So, the instructions were pretty straight forward accept for Step 3. Modify the "authMethod" in the pdwpm.conf file to the value SSO. This file was supposed to be at /opt/PolicyDirector/etc on the WPM server, but is wasn't. The only file that was close was pdwpm.conf.template. So I assumed that they wanted me to copy this to pdwpm.conf and make the modification as noted in the step.
Another little difference is that when you web to the WAS server to get to the Admin console, prior to version 6 the default port was 9090. For WAS 6 it is 9060. The instructions here walk you through the Admin Console to set up LTPA and User Registry parameters. Essentially you will be pointing the WAS server to the LDAP so this Admin Console will also be secure when you are done. No longer will you be able to just type anything in the login prompt to get into the Admin console. You may have to create some LDAP users along the way for this to work. I created a WAS Admin ID and a WPM User ID for this whole process. One thing to note is that in Step 11 you will have to complete the User Registry Form and the Bind (DN) shown in the example uses cn=root. I tried a different user ID that has basically just read access to the LDAP and when I tried to apply the User Registry settings I had a credential failure. I had to use the cn=root as shown in the instructions. I'm guessing this is because my other user did not have enough access to something in the LDAP, the instructions do not really explain what exactly all these accounts need to do.
The only thing I did not do from these instructions is enable the Diagnostic Trace Service. (I may need to go back and do this)
The Problem:
When I try to access Web Portal Manager via WebSeal I get a login prompt:
a.) If I try to login as sec_master or other TAM users I get an error "Could not Sign User on"


If I try to login as another TAM user I get a different error "Delegate credential was specified but its value is null"


/opt/IBM/WebSphere/AppServer/profiles/default/installedApps/wpmNode01Cell/TAMWPM.ear/classes
Well, I should hopefully have an answer from IBM Tech support soon on this. If not, then maybe I wont worry about putting the WPM behind TAM at all.
1 comment:
So did you find out any more info. In particular around the "Delegate credential was specified but its value is null" I am receiving the same error?
Post a Comment