Parameter
Value
/pass
<userPassword>
For this configuration example, you would enter the following command to create a keytab file
named
:
nidpkey
ktpass /out nidpkey.keytab /princ HTTP/amser.provo.novell.com@AD.
NOVELL.COM /mapuser amser@AD.NOVELL.COM /pass novell
2 Copy the keytab file to the Identity Server.
Copy the file to the default location on the Identity Server:
Linux:
/opt/novell/java/jre/lib/security
Windows:
C:\Program Files\Novell\jre\lib\security
3 If the cluster contains multiple Identity Servers, copy the keytab file to each member of the
cluster.
Adding the Identity Server to the Forward Lookup Zone
1 In Manage Your Server on your Windows 2003 server, click Manage this DNS server.
2 Click Forward Lookup Zone.
3 Click the Active Directory domain.
4 In the right pane, right click, and select New Host (A).
5 Fill in the following fields:
Name: Specify the hostname of the Identity Server.
IP Address: Specify the IP address of the Identity Server.
6 Click Add Host.
3.4.3 Configuring the Identity Server
You need to configure the Identity Server to use the Active Directory server as a user store,
configure a Kerberos authentication class, method, and contract, create a configuration file, enable
logging to verify the configuration, then restart Tomcat. These instructions assume that you have
installed and configured an Identity Server cluster configuration. If you have not, see the
Access Manager 3.1 SP1 Installation Guide
This section covers the following tasks:
"Enabling Logging for Kerberos Transactions" on page 118
"Configuring the Identity Server for Active Directory" on page 118
"Creating the Authentication Class, Method, and Contract" on page 119
"Creating the bcsLogin Configuration File" on page 122
"Verifying the Kerberos Configuration" on page 123
Description
Specify the password for this user.
and the
Novell Access Manager 3.1 SP1 Setup
Configuring Advanced Local Authentication Procedures 117
Novell
Guide.
Need help?
Do you have a question about the ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER and is the answer not in the manual?