13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Ensure that Domino is using the LDAP protocol and users are listed in thedirectory and can be found under the right suffixes. Domino provides acommand-line search utility that allows you to use LDAP to search entries in theDomino Directory on a server that runs the LDAP service, or search entries in athird-party LDAP directory.This tool is included in the Domino server and Notes client software.Note: To use the ldapsearch tool for searching against a Domino Directory,the LDAP task in the Domino Server must be started and the notes.ini filemust be included in the machine system’s Path environment variable whereldapsearch will be executed.To search for wasadmin user in Domino LDAP, issue the following commandat the command prompt:ldapsearch -v -h “uid=wasadmin”Configuring <strong>WebSphere</strong> to use Domino LDAPTo configure <strong>WebSphere</strong> to use Domino as its user registry, follow the stepsbelow.1. Start the <strong>WebSphere</strong> Administrator’s Console.2. Expand the tree <strong>Security</strong> -> User Registries -> LDAP. You will see theLDAP configuration panel open in the main window.3. Fill in the following configuration settings:– Server User ID: this field must contain the value specified in the ShortName/User ID field in the Person Document of the Domino Directorycreated in the steps above for the <strong>WebSphere</strong> administrator; tis is the userID that will have to be used for login to start the <strong>WebSphere</strong>Administrator’s Console once security is enabled, for example: wasadmin.– Server User Password: enter the Internet password set for the wasadminuser in this document.– Type: Domino– Host: name for the Domino (directory) server, for example: dominosrv– Port: 389– Base Distinguished Name: this is the base distinguished name of thedirectory service, indicating the starting point for LDAP searches of thedirectory service. As we defined all our users and groups under /ITSO, wehave entered o=itso for this field.464 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!