OneIM SQLiteDatabasesConnector UserGuide
OneIM SQLiteDatabasesConnector UserGuide
One Identity Manager Native Database Connector User Guide for Connecting SQLite Databases
Updated - January 2020
Version - 8.1.2
Contents
Error handling 31
Help for the analysis of synchronization issues 31
About us 32
Contacting us 32
Technical support resources 32
Index 33
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases
3
1
With this native database connector, you can synchronize external databases with the One
Identity Manager database. One Identity Manager supports connecting to SQLite databases,
amongst others.
The native database connector cannot load any random external database system data
configuration. For example, custom data types and columns containing value list are not
currently supported.
The native database connection does not provide a project template for setting up
synchronization. You must create synchronization configuration components
(mappings, workflows, start up configurations ...) manually after the synchronization
project has been saved.
In the Synchronization Editor, external database tables and columns are referenced as
schema types and schema properties.
1. Install and configure a synchronization server and declare the server as Job server in
One Identity Manager.
2. Provide One Identity Manager users with the required permissions for setting up
synchronization and post-processing of synchronization objects.
3. Create a synchronization project with the Synchronization Editor.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 4
Native database connector for SQLite databases
Users and permissions for
synchronizing
In the synchronization with the database connectors, there are three use cases for mapping
synchronization objects in the One Identity Manager data model.
In the case of non-role-based login to One Identity Manager tools, it is sufficient to add one
system user in the DPR_EditRights_Methods permissions group. For detailed
information about system users and permissions groups, see the One Identity Manager
Authorization and Authentication Guide.
User Tasks
There are different steps required for role-based login, in order to equip One Identity
Manager users with the required permissions for setting up synchronization and post-
processing of synchronization objects.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 5
Native database connector for SQLite databases
Table 2: User and permissions groups for role-based login: Mapped as custom
target system
User Tasks
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 6
Native database connector for SQLite databases
User Tasks
Table 3: User and permissions groups for role-based login: Mapped as default
tables
User Tasks
Table 4: Users and permissions groups for role-based login: Mapped in custom
tables
User Tasks
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 7
Native database connector for SQLite databases
User Tasks
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 8
Native database connector for SQLite databases
Detailed information about this topic
1. In the Manager, select the default application role to use to edit the objects you want
to synchronization.
l Establish the application role's default permissions group.
If you want to import employee data, for example, select the Identity
Management | Employees | Administrators application role. The default
permissions group of this application role is vi_4_PERSONADMIN.
2. In the Designer, create a new permissions group.
l Set the Only use for role based authentication option.
3. Make the new permissions group dependent on the vi_4_SYNCPROJECT_ADMIN
permissions group.
The vi_4_SYNCPROJECT_ADMIN permissions groups must be assigned as the parent
permissions group. This means that the new permissions group inherits the
properties.
4. Make the new permissions group dependent on the default permissions group of the
selected default application role.
The default permissions group must be assigned as a subgroup. This means that the
new permissions group inherits the properties.
5. Save the changes.
6. In the Manager, create a new application role.
a. Assign the selected application role to be the parent application role.
b. Assign the new permissions group.
7. Assign employees to this application role.
8. Save the changes.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 9
Native database connector for SQLite databases
To set up an application role for synchronization (use case 3):
1. In the Designer, create a new permissions group for custom tables, which are
populated though synchronization.
l Set the Only use for role based authentication option.
2. Guarantee this permissions group all the required permissions to the custom tables.
3. Create another permissions group for synchronization.
l Set the Only use for role based authentication option.
4. Make the permissions group for synchronization dependent on the permissions group
for custom tables.
The permissions group for custom tables must be assigned as parent permissions
group. This means the permissions groups for synchronization inherits its properties.
5. Make the permissions group for synchronization dependent on the vi_4_
SYNCPROJECT_ADMIN permissions group.
The vi_4_SYNCPROJECT_ADMIN permissions groups must be assigned as the parent
permissions group. This means the permissions groups for synchronization inherits
its properties.
6. Save the changes.
7. In the Manager, create a new application role.
a. Assign the Custom | Managers application role as the parent
application role.
b. Assign the permissions group for the synchronization.
8. Assign employees to this application role.
9. Save the changes.
For detailed information about setting up application roles and permissions groups, see the
One Identity Manager Authorization and Authentication Guide.
The synchronization server must be declared as a Job server in One Identity Manager.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 10
Native database connector for SQLite databases
Use the One Identity Manager Service to install the Server Installer. The program executes
the following steps:
NOTE: To generate processes for the Job server, you need the provider, connection
parameters, and the authentication data. In the default case, this information is determ-
ined from the database connection data. If the Job server runs through an application
server, you must configure extra connection data in the Designer. For detailed inform-
ation about setting up Job servers, see the One Identity Manager Configuration Guide.
NOTE: The program executes remote installation of the One Identity Manager Service.
Local installation of the service is not possible with this program. Remote installation is
only supported within a domain or a trusted domain.
To remotely install the One Identity Manager Service, you must have an
administrative workstation on which the One Identity Manager components are
installed. For detailed information about installing a workstation, see the One Identity
Manager Installation Guide.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 11
Native database connector for SQLite databases
NOTE: You can use the Extended option to make changes to other properties
for the Job server. You can also edit the properties later with the Designer.
4. On the Machine roles page, select Job server.
5. On the Server functions page, select Native database connector.
6. On the Service Settings page, enter the connection data and check the One Identity
Manager Service configuration.
NOTE: The initial service configuration is predefined already. If further changes
need to be made to the configuration, you can do this later with the Designer. For
detailed information about configuring the service, see the One Identity Manager
Configuration Guide.
l For a direct connection to the database:
a. Select Process collection | sqlprovider.
b. Click the Connection parameter entry, then click the Edit button.
c. Enter the connection data for the One Identity Manager database.
l For a connection to the application server:
a. Select Process collection, click the Insert button and select
AppServerJobProvider.
b. Click the Connection parameter entry, then click the Edit button.
c. Enter the connection data for the application server.
d. Click the Authentication data entry and click the Edit button.
e. Select the authentication module. Depending on the authentication
module, other data may be required, for example, user and password.
For detailed information about the One Identity Manager authentication
modules, see the One Identity Manager Authorization and
Authentication Guide.
7. To configure remote installations, click Next.
8. Confirm the security prompt with Yes.
9. On the Select installation source page, select the directory with the install files.
10. On the Select private key file page, select the file with the private key.
NOTE: This page is only displayed when the database is encrypted.
11. On the Service access page, enter the service's installation data.
l Computer: Name or IP address of the server that the service is installed and
started on.
l Service account: User account data for the One Identity Manager Service.
l To start the service under the NT AUTHORITY\SYSTEM account, set
the Local system account option.
l To start the service under another account, disable the Local system
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 12
Native database connector for SQLite databases
account option and enter the user account, password and password
confirmation.
l Installation account: Data for the administrative user account to install
the service.
l To use the current user’s account, set the Current user option.
l To user another user account, disable the Current user option and enter
the user account, password and password confirmation.
l To change the install directory, names, display names or description of the One
Identity Manager Service, use the other options.
12. Click Next to start installing the service.
Installation of the service occurs automatically and may take some time.
13. Click Finish on the last page of the Server Installer.
NOTE: In a default installation, the service is entered in the server’s service
management with the name One Identity Manager Service.
Data Explanation
Synchronization All One Identity Manager Service actions are executed against
server the target system environment on the synchronization server.
Data entries required for synchronization and administration
with the One Identity Manager database are processed by the
synchronization server.
Installed components:
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 13
Native database connector for SQLite databases
Data Explanation
Base object You cannot normally specify a base object for synchronizing with
database connectors. In this case, assignment of one base table
and the synchronization server is sufficient.
l Select the Base table from the menu in which to load the
objects. The base table can be used to defined
downstream processes for synchronization. For more
information about downstream processes, see the One
Identity Manager Target System Synchronization
Reference Guide.
l The Synchronization servers menu displays all Job
servers for which the Native database connector
server function is activated.
Variable set If you implement specialized variable sets, ensure that the start
up configuration and the base object use the same variable set.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 14
Native database connector for SQLite databases
To configure synchronization with the native database connector
2. Add mappings. Define property mapping rules and object matching rules.
3. Create synchronization workflows.
4. Create a start up configuration.
5. Define the synchronization scope.
6. Specify the base object of the synchronization.
7. Specify the extent of the synchronization log.
8. Run a consistency check.
9. Activate the synchronization project.
10. Save the new synchronization project in the database.
If you execute the project wizard in expert mode or directly from Synchronization Editor,
additional configuration settings can be made. Follow the project wizard instructions
through these steps.
1. Start the Launchpad and log on to the One Identity Manager database.
NOTE: If synchronization is executed by an application server, connect the
database through the application server.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 15
Native database connector for SQLite databases
3. On the System access page, specify how One Identity Manager can access the
target system.
l If access is possible from the workstation on which you started
Synchronization Editor, you do not need to make any settings.
l If access is not possible from the workstation on which you started
Synchronization Editor, you can set up a remote connection.
Enable the Connect using remote connection server option and select the
server to be used for the connection under Job server.
4. Select the database system to which you want to connect on the Select database
system page.
l Select SQLite.
5. Configure the system connection.
For more information, see Connecting a system to an SQLite database on page 17.
6. You can save the current configuration as a template on the Save configuration
page. When you reconnect to a database system of the same type, you can use this
configuration as a template.
l Click and enter the name and repository of the configuration file.
7. You can save the connection data on the last page of the system connection wizard.
l Set the Save connection locally option to save the connection data. This can
be reused when you set up other synchronization projects.
l Click Finish, to end the system connection wizard and return to the
project wizard.
8. On the One Identity Manager Connection tab, test the data for connecting to the
One Identity Manager database. The data is loaded from the connected database.
Reenter the password.
NOTE: If you use an unencrypted One Identity Manager database and have not
yet saved any synchronization projects to the database, you need to enter all
connection data again. This page is not shown if a synchronization project
already exists.
9. The wizard loads the target system schema. This may take a few minutes depending
on the type of target system access and the size of the target system.
10. Select a project template on the Select project template page to use for setting up
the synchronization configuration.
NOTE: The native database connector does not provide a default project template
for setting up synchronization. If you have created your own project template, you
can select it to configure the synchronization project. Otherwise, select Create
blank project.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 16
Native database connector for SQLite databases
11. Enter the general setting for the synchronization project under General.
Property Description
Script Language in which the scripts for this synchronization project are
language written.
Scripts are implemented at various points in the synchronization
configuration. Specify the script language when you set up an empty
project.
IMPORTANT: You cannot change the script language once the
synchronization project has been saved.
If you use a project template, the template's script language is
used.
Data Explanation
User account and User account and password used by the native database
password connector to log in to the external database. Make a user
account available with sufficient permissions.
1. Enter the connection parameters on the Database connection page. Enter all the
parameters required by the database connector to create a connection with the
selected database system.
l To enter additional system-specific information about the system connection,
click Advanced.
The database system connection is tested the moment you click Next.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 17
Native database connector for SQLite databases
2. Enter a display name and a unique identifier for the database connection on the
Describe the database page.
Property Description
Display name of Display name of the database for display in the One Identity
database Manager tools.
3. You can enter a file on the Load configuration page from which the connection
configuration can be loaded. This data is used in subsequent steps in the connection
wizard and can be modified there.
4. Select the time zone for the time zone data in the database on the page, Time zone
selection. The time zone is required to convert the time saved in the database into
the local time. The local time is displayed in the One Identity Manager tools.
5. You can specify additional connection settings on the Initializing page. Write a
script in the database syntax to specify number and date formats, language, and
data sort order, for example. This script is then executed every time you
connect the system.
6. The database schema is loaded on the Schema detection page. during which One
Identity Manager tries to identify a known schema.
l If a One Identity Manager schema is detected, the Fill in system
description completely option is displayed. If you only want allow read-only
access to the database, you can deactivate this option.
If the schema is loaded successfully, the next step in the sequence can be
carried out.
7. On the Extend key information page, specify columns for each table to be used as
unique keys for identifying objects.
NOTE:
l This page is only displayed if the schema of the external database there are
tables with no identifiable unique keys.
l Tables without unique keys are not used in the synchronization configuration.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 18
Native database connector for SQLite databases
Table 9: Defining unique keys
Property Description
Hide Specifies whether table are hidden if no settings have been changed.
unconfigured
tables
Column Button for editing column groups. Create a column group, if a unique
group key can only be made of a combination of more than one column.
l To create a column group, click Add
l To edit or remove an existing column group, click Edit or
remove
Property Description
Key name Column group identifier. Permitted characters are letters and under-
score. A virtual schema property is formed from the column group with
the name vrtColumnGroup<column group>.
Columns Columns included in the column group. Mark all the columns that
together make up the unique key.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 19
Native database connector for SQLite databases
8. You can enter information about object relations in the Define data relations page.
Property Description
Hide Specifies whether table are hidden if no settings have been changed.
unconfigured
tables
Target(s) Columns to which the reference refers. Enter table and column
names in the following syntax: [<schema>].<table name>.<column
name>. If a reference points to several column, enter the targets in a
comma delimited list. The target columns must be labeled as key
columns.
TIP: You can copy the column name of a referenced column using
the Copy fully qualified column names item in the context
menu and add this as a target.
Referential Specifies whether the referential integrity of the data in the target
integrity table has been tested.
enabled
9. You can enter additional schema information on the Complete schema page.
Property Description
Hide Specifies whether table are hidden if no settings have been changed.
unconfigured
tables
Revision Specifies whether the column contains the revision counter. The
counter data in this column form the comparison value for revision filtering.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 20
Native database connector for SQLite databases
Property Description
Sort criteria Specifies whether the value in this column represents the path in an
for object hierarchy. If this table’s objects are sorted by this column, it
hierarchies results in a list sorted in hierarchical order. This makes it possible to
resolve object dependencies. Only one column per table can be
marked as a sort criterion. An example is the CanonicalName column.
Scope Specifies whether the column can be used to form the reference
reference scope. Only one column per schema type can be labeled as the
reference scope.
Property Description
10. You can specify special operations for changing data in the external database on the
Define data operations page. This is only required, if the default operations
INSERT, UPDATE and DELETE cannot be used in the external database system.
Property Description
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 21
Native database connector for SQLite databases
Property Description
Strategy Description
11. The Extend target system schema page opens if you enable the Fill in system
description completely option on the Load schema page or make settings on the
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 22
Native database connector for SQLite databases
Define data operations page. You can add virtual schema properties to the target
system schema here. Use the virtual schema properties to provide additional data
for your own DML handling.
Property Description
Hide Specifies whether table are hidden if no settings have been changed.
unconfigured
tables
Schema Tables in the target system schema for which virtual schema proper-
ties can be added or exist already.
Related topics
Updating schemas
All the schema data (schema types and schema properties) of the target system schema
and the One Identity Manager schema are available when you are editing a synchronization
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 23
Native database connector for SQLite databases
project. Only a part of this data is really needed for configuring synchronization. If a
synchronization project is finished, the schema is compressed to remove unnecessary data
from the synchronization project. This can speed up loading the synchronization project.
Deleted schema data can be added to the synchronization configuration again at a later
point.
If the target system schema or the One Identity Manager schema has changed, these
changes must also be added to the synchronization configuration. Then the changes can be
added to the schema property mapping.
To include schema data that have been deleted through compressing and schema
modifications in the synchronization project, update each schema in the synchronization
project. This may be necessary if:
To edit a mapping
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 24
Native database connector for SQLite databases
Starting synchronization
Synchronization is started using scheduled process plans. A scheduled process plan is
added once a start up configuration is assigned to a schedule. Use schedules to define
executing times for synchronization.
NOTE: Synchronization can only be started if the synchronization project is enabled.
To execute synchronization regularly, configure, and activate the a schedule. You can also
start synchronization manually if there is no active schedule.
IMPORTANT: As long as synchronization is running, you must not start another
synchronization for the same target system. This applies especially, if the same
synchronization objects would be processed.
If you want to specify the order in which target systems are synchronized, use the start up
sequence to run synchronization. In a start up sequence, you can combine start up
configurations from different synchronization projects and specify the order of execution.
For detailed information about start up configurations, see the One Identity Manager Target
System Synchronization Reference Guide.
Analyzing synchronization
Synchronization results are summarized in the synchronization log. You can specify the
extent of the synchronization log for each system connection individually. One Identity
Manager provides several reports in which the synchronization results are organized under
different criteria.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 25
Native database connector for SQLite databases
3. Click in the navigation view toolbar.
Logs for all completed synchronization runs are displayed in the navigation view.
4. Select a log by double-clicking it.
An analysis of the synchronization is shown as a report. You can save the report.
l In the Designer, enable the DPR | Journal | LifeTime configuration parameter and
enter the maximum retention period.
This means, all memberships and assignments remain intact until the outstanding objects
have been processed.
Start target system synchronization to do this.
Related topics
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 26
Native database connector for SQLite databases
To create a target system type
Property Description
Display name Name of the target system type as displayed in One Identity Manager
tools.
Show in compli- Specifies whether the target system type for compliance rule wizard
ance rule wizard can be selected when rule conditions are being set up.
Text snippet Text snippets used for linking text in the compliance rule wizard.
NOTE: The connector must have write access to the target system in order to publish
outstanding objects that are being post-processed. That means, the Connection is
read-only option must no be set for the target system connection.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 27
Native database connector for SQLite databases
To publish outstanding objects
l For each table for which you want to publish outstanding objects, create a process,
which is triggered by the event HandleOutstanding and which executes the
provisioning of the objects. Use the AdHocProjection process function of the
ProjectorComponent process component. For detailed information about defining
processes, see the One Identity Manager Configuration Guide.
Publish The object is added in the target system. The Outstanding label
is removed for the object.
The method triggers the HandleOutstanding event. This runs a
target system specific process that triggers the provisioning
process for the object.
Prerequisites:
l The table containing the object can be published.
l The target system connector has write access to the target
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 28
Native database connector for SQLite databases
Icon Method Description
system.
l A custom process is set up for provisioning the object.
NOTE: By default, the selected objects are processed in parallel, which speeds up
execution of the selected method. If an error occurs during processing, the action is
stopped and all changes are discarded.
Bulk processing of objects must be disabled if errors are to be localized, which means the
objects are processed sequentially. Failed objects are named in the error message. All
changes that were made up until the error occurred are saved.
Related topics
l Memberships are saved in the target system as an object property in list form
(Example: List of user accounts in the Members property of an Active Directory group).
l Memberships can be modified in either of the connected systems.
l A provisioning workflow and provisioning processes are set up.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 29
Native database connector for SQLite databases
To allow separate provisioning of memberships
For each assignment table labeled like this, the changes made in One Identity Manager are
saved in a separate table. During modification provisioning, the members list in the target
system is compared to the entries in this table. This means that only modified
memberships are provisioned and the members list does not get entirely overwritten.
NOTE: The complete members list is updated by synchronization. During this process,
objects with changes but incomplete provisioning are not handled. These objects are
logged in the synchronization log.
You can restrict single provisioning of memberships with a condition. Once single provi-
sioning has been disabled for a table, the condition is deleted. Table that have had the
condition deleted or edited are marked with the following icon: . You can restore the
original condition at any time.
1. Select the auxiliary table for which you want to restore the condition.
2. Right-click on the selected row and select the Restore original values
context menu item.
3. Save the changes.
For more detailed information about provisioning memberships, see the One Identity
Manager Target System Synchronization Reference Guide.
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 30
Native database connector for SQLite databases
2
Error handling
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 31
Error handling
About us
About us
One Identity solutions eliminate the complexities and time-consuming processes often
required to govern identities, manage privileged accounts and control access. Our solutions
enhance business agility while addressing your IAM challenges with on-premises, cloud and
hybrid environments.
Contacting us
For sales and other inquiries, such as licensing, support, and renewals, visit
[Link]
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 32
About us
Index
I ndex
A R
application role 5 remote connection server 13
application role for synchronztion 9
S
B schema
base object 13 changes 23
shrink 23
D update 23
synchronization
database connector
start 25
native 4
synchronization analysis report 31
synchronization configuration 13, 15
J
synchronization log 25
Job server synchronization server 13
edit 10 configure 10
install 10
M Job server 10
membership
modify provisioning 29 T
target system synchronization
O table to assign 26
delete immediately 28
outstanding 26, 28 V
publish 28 variable set 13
outstanding object 26
W
P
workflow 13
provisioning
members list 29
One Identity Manager 8.1.2 Native Database Connector User Guide for
Connecting SQLite Databases 33
Index