2. Prerequisites#

Before you install the OX Connector, make sure that your Nubus deployment and OX App Suite meet the prerequisites.

2.1. OX App Suite server#

The OX App Suite server must meet the following prerequisites:

  1. Installed OX App Suite instance

    You need an existing OX App Suite instance. The OX Connector doesn’t install, configure, or operate OX App Suite.

    For information about installing OX App Suite, see App Suite Admin Guide 7.10.6 [3].

  2. SOAP API access

    The OX App Suite instance must allow SOAP requests so that the OX Connector can access the /webservices endpoint in OX App Suite.

  1. OX App Suite administrator

    Set up an administrator user in OX App Suite who can create OX contexts. The OX Connector uses this user to manage OX contexts. In the connector configuration, enter the username and password for this user. For information about managing OX contexts manually, see App Suite Admin Guide 7.10.6 [3].

    For the OX Connector app in Univention App Center, use the settings OX_MASTER_ADMIN and OX_MASTER_PASSWORD.

    If OX Connector and OX App Suite run on separate UCS systems, retrieve the password from the /etc/ox-secrets/master.secret file on the UCS system that runs OX App Suite. Use oxadminmaster as the administrator username.

    For Nubus for Kubernetes, configure the OX administrator credentials in the Helm values for the OX Consumer.

    For manually managing OX contexts without the OX Connector, see Contexts.

  2. Duplicate display names

    Allow duplicate display names in OX App Suite. Add the lines in Listing 2.1 to the user.properties file.

    Listing 2.1 Allow duplicate display names in OX App Suite#
    com.openexchange.user.enforceUniqueDisplayName=false
    com.openexchange.folderstorage.database.preferDisplayName=false
    
  3. Group names

    OX App Suite must allow all group names that administrators can use in Nubus. Add the line in Listing 2.2 to the Group.properties file.

    Listing 2.2 Allow all group names in OX App Suite#
    CHECK_GROUP_UID_FOR_NOT_ALLOWED_CHARS=false
    

2.2. OX Connector app in Univention App Center#

The OX Connector app from Univention App Center needs the referential integrity overlay in the central LDAP directory.

The overlay keeps the Univention Directory Manager (UDM) objects that the OX Connector uses consistent. It also ensures that these UDM objects reference user objects correctly.

For details, see Referential Integrity in OpenLDAP Software 2.4 Administrator's Guide [4].

If you install the OX Connector app from Univention App Center on UCS Primary Directory Node, the app activates the referential integrity overlay. You don’t need to take further action.

If you install the OX Connector app from Univention App Center on a Nubus for UCS system role other than the UCS Primary Directory Node, run the commands in Listing 2.3 on the UCS Primary Directory Node with root privileges.

Listing 2.3 Activate the OpenLDAP referential integrity overlay on the UCS Primary Directory Node#
$ ucr set ldap/refint=true
$ service slapd restart

2.3. Nubus for Kubernetes#

On Nubus for Kubernetes, the OX Connector runs as the OX Consumer.

Before you install the OX Consumer, install the packaged integration for OX App Suite. Follow Load packaged integrations. The packaged integration installs the required LDAP schema in the Directory Service. It also adds the required customizations to the Management UI in Nubus for user accounts, user groups, and resources.

Before you install the packaged integration, ask the team that provides it for the container image details.

You need the registry name and the repository name. This documentation uses the following example values:

Registry:

artifacts.software-univention.de

Repository:

nubus/images/ox-extension

For details, see Univention Nubus - Customization and Modification Manual [5].