CA LDAP Server for z/OS (RACF) does not support the following SiteMinder features:
Password Services is not supported.
When configuring a CA LDAP Server r15 for z/OS (RACF) as a user store, provide values for the Administrator Credentials in the Create User Directory page.
The following characters are not supported in user names:
Adding a user group to a policy and attempting to authorize a user in that group fails.
LDAP Failover and Replication is not supported.
This section describes the settings that are required to configure the CA LDAP Server r15 for z/OS (ACF2) as a user store with the Policy Server.
The CA LDAP Server r15 for z/OS (ACF2) contains a different set of objectclasses than other LDAP servers. Before configuring a user directory connection from the Policy Server to the CA LDAP Server, add the ACF2 objectclasses to certain Policy Server registry entries in the LDAP namespace. Substitute the replacement values for the default values of the following Policy Server registry entries:
Specifies the following registry entry location:
HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion\Ds.
Specifies the default value of the registry entry.
Specifies a new value containing the ACF2 objectclasses for the registry entry.
organization,organizationalUnit,groupOfNames,groupOfUniqueNames,group
class_filters_default_value,*
groupOfNames,groupOfUniqueNames,group
group_class_filters_default_value,*
organizationalPerson,inetOrgPerson,organization,organizationalUnit,groupOfNames,groupOfUniqueNames,group
policy_class_filters_default_value,*
Add the following ACF2 objectclasses to this registry entry:
ACF2 Objectclass |
Registry Key Type |
Data |
---|---|---|
acf2lid |
REG_DWORD |
0x00000001(1) |
acf2admingrp |
REG_DWORD |
0x00000002(2) |
eTACFLidName |
REG_DWORD |
0x00000001(1) |
In UNIX, add the following ACF2 objectclass to this registry entry:
ACF2 Objectclass |
Registry Key Type |
Data |
---|---|---|
LDAPPingTimeout= |
REG_DWORD |
300; |
Note: The value of this registry key can be changed based on the response time of the CA LDAP Server r15 for z/OS (ACF2).
To configure a directory connection from the Policy Server to the CA LDAP Server for z/OS (RACF) or CA LDAP Server for z/OS (ACF2), open an existing user directory object in the Administrative UI.
Follow these steps:
Note: For more information, see the topic LDAP Namespace Directory Setup Tab in the Policy Design Reference Guide.
Note: Failover is not supported for this LDAP Server.
Note: A greater timeout value is required, because the Policy Server takes more time to retrieve data from this LDAP Server.
Important! Specifying administrator credentials is mandatory as anonymous binds to the user store are not allowed with CA LDAP Server r15 for z/OS (RACF) and CA LDAP Server r15 for z/OS (ACF2).
Copyright © 2012 CA.
All rights reserved.
|
|