Overview of LDAP Sync Tool

The IRM server includes a command-line LDAP synchronization tool. You can add the command to a script to schedule routine synchronization.

NOTE: At least one manual sync must be performed on a given directory before using the LDAP synchronization tool on that directory for the first time.

Using the LDAP Sync Tool

The LDAP sync command line tool (imldapsync) uses LDAP credentials that are encrypted with a Windows account (user or machine scope), or an IRM System Admin Group user account, and stored. The stored credentials are then used along with the cluster name, library name, and directory root trustee sync ID, to perform the synchronization.

To run LDAP Sync Tool, a user must be a member of the System Admin Group. For more information about this group, and how to add users to the group, refer to Create and Manage Users.

Storing accounts to be used (for encryption of LDAP credentials and) to run LDAP sync

Use the imldapsync and -storeaccounts parameter to prompt for and store account information with user-level encryption, without running an LDAP sync.

  1. On the command line, browse to \iManage RM Library Manager\rmserver\bin\win\rmserver\bin\win.

  2. Execute the following command type:
    imldapsync -cluster <cluster name> -storeaccounts -connection <ldap connection name> -pwmode [user | machine] -ldapcurrentaccount

    where

    •  -pwmode user restricts access to the specified Windows account.
      TIP: If a non-elevated account, such as a service account is specified, the synchronization can be performed using that account through the runas command.

    •  -pwmode machine provides access to accounts that can sign in to the current machine.

    •  -ldapcurrentaccount is an optional parameter. When added, LDAP connections will be attempted with the active (currently authenticated) Windows account. When storing credentials this way, there's no prompt for LDAP credentials. There's also no prompt upon loading. This negates the need for reconfiguration when the Windows password for the user account is changed.

      • Example command using this parameter:
        imldapsync -cluster <cluster name> -storeaccounts -connection <ldap connection name> -pwmode user -ldapcurrentaccount

  3. (Unless -ldapcurrentaccount is selected) You're then prompted to enter:

    • IRM admin domain

    • IRM admin ID

    • IRM admin password

    • LDAP account

    • LDAP password

    • And if -pwmode user is specified:

      • Windows account domain

      • Windows account ID

      • Windows account password

    A success message is displayed.

You can now use the stored account to run LDAP synchronization.

Performing LDAP synchronization

You can run or schedule routine LDAP synchronization with the LDAP sync tool, using the account(s) stored.

  1. The sync ID of the root-level LDAP node, that is, the directory root trustee sync id is required to perform synchronization. To obtain this, select the root node of an imported LDAP tree. The root node has an L icon.

  2. Select Action.

  3. Select Edit. 

  4. In the Edit Trustee dialog, select the Synchronization Status tab. Records Manager Sync ID is displayed and is selectable for copying.

  5. Copy Records Manager Sync ID. You can now use the imldapsync command-line tool to perform synchronization.

  6. On command line, browse to \iManage RM Library Manager\rmserver\bin\win.

  7. Execute the following command type:
    imldapsync -cluster <cluster name> -syncid <directory root trustee sync id (GUID)> -loadaccounts -ldapcurrentaccount

    where

    • <directory root trustee sync id (GUID)> is Records Manager Sync ID copied in Step 5.

    • -ldapcurrentaccount is an optional parameter which (when stored) will attempt to connect to LDAP with the active (currently authenticated) Windows account, without prompt. For more information about storing the active user account, refer to Step 2 of Storing accounts to be used (for encryption of LDAP credentials and) to run LDAP sync.

    The synchronization runs. If required, you can verify synchronization.