Previous Topic: How to Configure the Directory Server as a Policy StoreNext Topic: Create the Policy Store


Point the Policy Server to the Directory Server

You point the Policy Server to the LDAP directory server so that the Policy Server has the necessary system information and administrative privileges to read and write information to the policy store.

To point the Policy Server to the directory server

  1. Run the following command from the Policy Server host system:
    smldapsetup status -hhost -pport -dAdminDN
    -wAdminPW -rroot -ssl1/0 -ccert
    
    -hhost

    Specifies the IP Address of the LDAP server host system.

    -pport

    Specifies the port on which the LDAP server is listening.

    -dAdminDN

    Specifies the name of an LDAP user with privileges to create LDAP schema in the LDAP directory server.

    ADAM or AD LDS: Specifies the full domain name, including the guid value, of the directory server administrator.

    Example: CN=user1,CN=People,CN=Configuration,CN,{guid}

    -wAdminPW

    Specifies the password for an LDAP user with privileges to create LDAP schema in the LDAP directory server.

    -rroot

    Specifies the DN location of the SiteMinder data in the LDAP directory.

    ADAM or AD LDS: Specifies the existing root DN location of the application partition in the ADAM or AD LDS server where you want to put the policy store schema data.

    -ssl1|0

    Specifies an SSL connection.

    Limits: 0=no | 1=yes

    Default: 0

    -ccert

    (Only required if the ssl value is 1) Specifies the path to the directory where the SSL client certificate database file, cert7.db, exists.

    The correct configuration of the LDAP policy store connection parameters is verified.

  2. Run the following command:
    smldapsetup reg -hhost -pport -dAdminDN
    -wAdminPW -rroot -ssl1/0 -ccert
    

    The connection to the LDAP directory server is tested and the server is configured as a SiteMinder policy store.