Configuring the cn attribute

You can configure the cn attribute.

About this task

The Active Directory Adapter user account class contains the following attributes for the attribute cn defined in the Active Directory:
  • IBM Security Verify Governance common schema attribute cn
  • erADFullName.

The cn attribute is used on the account form, by default. The adapter processes the cn attribute in the user add, modify, and reconciliation operations. The adapter uses the registry key UseITIMCNAttribute to use either the cn or the erADFullName attribute. When the compliance alerts on IBM Security Verify Governance are enabled, avoid using the cn attribute on the account form. To use the erADFullName attribute, you must customize the account form and set the registry key UseITIMCNattribute.

When you set the registry key UseITIMCNAttribute to FALSE, the adapter uses the erADFullName attribute for the cn attribute defined in the Active Directory for the user add, modify, and reconciliation operations.

To use the erADFullName attribute on the account form, perform the following steps:

Procedure

  1. Add the erADFullName attribute to the user account form by customizing the Active Directory account form.
    For more information about customizing the user account form, see the IBM Security Verify Governance product documentation.
  2. Set the registry key UseITIMCNAttribute to FALSE by using the agentCfg utility.