CA LDAP Server for z/OS does not support the following SiteMinder features:
When configuring a CA Top Secret LDAP Server as a user store, you must provide values in the fields on the Administrator Credentials group box on the Create User Directory pane.
The following characters are not supported in user names:
Load balancing and failover is not supported.
Password Services is not supported.
Adding a user group to a policy and attempting to authorize a user in that group fails.
This section describes the settings that are required to configure the CA LDAP Server r15 for z/OS (RACF) as a user store with the Policy Server.
The CA LDAP Server r15 for z/OS (RACF) contains a different set of objectclasses than other LDAP servers. Before configuring a user directory connection from the Policy Server to the CA LDAP Server, add the RACF objectclasses to certain Policy Server registry entries in the LDAP namespace. Substitute the replacement values for the default values of the following Policy Server registry entries:
Specifies the following registry entry location:
HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion\Ds.
Specifies the default value of the registry entry.
Specifies a new value containing the RACF objectclasses for the registry entry.
organization,organizationalUnit,groupOfNames,groupOfUniqueNames,group
class_filters_default_value,*
groupOfNames,groupOfUniqueNames,group
group_class_filters_default_value,*
organizationalPerson,inetOrgPerson,organization,organizationalUnit,groupOfNames,groupOfUniqueNames,group
policy_class_filters_default_value,*
Add the following RACF objectclasses to this registry entry:
RACF Objectclass |
Registry Key Type |
Data |
---|---|---|
eTRACUserid |
REG_DWORD |
0x00000001(1) |
eTRACAdminGrp |
REG_DWORD |
0x00000002(2) |
In UNIX, add the following RACF objectclass to this registry entry:
RACF Objectclass |
Registry Key Type |
Data |
---|---|---|
LDAPPingTimeout= |
REG_DWORD |
300; |
Note: The value of this registry key can be changed based on the response time of the CA LDAP Server r15 for z/OS (RACF).
Copyright © 2012 CA.
All rights reserved.
|
|