
Preparing the Applications and the J2EE Servers
77
n
ov
do
cx (e
n)
16
Ap
ril 20
10
series of queries, one for each group, to determine whether the user is currently a member. If
membership is not what it should be, the TAI synthesizes a modification of the individual group
object.
In the reverse direction, a similar optimization is applied, in which updates to the groupMembership
back reference attribute are combined into a single joint LDAP modification.
Implementing the Trust Association Interceptor Module
The TAI module is implemented in eDirectory, WebSphere Application Server, and Novell Access
Manager
Configuring eDirectory
Use the following configuration for eDirectory:
Place all application groups inside a container. For example,
ou=Groups,o=MyOrg
Create a wpstaibind user. For example, cn=wpstaibind,ou=Admins,ou=Services,o=MyOrg.
This user updates the LDAP groups for the TAI module. Assign the following rights to this
user:
Create and Modify rights to the ou=Groups,o=MP container.
Modify rights to the Membership attribute of all users under the user container.
Create a cn=wasadmins,ou=Groups,o=MyOrg group for all WebSphere Application Server
administrators.
NOTE:
The exact location of WebSphere Portal Server groups can change to a specific
application container below the ou=Groups,o=MyOrg container.
Configuring the WebSphere Application Server
Copy the following files to the
/usr/WebSphere/AppServer/lib
folder:
ldap.ja
r
utilities.jar
roller.ja
r
NOTE:
The
ldap.jar
and
utilities.jar
files are found in the Novell LDAP SDK, located at
LDAP Classes for Java (http://developer.novell.com/wiki/index.php/LDAP_Classes_for_Java)
.
To configure and enable the TAI module: .
1
Log in to the WebSphere Application Server Admin Console and go to Security / Global
Security.
2
Select
Authentication Mechanism > Authentication
.
3
Select
LTPA
.
4
Select
Trust Association
.
5
Enable the
enable trust association
check box.
6
Click
Apply
to save the changes.
Содержание Access Manager 3.1 SP 2
Страница 4: ...4 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 8: ...8 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 44: ...44 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...
Страница 83: ...Preparing the Applications and the J2EE Servers 83 novdocx en 16 April 2010...
Страница 108: ...108 Novell Access Manager 3 1 SP2 J2EE Agent Guide novdocx en 16 April 2010...