Oracle Internet Directory is an LDAP compliant user directory. To my surprise I recently found out that it does not remove membership attributes from groups when users get disabled. This is at least true for the version 10.1.4.3. I am not sure if the behavior is different in the 11g version. This became an issue for us because the IT security department wanted to ensure that memberships were removed when users were disabled. Our solution was to basically create a plug-in and register the plug-in with OID. Oracle Identity Management Application Developers Guide located here provides detailed information on how to extend the behavior of OID. This document has sections for building custom plug-ins and their deployment. I used their JAVA API to build this plug-in. Before I start sharing some code, here is some general information about the plug-in. 1. The plug-in will get executed whenever OID performs a modify operation. 2. The plug-in will determin...
Keeping me and perhaps you up to date with focus on technology