can see below:

22/05/2015-10:55:19 < INFORMATION >: class-> Org.IdentityConnectors.Exchange.RemoteRunspaceInstance-> InvokeScript method, Message-> enter the method


22/05/2015-10:55:19 < VERBOSE >: class-> Org.IdentityConnectors.Exchange.RemoteRunspaceInstance,-> InvokeScript method, Message-> Script: Set-ADServerSettings - ViewEntireForest: $true; Get-User "PRODTESTUSER21" - ReadFromDomainController

I think, because of this script, Exchange Server recovers first of any domain controller available to search for the user. Yes, is there a way to restrict or put domain controller's favorite?

There is a hotfix available for this problem. Here are the details:

Patch 19692488: APPLICATION of MERGER on top of 11.1.1.6.0 FOR the BUGS 18310438 19478076

Bugs resolved by this fix

UPDATED EXCHANGE CONNECTOR SMTP PRIMARY ADDRESS 16813315 PROBLEM

17949931 DELAY IN EXCHANGE / COMMISSIONING

19478076 WITH REGARD TO THE EXCHANGE OF SUPPLY FAILURES.

Concerning

Suren

Tags: Fusion Middleware

Similar Questions

  • What is the Kingdom of multi site profile

    Hi all

    What is an average of Kingdom to ATG? What is the role of the Kingdom in Multi site profile? I went through the docs of the ATG, but I was not able to understand the exact meaning.

    A profile can be associated with a site using profile Kingdom. that means him.

    Thank you

    TT

    Trade Oracle ATG Web - profile realms, it looks like realms of profile allow you to have a single account for multiple sites or allow you to have an account for a group of sites, but not another.

    For example, if you have 3 sites (electronic website, clothing and kitchen utensils Site), you can create a profile named welcome the Kingdom of goods Kingdom that has electronic Site and kitchen utensils and a Kingdom called Kingdom of clothes clothing Site containing profile. If a user creates an account on the website, the account will allow you to connect on the Site of kitchen utensils, but not the Site of clothing because the site of kitchenware is in the same domain and clothing is not. To connect on clothing, you need to create an account on a site in this area.

    Thank you

    Joe

  • How does the option of multi site

    I realize that Muse is not true "adapted" and you need to create a version for each platform, so how this work?

    Lets say I created a desktop, Tablet, and the mobile version of my site. How to publish the project so that all three versions are active and how he treats people visiting the site on these platforms. Typo www.acme.com via mobile phone, for example, will take me to the correct version or is at - it a transmission, a code injection should be done to take the visitor to the correct site or are the three versions actually three completely separate versions?

    Hi Christian,

    Versions for desktop, phone and Tablet for a single site will be in the same file of muse. So, if the site will be accessible on any device, it will be automatically identified and appropriate version will be displayed.

    Is attached a screenshot of the plan view to add the phone and tablet on the site.

    Kind regards

    Neha

  • SSRS for lack of outer join with the Oracle data source

    It seems to be a problem with the Oracle driver used in the Reporting SERVICES query designer.

    When you use an Oracle data source, if I create an outer join in the graphic designer, it automatically inserts '{OJ' before the join and '} ' after her.  This is an incorrect syntax for Oracle and refuses to start.  The curly braces and the JO editable in designer text, but if I go back to the graphic designer and immediately to reintegrate them.

    Only, this has started to happen a year or two ago - before that it worked, but with the old (+) syntax.

    Can it not be healed?  It makes things very difficult.

    -Geoff

    Hi Geoff,

    Thanks for posting in the Microsoft Community.

    However, the question you posted would be better suited in the Forums of the Oracle Support; We recommend that you post your query in Oracle Support Forums to get help:

    https://forums.Oracle.com/forums/main.jspa;JSESSIONID=8d92100c30d8fb401bcbd10b46c38c9ddf1a3242549a.e34SbxmSbNyKai0Lc3mPbhmSc3aNe0? CategoryID = 84

    If you have any other questions or you need Windows guru, do not hesitate to post your questions and we will be happy to help you.

  • Error message Windows Explorer.EXE for lack of certificate root when the computer is turned on

    After trying to download updates from Microsoft to start my computer displays this windows explorer.exe error message...
    C:\windows\sys32\vsinit.dll--Il you are missing a necessary root certificate.
    As a result of this error message, I noticed that can't copy or move existing document files to any drive.  If I try to open a file backup quicken computer program stops and I have to restart the computer.  I tried to download other updates of Microsoft but they do not have to install, based on the error message above.  I do not have the xp software disk has been loaded on the computer when you purchase through HP and I never created software XP backup discs.
    Any suggestions on how to fix the missing root certificate error message for this problem.  Appreciate the help, and thanks for your suggestions to solve this problem.

    Hi ronjul2,

    Thank you for visiting the website of Microsoft Windows Vista Community. The question you have posted is related to a third party of program, ZoneAlarm, installed on your computer.  Try to uninstall and reinstall the software.  For more information about this error, you can visit the Support of ZoneAlarm.

    Using third-party software, including hardware drivers can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the use of third-party software can be solved. Software using third party is at your own risk.

    Please let us know if this helped.

    Dena
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Gap phone build for iOS is not because of the WhitelistPlugin

    Hello

    My version of iOS is a failure due to an error in com.indigoway.cordova.whitelist.WhitelistPlugin. The amount of the fine for Android build.

    All points will be a great help.

    In file included from /project/edumerge/Plugins/com.indigoway.cordova.whitelist.WhitelistPlugin/CDVNavigationWhitelistPlugin.m:20: /project/edumerge/Plugins/com.indigoway.cordova.whitelist.WhitelistPlugin/CDVNavigationWhitelistPlugin.h:23:9: fatal error: 'Cordova/CDVURLRequestFilter.h' file not found #import <Cordova/CDVURLRequestFilter.h> ^ 

    https://build.PhoneGap.com/apps/672738/logs/iOS/build/

    Thank you

    Rajat

    It would be a good time to read the documentation of BMPS Plugins section.

    It would be

    In addition, you will find all the instructions if you please google "npmjs cordova-plugin-whitelist. This is probably the first or second shot of Google.

  • Download optimized photos we three iOS devices is blocked probably for lack of storage space on the device.

    I transferred my photo library 47 000 iMac to iCloud. It took nearly a week, then downloaded iCloud all optimized to my iPhone photos 6 and iPad. My wife's phone has however only uploaded 20 000 photos and seems stuck. Remaining storage is equal to zero. the file of the photo and the camera is 8.4 GB on 11. We have removed all but essential applications.

    There were several thousand photos on his phone before the download starts.

    I tried to load his camera on pictures and it shows 2240 photos that were imported to the pictures already. If I could remove these, it could open enough space on the phone to continue and complete the download and optimization.

    Disable iCloud photo library before removing all the pictures, then turn it back on.

  • Extend the L2 VLAN multi-site WAN

    Hello

    I have several sites connected over a MPLS network provider, everything works as expected, have full connectivity L3 in all these sites.

    I now need to establish layer 2 connectivity (VLAN) on the 21 sites. Ideally, I would intend to attach additional routers behind routers of THIS (don't have no access to these suppliers or PEs, but provider may re - configure BGP on the CE peer with our device) and use a port on these routers as port Lan Layer 2, but do not know which technology to use

    1. L2TPv3 comes to mind, but can L2TPv3 works in a multipoint configuration? Can I have a site as a hub and others like rays and talk through the hub? Traditional using L2TPV3 config, how do I use multiple Xconnects for the same VLAN on the same interface?
    2. Worse, I can run on (also our new routers VPLS PEs) MPLS VPLS, but seems like overkill.

    What you guys say is the most simple/more elegant solution for this puzzle?

    L2TPv3 does not support multitouch.  It can perform point to point.

    VPLS does support multitouch, but you need much more expensive kit to do.

    I have just a brainwave!  You only use the IP protocol for this network of layer 2?  If so, use LISP.  It works on the same lower end kit of Cisco.  I would like to convert your entire network to him.

    In particular, you must activate the LISP mobility.

    General information of LISP:

    http://Lisp.Cisco.com/

    An example of an extension of the continuous complex layer 2 using LISP with full redundancy.  You don't want something this complex, but it shows what you want to do, and the massive power that LISP has.

    http://www.Cisco.com/c/en/us/TD/docs/solutions/Enterprise/Data_Center/DCI/5-0/LISPmobility/DCI_LISP_Host_Mobility/LISPmobile_4.html

  • Cannot install the update of security for Jscript 5.8 for Windows XP (KB971961), also tried the manual installation

    While were are at it, I have not been able to install this update, guard saying failed, and have also tried manual installation just in case you ask

    A security update for Jscript 5.8 for Windows XP (KB971961)

    See the section "How to get help" of http://support.microsoft.com/kb/971961

    Visit the Microsoft Solution Center and antivirus security for resources and tools to keep your PC safe and healthy.  If you have problems with the installation of the update itself, visit the Microsoft Update Support for resources and tools to keep your PC updated with the latest updates.

    Security customer includes home links page free security update support, too
    https://consumersecuritysupport.Microsoft.com/

    For more information about how to contact your local Microsoft subsidiary for security update support issues, visit the International Support Web site: http://support.microsoft.com/common/international.aspx

    For enterprise customers, support for security updates is available through your usual support contacts.

    ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • There is a problem with the driver for Ralink Bluetooth PCIe Adapter. The driver must be reinstalled error code 39.

    HP Pavilion 17 laptop

    There is a problem with the driver for Ralink Bluetooth PCIe Adapter. The driver must be reinstalled.

    OT: Driver help

    Name: PCIe Ralink Bluetooth adapter
    Error code: 39

    Hello

    Thanks for posting the query on the Microsoft Community Forums. You have reached the right place. Let us work together to find the cause of this problem and try to solve.

    What is the number of full model of the laptop?

    39 error code means Windows cannot load the driver for this hardware device. The driver may be corrupted or missing. To resolve the problem, you will need to uninstall and reinstall the drivers for Ralink Bluetooth PCIe card on the manufacturer's Web site.

    I hope this helps. Let us know if you have other problems with Windows in the future.

  • The Web of Toshiba site does not recognize of my drive hard number and P/N

    Hello

    There is a little less than two months, I bought my HDD Toshiba Canvio Basics 3.0 from Amazon. The hard drive has stopped working for some reason any (I drop or something, it simply stopped working).

    Of course, I was trying to use my warranty to repair or Exchange it, but the Web of Toshiba site does not recognize my serial number and product number. They are just there, black and white on the sticker on the back of my hard drive, but the site says they are not valid.

    Someone has an idea what is happening? I would rather not throw 50 euros by the window for less than two months of use.

    Product number is HDTB105XK3AA - and not to HDTB105 * E * K3AA like some sites say (including Amazon).

    Thanks for your help.

    Stand by. Have you contacted Amazon using Amazon options for repair under warranty or Exchange?

    Check please help Amazon option and collect detailed information on defective, damaged or significantly different returns.

    Two years ago I had problem with the mobile phone bought by Amazon and I send direct Amazon with bill Amazon.

    By the way: can you please post the link where you have tried to check the serial number of your HARD drive?

  • Remove 1 of the 3 domain controllers in a Windows environment

    I have a Windows domain that has Windows 2003 and 2008 R2 servers to support workstations, SharePoint and exchange among other things. There are 3 domain controllers. The first domain controller created on window 2003 server. Later, more 2 domain controllers were added on Windows 2008 R2. During the promotion of each of the servers in DC, each of them were activated as DNS and Global catalog servers. In addition, both 2008 DHCP configuration on them were servers and one Server 2008 R2 is configured as primary and the second as the secondary. The 2003 is just a DC member. I made main hold all 5 FSMO roles and replication works as well on both servers.
    I now have to demote the first Windows Server 2003, and then it must be taken out of the area. But whenever I have to run DCPromo to demote the server he kept a message that no other DC cannot be contacted, and when I try to disable the NIC in Server 2003, replication will stop automatically on the two 2008 R2.

    Any help please.
    Thanks in advance.

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • It is only five years, since I bought the MBP. And "not Stopped Apple hardware support for this products just because they sell it?

    Hello

    I have a 17-inch, mid 2010 MBP.

    The internal DVD drive is broken.

    I contacted the Support of Apple. And sheet metal tech me that "Apple does not support any material for the MBP.» And what I can do is to get an "external DVD drive.

    It is only five years, since I bought the MBP. And "not Stopped Apple hardware support for this products just because they sell it?

    Ed

    < re-titled by host >

    If your computer is on this list it is no longer supported: Vintage and obsolete products - Apple Support

  • How can you get an iTunes card code goes through which is stuck on a peel off sticker and I don't have the receipt for refund or Exchange

    How can I get a card code iTunes pass go throu that is stuck on a peel off sticker and I don't have the receipt for refund or Exchange

    You can try to contact iTunes support, they are likely to want to see images of the front and back of the card, and they might also want to see a picture of the reception (you looked for the reception?): https://www.apple.com/emea/support/itunes/contact.html

  • Is my office empty (on Server 2008 R2) because of the lack of activation of Windows?

    I installed the Server 2008 R2 in October (the 5th, to be more precise) and then Exchange 2010. Apparently I forgot either activate or enter a valid license key (I don't remember that far back) and now the machine starts at the standard login screen Ctrl-Alt-Delete, but once I connect (creds Admin, but not the local administrator account) the screen is empty except for three lines of text in the lower right :

    Windows Server 2008 R2 Enterprise Edition

    Build 7601

    This copy of Windows is not genuine.

    Although there is no Explorer shell and no icons, I can Ctrl-Alt-Del and start the Task Manager. I tried to use "slmgr-rearm' (and almost every option slmgr) by using a command prompt, but nothing happens." I tried to run slui.exe but nothing happens.

    Any help to get this machine would be appreciated.

    Hello

    Your question Windowss is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please post your question in the Technet Forums. You can follow the link to your question:

Maybe you are looking for