03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Ensure that Domino is using the LDAP protocol and users are listed in the<br />

directory and can be found under the right suffixes. Domino provides a<br />

command-line search utility that allows you to use LDAP to search entries in the<br />

Domino Directory on a server that runs the LDAP service, or search entries in a<br />

third-party LDAP directory.<br />

This tool is included in the Domino server and Notes client software.<br />

Note: To use the ldapsearch tool for searching against a Domino Directory,<br />

the LDAP task in the Domino Server must be started and the notes.ini file<br />

must be included in the machine system’s Path environment variable where<br />

ldapsearch will be executed.<br />

To search for wasadmin user in Domino LDAP, issue the following command<br />

at the command prompt:<br />

ldapsearch -v -h “uid=wasadmin”<br />

Configuring <strong>WebSphere</strong> to use Domino LDAP<br />

To configure <strong>WebSphere</strong> to use Domino as its user registry, follow the steps<br />

below.<br />

1. Start the <strong>WebSphere</strong> Administrator’s Console.<br />

2. Expand the tree <strong>Security</strong> -> User Registries -> LDAP. You will see the<br />

LDAP configuration panel open in the main window.<br />

3. Fill in the following configuration settings:<br />

– Server User ID: this field must contain the value specified in the Short<br />

Name/User ID field in the Person Document of the Domino Directory<br />

created in the steps above for the <strong>WebSphere</strong> administrator; tis is the user<br />

ID that will have to be used for login to start the <strong>WebSphere</strong><br />

Administrator’s Console once security is enabled, for example: wasadmin.<br />

– Server User Password: enter the Internet password set for the wasadmin<br />

user in this document.<br />

– Type: Domino<br />

– Host: name for the Domino (directory) server, for example: dominosrv<br />

– Port: 389<br />

– Base Distinguished Name: this is the base distinguished name of the<br />

directory service, indicating the starting point for LDAP searches of the<br />

directory service. As we defined all our users and groups under /ITSO, we<br />

have entered o=itso for this field.<br />

464 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!