ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Integration Bus Web User Interface LDAP Authentication

Post new topic  Reply to topic
 Integration Bus Web User Interface LDAP Authentication « View previous topic :: View next topic » 
Author Message
LoQutus
PostPosted: Wed Nov 02, 2016 2:24 am    Post subject: Integration Bus Web User Interface LDAP Authentication Reply with quote

Newbie

Joined: 02 Nov 2016
Posts: 3

Hi,

At one of my customers, we're using LDAP authentication for the Web User Interface.

My question is: "Can we enter multiple LDAP server hostnames or IP addresses in the ldapAuthenticationUri ? Maybe in the form of a comma-separated-value ?"


The customer has multiple LDAP servers (for failover / redundancy reason).


Regards,

Bram - LoQutus
Back to top
View user's profile Send private message
LoQutus
PostPosted: Wed Nov 02, 2016 2:27 am    Post subject: ldapAuthenticationUri Reply with quote

Newbie

Joined: 02 Nov 2016
Posts: 3

The configuration for this is described in the following article on the Knowledge Center:

https://www.ibm.com/support/knowledgecenter/SSMKHH_10.0.0/com.ibm.etools.mft.doc/ap04143_.htm

But it provides no information on what values are suitable...
Back to top
View user's profile Send private message
Vitor
PostPosted: Wed Nov 02, 2016 4:20 am    Post subject: Re: Integration Bus Web User Interface LDAP Authentication Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

LoQutus wrote:
The customer has multiple LDAP servers (for failover / redundancy reason).


How does your customer expose these multiple servers to other LDAP users; i.e how does (for example) a WAS server reach one or another LDAP server, especially if the LDAP server it was previously using goes down?

Use that same technique for IIB.

I would suspect the customer has these servers behind an F5.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
LoQutus
PostPosted: Wed Nov 02, 2016 4:55 am    Post subject: Reply with quote

Newbie

Joined: 02 Nov 2016
Posts: 3

Hi,

1/ LDAP servers behind a network load balancer, virtual IP, etc... could be an option; I'll ask the customer what is possible with their current infrastructure..., but I was looking for the possibilities / capabilities within the IIB product itself

2/ for WAS, you can define additional LDAP servers in the configuration

3/ for IIB, I've talked to someone of IBM, he told me that for the moment you can only define one entry for the ldapAuthenticationUri attribute



Regards,

Bram - LoQutus
Back to top
View user's profile Send private message
Vitor
PostPosted: Wed Nov 02, 2016 6:22 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

LoQutus wrote:
2/ for WAS, you can define additional LDAP servers in the configuration


Well I've learned something today. Our WAS people will be interested to learn that as well.....

LoQutus wrote:
3/ for IIB, I've talked to someone of IBM, he told me that for the moment you can only define one entry for the ldapAuthenticationUri attribute


As you'd expect from someone from IBM, that's right.

LoQutus wrote:
1/ LDAP servers behind a network load balancer, virtual IP, etc... could be an option


It's what we do. For IIB, WAS and all of our other LDAP consumers.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Integration Bus Web User Interface LDAP Authentication
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.