Status

FunctionalityDeprecated (if favor of SSH Connector)
Support statusSupported
Support provided byEvolveum
OriginEvolveum
Target systemsMicrosoft Windows Server 2012R2
NotesOnly scripting operations are supported

Description

Specialized connector that provides PowerShell scripting capabilities.


Protocol

Win-RS (WS-MAN)

Framework

ConnId 1.5.x

Bundle name

com.evolveum.polygon.connector.powershell

Connector name

com.evolveum.polygon.connector.powershell.PowerShellConnector

Capabilities and Features

SchemaNO

Provisioning

NO


Live Synchronization

NO


Password

NO


Activation

NO


Paging support

NO


Native attribute namesNO


ScriptingYESCommand execution and Powershell by using WinRM (WS-MAN)

History

This connector was "separated" from Active Directory Connector (LDAP) version 2.4.

Versions

This connector is part of the LDAP Connector bundle. It is distributed together with LDAP Connector and eDirectory Connector.

Version

Origin

Binary

Sources

Build Date

ConnId
Framework
Bundled with midPoint

Description

1.0Evolveum

download jar

GitHub

3 Apr 20201.5.0.0None

Initial version.
Separated from AD connector version 2.4

1.1Evolveum

download jar

GitHub

21 July 20201.5.0.0None

Option to disable certificate checks.

1.1.1Evolveum

download jar

GitHub

6 August 20201.5.0.0None

Fixing disableCertificateChecks: allowing FQDN and CN mismatch.

Interoperability

Following versions of Windows servers are supported:

This connector is deprecated. The Win-RM services proved to be very problematic and unstable while using this connector. Fortunatelly, recent Windows servers have an option to install SSH servers. Use of SSH instead of Win-RM is strongly recommended. Please use SSH Connector instead of this connector whenever possible.

Connector is supported only in Java 11 environment.

MS Exchange Interoperability

Technically, this connector can be used to provision Microsoft Exchange servers in a indirect way by using PowerShell scripts.

Firstly, the Exchange attributes are accessible in Active Directory when the Exchange software is installed. The Active Directory Connector (LDAP) is needed to manage those attributes.

Secondly, this connector can be used to execute powershell scripts remotely using the WinRM interface. This feature can be used to manage Exchange mailboxes and additional settings. Please see Powershell Support in AD/LDAP Connector page for more details.

However, support for MS Exchange is not  included in standard support for this connector (see below).

Support

This connector was deprecated in favor of SSH Connector.

This connector is still supported (but it is not bundled with midPoint support, it has to be purchased separately). However, there are limitations:

Licensing

The connector itself is available under the terms of Apache License 2.0.  We are not using any Microsoft library or any other component that might be subject to Microsoft licensing. To our best knowledge no extra license is needed to use the connector with Windows servers. However the Microsoft license texts are not entirely clear and we are not lawyers. Therefore it is recommended for each user to make his own analysis of the licensing issues. Please use your Microsoft support program and contact Microsoft with the licensing question when in doubt.

Resource Examples

See Also