Changes in OpenDJ are detected using External Change Log (ECL) mechanism, similar mechanism to the one that was known as Retro Change Log in Sun Directory Servers. The ECL is presented as an LDAP subtree with base DN of cn=changelog. Each change is represented as an entry in that subtree and it remains in that subtree for few days.

Modified Identity Connector Framework (ICF) LDAP connector is recommended. The connector scans the cn=changelog subtree for new entries in regular intervals.

The connector is using a special user for accessing OpenDJ, e.g. uid=idm,ou=Administrators,dc=example,dc=com. The connector should not use the cn=directory manager superuser. Firstly, this is a best practice. Secondly, midPoint is itself making the changes to the directory tree during provisioning. We do not want to detect these changes in LDAP (as "echoes"), as it may cause loops in the business logic. Therefore connector is filtering out all changes made by this user. Therefore, this user should be dedicated to midPoint.

Recommended Connectors




OpenICF Generic LDAP connector

LDAP Connector

Need to use simulated activation (enabled/disable)

Resource Configuration

Please see the chapter on OpenDJ Installation and Configuration.

Connector Configuration

See LDAP Connector documentation.

Connector Configuration Example


    <!-- Configuration specific for the LDAP connector -->

    <!-- Generic ICF configuration -->






Resource Sample

Simple resource sample (Git master).

Advanced resource sample (Git master).


Check External Changelog Availability

ldapsearch -h localhost -p 1389 -D "uid=idm,ou=Administrators,dc=example,dc=com" -w secret -b "cn=changelog" "(objectclass=*)"

Check Replication Purge Delay

dsconfig -h localhost -p 4444 -D "cn=directory manager" -w secret -n get-replication-server-prop --provider-name "Multimaster Synchronization" --advanced --property replication-purge-delay -X

Change Replication Purge Delay

dsconfig -h localhost -p 4444 -D "cn=directory manager" -w secret -n set-replication-server-prop --provider-name "Multimaster Synchronization" --set replication-purge-delay:1d -X

Purging Changelog

There seems not be no better way than to manipulate the replication purge delay. Change the delay to 1s, wait and a second and then change it back to the original value.

Frequent Errors

Password Reset Privileges

LDAP: error code 50 - You do not have sufficient privileges to reset user passwords

This indicates that the connector user does not have privilege to reset users password. In OpenDJ this is a special privilege and the ACI setup is not enough to enable this. Make sure that the IDM LDAP user has the password-reset privilege, e.g.:

dn: uid=idm,ou=Administrators,dc=example,dc=com
uid: idm
ds-privilege-name: password-reset

Deployment Tips

