Previous Topic: Configure the Agent to Return Group Membership to WebLogic Server Using Agent Configuration Parameters

Next Topic: SiteMinder User Directory Not Configured in Identity Manager Environment (Use DMS API)

SiteMinder User Directory Configured in Identity Manager Environment

In this set up, you must have CA Identity Manager (licensed separately) installed and configured. The Policy Server user store must be associated with a CA Identity Manager environment. Then, configure the SMAdminUserName, SMAdminUserPassword, and SmUserDirectory parameters in the SiteMinder Agent Configuration Object.

Note: Verify that the CA Identity Manager smjavasdk2.jar library is included in the classpath; the SiteMinder Agent uses it to query CA Identity Manager.

We recommend that you set these parameters centrally in the Agent Configuration Object using the Administrative UI because the SiteMinder administrator password cannot be encrypted in the WebAgent.conf file. Using this interface, you can encrypt this password in the Agent Configuration Object stored in the policy store.

Note: The following procedure provides an overview of the steps required to create the required policy objects with appropriate parameter settings. For detailed procedural information, see the Policy Server Configuration Guide.

To modify the Agent Configuration Object in the Policy Store

  1. Open the SiteMinder Administrative UI.
  2. Open the Agent Configuration Object that you want to modify.
  3. Add the following SiteMinder administrator parameters:

Parameter Name

Value

Description

SMAdminUserName

 

SiteMinder administrator user name

 

User name of the Administrator with full permissions to manage all SiteMinder domain objects and users.

SMAdminUserPassword

Encrypted password

Encrypted Administrator password

  1. Add the following CA Identity Manager environment parameter:

Parameter Name

Value

Description

SMUserDirectory

IMS, IMS_environ

 

(IMS means CA Identity Manager.)

IMS_environ is the name of the CA Identity Manager environment.

For example:

IdentityManagerEnv

Note: Because SmUserDirectory can be a multivalued parameter, you can configure more than one user directory in the Agent Configuration Object. You can use multiple parameters to declare more than one DMS configuration or CA Identity Manager environment.

  1. Restart the WebLogic Server for configuration changes to take effect. Reboot this server because the SmUserDirectory parameter is not dynamic.


Copyright © 2010 CA. All rights reserved. Email CA about this topic