none
PCNS: How to debug? RRS feed

  • Question

  • Hi Guys,

    I have PCNS installed on 2008, and via it and the MAs defined in FIM RC1, I'm able to synchronise successfully with Live@edu (cloud service). What I am struggling with though is that I'm not able to synchronise with an iPlanet destination. No errors are being reported, the iPlanet MA is selected as an additional target in the AD MA, but the nett result is the password is just not propegating despite the Event Log on the relevant domain controller stating it managed to successfully push to all target MAs.

    Is there a way to turn on some kind of logging to see in detail what PCNS is trying to do, and possibly how far it's getting? I'm not talking about debugging, as I'm just not skilled enough in coding anymore to do that efficiently. I'm talking about logging. Does PCNS have it, or not?

    Cheers,
    Lain
    Thursday, December 17, 2009 8:25 AM

Answers

  • Nevermind. After going through the FIM UI again, in particular the AD MA, I noticed there's actually an option that governs this exact settings (under Configure Directory Partitions > Targets button > Changes in a 24hr period) that was selected. Removing the check from this checkbox resolved the issue.

    Cheers,
    Lain
    • Marked as answer by Lain Robertson Friday, December 18, 2009 12:48 AM
    Friday, December 18, 2009 12:48 AM

All replies

  • I stand corrected about there being no errors, though I'm none the wiser for finding this one. The domain controllers report success, but it appears as though the password reset requests are queueing up on the FIM server. Why? I don't know. These are the eventlog details:

    Source: FIMSynchronizationService
    Event ID: 6917
    Task Category: Password Synchronization

    Details:
    A password notification was received but was not processed because the maximum number of changes for this connector space object in a 24-hour period has been reached.
     
    Additional information:
    Reference ID: {4D66F660-31E3-4A72-9737-BD4385657FF0}
    Source Object GUID: {D2D44402-7B8E-40DE-B13A-CAE7AE105C6E}
    Source DN: CN=Indianapolis Jones,OU=Users,OU=Students,OU=Notre Dame,DC=nd,DC=edu,DC=au
    Source MA Name: AD - Students
    Maximum changes: 5
    Current change: 13

    I have no idea where to go from here. As I say, this is all fine for the Outlook Live MA, just iPlanet is causing me grief. To the inexperienced layman that I am, it sounds like the iPlanet MA isn't even trying to send the password to the LDAP service.

    Cheers,
    Lain
    Thursday, December 17, 2009 9:04 AM
  • Okay, perhaps let me ask the question differently: Has anyone been able to get password synchronisation flowing into the "Sun and Netscape directory services" MA to work? (In FIM 2010 RC1, of course)

    All I have is an error which has nothing to do with the cause of the problem, only indicating the result of it.

    Cheers,
    Lain
    Friday, December 18, 2009 12:33 AM
  • Nevermind. After going through the FIM UI again, in particular the AD MA, I noticed there's actually an option that governs this exact settings (under Configure Directory Partitions > Targets button > Changes in a 24hr period) that was selected. Removing the check from this checkbox resolved the issue.

    Cheers,
    Lain
    • Marked as answer by Lain Robertson Friday, December 18, 2009 12:48 AM
    Friday, December 18, 2009 12:48 AM