2. Prerequisites#
Before you install the OX Connector, make sure that your Nubus deployment and OX App Suite meet the prerequisites.
2.1. OX App Suite server#
The OX App Suite server must meet the following prerequisites:
Installed OX App Suite instance
You need an existing OX App Suite instance. The OX Connector doesn’t install, configure, or operate OX App Suite.
For information about installing OX App Suite, see App Suite Admin Guide 7.10.6 [3].
SOAP API access
The OX App Suite instance must allow SOAP requests so that the OX Connector can access the
/webservicesendpoint in OX App Suite.
OX App Suite administrator
Set up an administrator user in OX App Suite who can create OX contexts. The OX Connector uses this user to manage OX contexts. In the connector configuration, enter the username and password for this user. For information about managing OX contexts manually, see App Suite Admin Guide 7.10.6 [3].
For the OX Connector app in Univention App Center, use the settings
OX_MASTER_ADMINandOX_MASTER_PASSWORD.If OX Connector and OX App Suite run on separate UCS systems, retrieve the password from the
/etc/ox-secrets/master.secretfile on the UCS system that runs OX App Suite. Useoxadminmasteras the administrator username.For Nubus for Kubernetes, configure the OX administrator credentials in the Helm values for the OX Consumer.
For manually managing OX contexts without the OX Connector, see Contexts.
Duplicate display names
Allow duplicate display names in OX App Suite. Add the lines in Listing 2.1 to the
user.propertiesfile.com.openexchange.user.enforceUniqueDisplayName=false com.openexchange.folderstorage.database.preferDisplayName=false
Group names
OX App Suite must allow all group names that administrators can use in Nubus. Add the line in Listing 2.2 to the
Group.propertiesfile.CHECK_GROUP_UID_FOR_NOT_ALLOWED_CHARS=false
2.2. OX Connector app in Univention App Center#
The OX Connector app from Univention App Center needs the referential integrity overlay in the central LDAP directory.
The overlay keeps the Univention Directory Manager (UDM) objects that the OX Connector uses consistent. It also ensures that these UDM objects reference user objects correctly.
For details, see Referential Integrity in OpenLDAP Software 2.4 Administrator's Guide [4].
If you install the OX Connector app from Univention App Center on UCS Primary Directory Node, the app activates the referential integrity overlay. You don’t need to take further action.
If you install the OX Connector app from Univention App Center on a Nubus for UCS system role other than the UCS Primary Directory Node, run the commands in Listing 2.3 on the UCS Primary Directory Node with root privileges.
$ ucr set ldap/refint=true
$ service slapd restart
2.3. Nubus for Kubernetes#
On Nubus for Kubernetes, the OX Connector runs as the OX Consumer.
Before you install the OX Consumer, install the packaged integration for OX App Suite. Follow Load packaged integrations. The packaged integration installs the required LDAP schema in the Directory Service. It also adds the required customizations to the Management UI in Nubus for user accounts, user groups, and resources.
Before you install the packaged integration, ask the team that provides it for the container image details.
You need the registry name and the repository name. This documentation uses the following example values:
- Registry:
artifacts.software-univention.de- Repository:
nubus/images/ox-extension
For details, see Univention Nubus - Customization and Modification Manual [5].