T l Identity Manager - .Configure the. base. ... Configuring SSL authentication for the LDAP adapter

  • View
    212

  • Download
    0

Embed Size (px)

Text of T l Identity Manager - .Configure the. base. ... Configuring SSL authentication for the LDAP adapter

  • Tivoli Identity Manager

    LDAP Adapter Installation and Configuration Guide

    Version 4.6

    SC32-1754-00

  • Tivoli Identity Manager

    LDAP Adapter Installation and Configuration Guide

    Version 4.6

    SC32-1754-00

  • Note: Before using this information and the product it supports, read the information in Appendix B, Notices, on page 37.

    Second Edition (November 2006)

    This edition applies to version 4.6 of this adapter and to all subsequent releases and modifications until otherwise indicated in new editions.

    Copyright International Business Machines Corporation 2006. All rights reserved. US Government Users Restricted Rights Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.

  • Contents

    Preface . . . . . . . . . . . . . . . v Who should read this book . . . . . . . . . v Publications and related information . . . . . . v

    Tivoli Identity Manager library . . . . . . . v Prerequisite product publications . . . . . . vii Related publications . . . . . . . . . . viii Accessing publications online . . . . . . . viii

    Accessibility . . . . . . . . . . . . . . viii Support information . . . . . . . . . . . viii Conventions used in this book . . . . . . . . ix

    Typeface conventions . . . . . . . . . . ix Operating system differences . . . . . . . . ix Definitions for HOME and other directory variables . . . . . . . . . . . . . . ix

    Chapter 1. Overview of the LDAP adapter . . . . . . . . . . . . . . . 1 Features of the adapter . . . . . . . . . . . 1 Architecture of the adapter . . . . . . . . . 1 Supported configurations . . . . . . . . . . 2

    Chapter 2. Installing and configuring the LDAP adapter . . . . . . . . . . . . 3 Software and operating system requirements . . . 3 Installing the LDAP adapter . . . . . . . . . 3 Importing the adapter profile into the IBM Tivoli Identity Manager server . . . . . . . . . . 4 Creating an LDAP service . . . . . . . . . . 5 Starting and stopping the adapter service . . . . . 6

    Chapter 3. Configuring the LDAP adapter . . . . . . . . . . . . . . . 9 Customizing the LDAP adapter profile . . . . . 9 Standard parameters . . . . . . . . . . . 10 Standard attributes . . . . . . . . . . . . 11 Configuration properties of the adapter . . . . . 11 Customizing operations for the directory server . . 12

    Suspending user accounts . . . . . . . . 12 Restoring user accounts . . . . . . . . . 13 Searching for user accounts . . . . . . . . 13 Change the RDN attribute for the group account 13 Add support for a new user/group object class 14 Configure the base points . . . . . . . . . 14 Add support for a new directory server . . . . 14

    Changing the port number for the RMI Dispatcher 14 Configuring logging for the adapter . . . . . . 14

    Naming the log file . . . . . . . . . . . 15 Sizing the log file . . . . . . . . . . . 15 Configuring logging levels . . . . . . . . 15 Displaying logs in the user interface . . . . . 15 Appending information to an existing log file . . 16

    Managing passwords when restoring accounts . . . 16

    Chapter 4. Configuring SSL authentication for the LDAP adapter . . 17 Overview of SSL and digital certificates . . . . . 17

    Private keys, public keys, and digital certificates 18 Self-signed certificates . . . . . . . . . . 18

    The use of SSL authentication . . . . . . . . 19 Configuring certificates for SSL authentication . . . 20

    Configuring certificates for one-way SSL authentication . . . . . . . . . . . . 20 Configuring certificates for two-way SSL authentication . . . . . . . . . . . . 22

    Chapter 5. Verifying the LDAP adapter profile installation . . . . . . . . . . 25

    Chapter 6. Troubleshooting the LDAP adapter installation . . . . . . . . . 27 Warning and error messages . . . . . . . . . 27 Logging information format . . . . . . . . . 29

    Chapter 7. Uninstalling the LDAP adapter . . . . . . . . . . . . . . 31

    Appendix A. Support information . . . 33 Searching knowledge bases . . . . . . . . . 33

    Search the information center on your local system or network . . . . . . . . . . . 33 Search the Internet . . . . . . . . . . . 33

    Contacting IBM Software Support . . . . . . . 33 Determine the business impact of your problem 34 Describe your problem and gather background information . . . . . . . . . . . . . 35 Submit your problem to IBM Software Support 35

    Appendix B. Notices . . . . . . . . . 37 Trademarks . . . . . . . . . . . . . . 38

    Index . . . . . . . . . . . . . . . 41

    Copyright IBM Corp. 2006 iii

  • iv IBM Tivoli Identity Manager: LDAP Adapter Installation and Configuration Guide

  • Preface

    This installation guide provides the basic information that you need to install and configure the IBM Tivoli Identity Manager Lightweight Directory Access Protocol Adapter (LDAP adapter). The LDAP adapter enables connectivity between the IBM Tivoli Identity Manager server and a system running the directory server. The IBM Tivoli Identity Manager server is the server for your Tivoli Identity Manager product.

    Who should read this book This book is intended for directory server security administrators responsible for installing software on their sites computer systems. Readers are expected to understand operating system concepts. The person completing the LDAP adapter installation procedure must also be familiar with their sites system standards. Readers should be able to perform routine security administration tasks.

    Publications and related information Read the descriptions of the IBM Tivoli Identity Manager library. To determine which additional publications you might find helpful, read the Prerequisite product publications on page vii and the Related publications on page viii. After you determine the publications you need, refer to the instructions in Accessing publications online on page viii.

    Tivoli Identity Manager library The publications in the technical documentation library for your product are organized into the following categories: v Release information v Online user assistance v Server installation and configuration v Problem determination v Technical supplements v Adapter installation and configuration

    Release Information:

    v Release Notes Provides software and hardware requirements for the product, and additional fix, patch, and other support information.

    v Read This First card Lists the publications for the product.

    Online user assistance:

    Provides online help topics and an information center for administrative tasks.

    Server installation and configuration:

    Provides installation and configuration information for the product server.

    Copyright IBM Corp. 2006 v

  • Problem determination:

    Provides problem determination, logging, and message information for the product.

    Technical supplements:

    The following technical supplements are provided by developers or by other groups who are interested in this product: v Performance and tuning information

    Provides information needed to tune your production environment, available on the Web at: http://publib.boulder.ibm.com/tividd/td/tdprodlist.html Click the I character in the A-Z product list to locate IBM Tivoli Identity Manager products. Click the link for your product, and then browse the information center for the Technical Supplements section.

    v Redbooks and white papers are available on the Web at: http://www.ibm.com/software/sysmgmt/products/support/IBMTivoliIdentityManager.html Browse to the Self Help section, in the Learn category, and click the Redbooks link.

    v Technotes are available on the Web at: http://www.redbooks.ibm.com/redbooks.nsf/tips/

    v Field guides are available on the Web at: http://www.ibm.com/software/sysmgmt/products/support/Field_Guides.html

    v For an extended list of other Tivoli Identity Manager resources, search the following IBM developerWorks Web address: http://www.ibm.com/developerworks/

    Adapter installation and configuration:

    The technical documentation library also includes a set of platform-specific installation documents for the adapter components of the product. Adapter information is available on the Web at:

    http://www.lotus.com/services/passport.nsf/WebDocs/Passport_Advantage_Home

    Click Support & downloads. Browse to the Downloads and drivers. Click the link for the adapter.

    Skills and training:

    The following additional skills and technical training information were available at the time that this manual was published: v Virtual Skills Center for Tivoli Software on the Web at:

    http://www.cgselearning.com/tivoliskills/ v Tivoli Education Software Training Roadmaps on the Web at:

    http://www.ibm.com/software/tivoli/education/eduroad_prod.html v Tivoli Technical Exchange on the Web at:

    vi IBM Tivoli Identity Manager: