LDAP sync disables or deletes users at large scale

  • 7017443
  • 01-Apr-2016
  • 04-Dec-2017

Environment

Micro Focus Filr 3.0
Novell Filr 2.0
Novell Filr 1.2

Situation

On very large Filr systems with several thousand users registered via LDAP, users get disabled (default setting) or deleted (if enabled) during an LDAP sync. If disabled, a subsequent LDAP sync can re-enable these users but if deleted, a subsequent sync will re-create these users.

Resolution

A fix for this issue is available in the Filr 1.2 Hot Patch 5 / Filr 2.0 Hot Patch 1, available via the Novell Patch Finder.

Note: If you encounter this problem in Filr 3.x when using eDirectory as the LDAP directory, please contact Micro Focus Customer Care with reference to this TID. Your issue may be associated with the way eDirectory handles paged LDAP results.

Cause

This issue is caused if environmental conditions, such as a lost LDAP connection occurs at a very specific time during the LDAP sync process and a fix for this specific condition is available in Filr 1.2-HP5 and Filr 2.0-HP1 onwards including Filr 3.0.