Previous Topic: Migrate an Existing Policy Store into an LDAP Directory

Next Topic: Configuring SiteMinder Data Stores in a Relational Database

Point the Policy Server at the Policy Store

Once you have created a new policy store or key store, or migrated or moved an LDAP policy store, you must configure the Policy Server to use the LDAP directory. You can also use the Policy Server Management Console to configure additional Policy Servers to leverage an existing policy store in an LDAP directory.

When you use the Policy Server Management Console to change the Policy Store from ODBC to LDAP, the key store does not automatically switch to LDAP, even when it is set to use the same store as the policy store. You must manually change both to LDAP for the key store to be accepted by the Policy Server Management Console.

Note: Refer to the Policy Server Management guide for detailed information about using the Policy Server Management Console.

To point the Policy Server at the policy store

  1. On the server where the Policy Server is installed, open the Policy Server Management Console and select the Data tab to bring it to the front.

    Important! If you are accessing this graphical user interface on Windows Server 2008, open the shortcut with Administrator permissions, even if you are logged into the system as an Administrator. For more information, see the release notes for your SiteMinder component.

  2. Do the following:
    1. In the Database drop-down menu, select Policy Store.
    2. In the Storage drop-down menu, select LDAP.
    3. In the LDAP Policy Store box, configure the fields for the LDAP policy store.

      The following lists sample values for the fields:

      LDAP IP Address: 123.123.12.12:3500

      Root DN: o=test

      Admin Username: cn=admin,ou=people,o=test

      Password: <masked password>

      Note: Refer to the Policy Server Management guide for a complete description of the LDAP settings.

    4. If the Policy Server is communicating with the LDAP directory over SSL, select the Use SSL check box.
    5. Click Apply after you have modified the LDAP fields.
    6. Click the Test LDAP Connection button to test the connection.

      If the connection is successful, SiteMinder returns a confirmation. If it is not successful, SiteMinder returns an error message. If you receive an error message, verify that the values you entered are correct and that the directory is running.