When LDAP authentication components initialize themselves, they automatically perform a consistency check that reports on:
Mappings with invalid values:
LDAP group does not exist
Enterprise Security role or group does not exist
Enterprise Security role or group mapped to more than one LDAP group
Important roles within Enterprise Security that do not have mappings defined to the LDAP server: PortalAdmin, PortalSecOfficer, and PortalWebPlugin.
Do not disable consistency checker
Although you can disable the automatic invocation of the consistency
checker using a configuration parameter, Sybase strongly recommends
that you do not.
The warnings generated by the consistency checker are important in the operation of the LDAP replicator. Possible reasons for warnings include: the LDAP group cannot be found, an EP role or group cannot be found, or important EP roles are not correctly mapped to LDAP entities.
Warnings generated by the consistency checker are written to security.log, and usually contain sufficient information for an administrator to resolve the problem.