Troubleshooting the Identity Server and Authentication
15
349
n
ov
do
cx (e
n)
16
Ap
ril 20
10
15
Troubleshooting the Identity
Server and Authentication
This section discusses the following topics:
Section 15.1, “Useful Networking Tools for the Linux Identity Server,” on page 349
Section 15.2, “Troubleshooting 100101043 and 100101044 Liberty Metadata Load Errors,” on
page 349
Section 15.3, “Authentication Issues,” on page 357
Section 15.4, “Problems Reading Keystores after Identity Server Re-installation,” on page 360
Identity Server logging information can be found in
Section 14.3, “Configuring Component
Logging,” on page 320
and
Section 14.4, “Configuring Session-Based Logging,” on page 323
.
15.1 Useful Networking Tools for the Linux
Identity Server
You can use the following tools (Linux and open source) to troubleshoot network problems:
netstat:
Displays information related to open ports on your server. Lets you view listeners and
various IP addresses, such as the TCP output state.
iptables:
Allows you to change the default ports (8080 and 8443) to the standard ports (80 and
443) for HTTP traffic. See
Section 1.5, “Translating the Identity Server Configuration Port,” on
page 36
.
netcat:
A networking utility that reads and writes data across network connections, using the
TCP/IP protocol. Netcat is useful for checking connectivity with the user store.
ldapsearch:
An LDAP search tool useful for the Administration Console and Identity Server.
For example, you can generate an LDAP search/bind matching what the Identity Server sends,
to confirm whether an issue is with the Identity Server JAR files.
tcpdump:
A command line tool for monitoring network traffic. Captures and displays packet
headers and matches them against a set of criteria.
LDAP Browser/Editor:
Lets you export configuration information to a file, and to confirm
that Access Manager objects and attribute values are valid in an AccessManagerContainer. A
number of open source versions are available from the Internet.
15.2 Troubleshooting 100101043 and 100101044
Liberty Metadata Load Errors
The Identity Server is the identity provider for the other Access Manager components. The Access
Gateways, ESP-enabled SSL VPN servers, and J2EE Agents have Embedded Service Providers.
When a device is imported into the Administration Console and an Identity Server configuration is
selected for them, a trusted relationship is established with the Identity Server by using test
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...