Previous Topic: Sample CA DSI Server Configuration with CIA Real-TimeNext Topic: Addressing Time Series Requirements


Obtain LDAP Configuration Values

The following CA LDAP Server values are required for the CA Compliance Manager interface installation procedure.

LPAR name or IP Address

Defines the name or IP address of the system running the CA LDAP Server.

Port number

Specifies the TCP/IP port that CA LDAP Server is using.

Example: 389

LDAP suffix

Specifies the values that let CA LDAP Server and CA Chorus for Security and Compliance Management communicate; these values identify the back-end.

Example: o=ca,c=us

Important! These values should have been obtained during installation of CA LDAP Server. If not, use the following procedure to obtain these values.

Follow these steps:

  1. Obtain LDAP status values by issuing the following command from a z/OS console:
    F LDAPRnn,STATUS
    

    CA LDAP Server displays the LDAP port and its status.

  2. Obtain LDAP back-end values by issuing the following command from a z/OS console:
    F LDAPRnn,BACKEND
    

    CA LDAP Server displays the LDAP suffix and current back-end values.

  3. Use the output to identify and record the values that you need for the installation.

Example: Sample Output from the STATUS Command

The following is an example of output from the STATUS command. This command shows the LDAP port.

Note: You need the field in bold to complete the installation.

ETLDP05I CA LDAP Server status: 928
          slapd            15.2012.0229
          libslapd         15.2012.0229
          libsi            15.2011.1104
          back_cmdc_utf    15.2012.0305
          libsqlite3       15.2012.0229
          libmapres        15.2012.0229
          CADCPP32         14.00.0000
          back_cmgr_utf    15.2012.0305
          libsqlite3       15.2012.0229
          libmapres        15.2012.0229
          DSNAOCLI         DSN0601
          Security Product ACF2 v15.0
          Debug Level      0
          Syslog Level     0
          Listeners        ldap://:1069 IP=(::):1069
                           ldap://:1069 IP=0.0.0.0:1069
          Enable Verify    No
          Auth Location    OS390
          Auth Source      CLIENT
          Auth Servers     none
          Auth Codeset     IBM-1047
          PT Appl Id       none
          PTReqr Id        none
          PTReqr PwFile    none
          Process ID File  "./conf/slapd.pid"
          Arguments File   "./conf/slapd.args"
          Max Threads      32
          Key Ring Name    none
          Cert Label       none
          Verify Clients   NEVER

Example: Sample Output from the BACKEND Command

The following is an example of output from the BACKEND command. This command shows you the LDAP suffix values that you need for the installation.

Note: You need the fields in bold to complete the installation.

ETLDP05I CA LDAP Server status: 935
      Status for cmgr_utf backend:
             suffix        o=cmgr,c=us
             DB Location   DSN0
             DB User       SYSADM1
             Tbl Qualifier CMGRQ1
             Policy DD     MAPDB
             Permit class  CIEM
             Permit entity CIEM
             DB Discovered Yes
             Adm Account   ADMACCOUNT
             Account Count 21
             Sec Control   SECCONTROL
             Control Count 15
             Adm Policy    ADMPOLICY
             Policy Count  21
             Adm Misc      ADMMISC
             Misc Count    19
             Obj Access    OBJACCESS
             Obj Acc Count 58
             Sys Access    SYSACCESS
             Sys Acc Count 20
             USS User      USSUSER
             User Count    32
             USS File      USSFILE
             File Count    32
             Header Delta  HDRDELTA
             Delta Count   13
             PDS Delta     PDSDELTA
             PDS Count     13
             List Delta    LSTDELTA
             List Count    26
             Single Delta  SNGDELTA
             Single Count  9
             Mulit Delta   MULDELTA
             Multi Count   4
             Chg Approval  CHGAPPROVED
             Chg App Count 10
      Status for cmdc_utf backend:
             suffix        o=cmdc,c=us
             DB DSN        DATACOM
             DB User       DCOMUSER
             Tbl Qualifier CMGRD1
             Policy DD     MAPDB
             Permit class  CIEM
             Permit entity CIEM
             DB Discovered Yes
             Adm Account   ADMACCOUNT
             Sec Control   SECCONTROL
             Adm Policy    ADMPOLICY
             Adm Misc      ADMMISC
             Obj Access    OBJACCESS
             Sys Access    SYSACCESS
             USS User      USSUSER
             USS File      USSFILE
             Header Delta  HDRDELTA
             Delta Count   13
             PDS Delta     PDSDELTA
             PDS Count     13
             List Delta    LSTDELTA
             List Count    26
             Single Delta  SNGDELTA
             Single Count  9
             Mulit Delta   MULDELTA
             Multi Count   4
             Chg Approval  CHGAPPROVED
             Chg App Count 10