Monday, November 11, 2013
Re-certification in IBM Security Identity Manager 6.0 no Person Types
I just find it a little annoying that when creating re-certifications in SIM 6, you can choose persons of type Person or BP Person, or you can choose all Persons, but if you had any custom SIM person classes defined the tool gives you no way to select your own custom Person type. Like the developers got 3/4 of the way developing this feature and said, "Oh, good enough".
Monday, February 18, 2013
What's Hot in Security?
These days, I am getting a lot of calls for security solutions. I would say we are busier than ever. Here are what people are asking us for:
1.) SIEM - Tons of customers are either ripping out old log management solutions and replacing them or they are just now getting around to implementing these. This space is fairly competitive. I'm running into McAfee Nitro, Dell SecureWorks, LogLogic, LogRythm, Tripwire and of course the one we sell QRadar.
2.) Database Security - This is a really hot area right now. So many of our customers are trying to put better controls on their databases. They want to ensure that any unacceptable database queries are stopped or at least alerted on. They want to ensure that even privileged users (DBAs) are controlled. They want to mask certain data from being seen in the tables. They want comprehensive audit reporting. And they want all this with little to no performance penalty on the database. I usually only see Imperva and Guardium in this market space although occasionally the Oracle shops tend to go for Oracle's solution. IBM Guardium rocks in this space.
3.) Application Security - We are working with quite a few customers who develop web applications in house for their Internet/Extranet, etc... There are a few spots where they are looking for help securing these applications. One is adhoc pen testing. Simply periodic testing of their web facing applications to ensure there are no new vulnerabilities. Second is during the software development lifecycle. It is widely known that its much more expensive to fix a bug after it is already deployed to production than catching it before it makes it to Prod. So scanning the source code and checking for vulnerabilities during the development process is much less expensive to resolve. AppScan is tops in this space at detecting and helping to solve these problems.
4.) Identity and Access - Many companies do this already, but I've helped companies who are on their first, second and 3rd deployments of Identity and Access. So this is not really slowing down. The interesting thing about this space is that over the last several years there has been a distinguishing line between Governance solutions and User Admin and Provisioning solutions. Many vendors have both included with-in their respective Identity Management solution, but in almost every case the Governance solution was a different acquisition from the User Provisioning solution. Anyhow this space is mature. For larger companies I am always running into Oracle and CA. We tend to recommend IBM at our company. But in smaller customers, there are many other options out there such as Microsoft, Sailpoint, Aveksa, Centrify and Courion. Sometimes we recommend a combination. We occasionally like an Aveksa + IBM solution for Identity Management. IBM's most flexible and mature provisioning solution accompanied by the user friendly governance offering from Aveksa is sometimes a great match. The options are plentiful.
5.) Privileged User Management - This comes up a lot with customers these days. Controlling what the root and admin users are doing is very important to those who are heavily regulated. The vendors I run into most in this space are CyberArk and Centrify. CyberArk seems to be a favorite among many people. They like the fact that it records video of what the admins are actually doing. Pretty cool. Centrify is a nice solution as well. IBM release a PIM solution at the end of 2012 which integrates its Identity Management offering + ESSO. Check in and check out the privileged user accounts, audit who uses the accounts and what did they access, etc....
We run into plenty of infrastructure projects as well Firewalls, IDS/IPS, etc...., but every day I get a call about one of the 5 above and not necessarily in that order. Security is very hot right now.
1.) SIEM - Tons of customers are either ripping out old log management solutions and replacing them or they are just now getting around to implementing these. This space is fairly competitive. I'm running into McAfee Nitro, Dell SecureWorks, LogLogic, LogRythm, Tripwire and of course the one we sell QRadar.
2.) Database Security - This is a really hot area right now. So many of our customers are trying to put better controls on their databases. They want to ensure that any unacceptable database queries are stopped or at least alerted on. They want to ensure that even privileged users (DBAs) are controlled. They want to mask certain data from being seen in the tables. They want comprehensive audit reporting. And they want all this with little to no performance penalty on the database. I usually only see Imperva and Guardium in this market space although occasionally the Oracle shops tend to go for Oracle's solution. IBM Guardium rocks in this space.
3.) Application Security - We are working with quite a few customers who develop web applications in house for their Internet/Extranet, etc... There are a few spots where they are looking for help securing these applications. One is adhoc pen testing. Simply periodic testing of their web facing applications to ensure there are no new vulnerabilities. Second is during the software development lifecycle. It is widely known that its much more expensive to fix a bug after it is already deployed to production than catching it before it makes it to Prod. So scanning the source code and checking for vulnerabilities during the development process is much less expensive to resolve. AppScan is tops in this space at detecting and helping to solve these problems.
4.) Identity and Access - Many companies do this already, but I've helped companies who are on their first, second and 3rd deployments of Identity and Access. So this is not really slowing down. The interesting thing about this space is that over the last several years there has been a distinguishing line between Governance solutions and User Admin and Provisioning solutions. Many vendors have both included with-in their respective Identity Management solution, but in almost every case the Governance solution was a different acquisition from the User Provisioning solution. Anyhow this space is mature. For larger companies I am always running into Oracle and CA. We tend to recommend IBM at our company. But in smaller customers, there are many other options out there such as Microsoft, Sailpoint, Aveksa, Centrify and Courion. Sometimes we recommend a combination. We occasionally like an Aveksa + IBM solution for Identity Management. IBM's most flexible and mature provisioning solution accompanied by the user friendly governance offering from Aveksa is sometimes a great match. The options are plentiful.
5.) Privileged User Management - This comes up a lot with customers these days. Controlling what the root and admin users are doing is very important to those who are heavily regulated. The vendors I run into most in this space are CyberArk and Centrify. CyberArk seems to be a favorite among many people. They like the fact that it records video of what the admins are actually doing. Pretty cool. Centrify is a nice solution as well. IBM release a PIM solution at the end of 2012 which integrates its Identity Management offering + ESSO. Check in and check out the privileged user accounts, audit who uses the accounts and what did they access, etc....
We run into plenty of infrastructure projects as well Firewalls, IDS/IPS, etc...., but every day I get a call about one of the 5 above and not necessarily in that order. Security is very hot right now.
Tulsa, OK
Visiting some clients this week I figured I would stay in downtown Tulsa. So I booked a night at the Courtyard. The Atlas Life building was built in 1922 and they have kept a lot of the charming old doors and some of the decor which is cool. Unfortunately I drew the short straw on the view from my room.
IBM Security Brand
This is sort of old news, but for some folks its completely new stuff. For a number of years I worked with IBM products in the Lotus brand and then the Tivoli brand. Tivoli was a huge brand including many different kinds of software solutions from asset management to security. I believe there were hundreds of software titles in the Tivoli brand. The security products I worked with were a handful in the ocean of Tivoli products. But at IBM there were other handfuls of security products sprinkled through-out the other brands. With the acquisition of Q1 Labs IBM also announce a new brand called IBM Security. Like Tivoli, IBM Security is its own business unit at IBM. Most of the products from all of the other brands that had anything to do with security have been moved with-in the IBM Security organization. This is good. It helps IBM and partners articulate a consistent message and strategy to customers. From support to development the expectation is that all of the products with-in the security organization will gain more consistency in development lifecycle, and will improve integrations between all of the security products.
So for those who are not up to speed on the new product names and versions, I'll mention some here
IBM Security Identity Manager (SIM) formerly known as IBM Tivoli Identity Manager
IBM Security Access Manager for eBusiness (SAM) formerly known as IBM Tivoli Access Manager for eBusiness
IBM Security Access Manager for Enterprise Single Sign On (SAM ESSO) formerly known as IBM Tivoli Access Manager for Enterprise Single Sign On
IBM Security Directory Server formerly known as IBM Tivoli Directory Server
You kind of get the idea. The acronyms are as silly as ever.
But there are other products from IBM which we are doing much more with:
IBM Security Identity and Access Assurance for one is a bundle of all of the IAM products and later in the year will likely include a SIEM solution again.
QRadar SIEM is a top notch security intelligence solution in the SIEM space and probably one of the best acquisitions IBM has made in security.
InfoSphere Guardium is another great IBM product top notch in data security.
AppScan is also head and shoulders above its competition in many ways and the market shows it.
So with all of these great solutions under one brand and the security division being led by a security guy, it has been very busy for us IBM leaning security people lately.
So for those who are not up to speed on the new product names and versions, I'll mention some here
IBM Security Identity Manager (SIM) formerly known as IBM Tivoli Identity Manager
IBM Security Access Manager for eBusiness (SAM) formerly known as IBM Tivoli Access Manager for eBusiness
IBM Security Access Manager for Enterprise Single Sign On (SAM ESSO) formerly known as IBM Tivoli Access Manager for Enterprise Single Sign On
IBM Security Directory Server formerly known as IBM Tivoli Directory Server
You kind of get the idea. The acronyms are as silly as ever.
But there are other products from IBM which we are doing much more with:
IBM Security Identity and Access Assurance for one is a bundle of all of the IAM products and later in the year will likely include a SIEM solution again.
QRadar SIEM is a top notch security intelligence solution in the SIEM space and probably one of the best acquisitions IBM has made in security.
InfoSphere Guardium is another great IBM product top notch in data security.
AppScan is also head and shoulders above its competition in many ways and the market shows it.
So with all of these great solutions under one brand and the security division being led by a security guy, it has been very busy for us IBM leaning security people lately.
End of Life or New Beginning
I was inches from killing this blog once and for all. For the past 2 years it sat idle collecting spam mainly. Every now and then I would meet someone in my IBM circles who would say, "hey I think I've read your blog". I'd replay, yeah I should really get out and do something about that thing.
Anyhow, Lots of reasons to not keep this thing going. For one, I found it hard to mention in too much detail the kinds of things I was doing at customers sites. Just trying to cleans the information was a task. Second, it really did not attract a whole lot of input from the outside. More often then not, someone was asking me a question about a problem they were having which would lead me on a wild goose chase to try and find a solution. I hate not replying to people, but then again, I have a full time job already. Thirdly, the material is a bit boring at times.
Well, times change and in my current role I actually do have more I could blog about than before. But it still takes effort to get out here and say something half way intelligent.
So here it goes. I'm going to try this again for a while and see if I can keep it up. If it goes stagnant again, I'll just kill it altogether.
Anyhow, Lots of reasons to not keep this thing going. For one, I found it hard to mention in too much detail the kinds of things I was doing at customers sites. Just trying to cleans the information was a task. Second, it really did not attract a whole lot of input from the outside. More often then not, someone was asking me a question about a problem they were having which would lead me on a wild goose chase to try and find a solution. I hate not replying to people, but then again, I have a full time job already. Thirdly, the material is a bit boring at times.
Well, times change and in my current role I actually do have more I could blog about than before. But it still takes effort to get out here and say something half way intelligent.
So here it goes. I'm going to try this again for a while and see if I can keep it up. If it goes stagnant again, I'll just kill it altogether.
Tuesday, January 12, 2010
Signed up for Pulse 2010 yet?
Granted the recession of late has curtailed spending all around, but for many IT departments there are still a number of high priority projects especially in security. If you are already an IBM shop, the Pulse conference is a great way to get a deeper look into the products and solutions that you are considering for the new year. You will spend the time and money doing this research anyhow. Why not come out to Vegas for a look under the hood?
Pulse represents a pretty large swath of products. Unlike Lotusphere which focuses Lotus and Portal, the Pulse conference covers all things Tivoli. There are over 300 products in the Tivoli brand so this conference is a bit different than Lotusphere. If you are into Asset Management or Performance and Monitoring, there are specific tracks for you. If you are interested in Security, there is a whole other track for you as well. Within each area, there are a number of presentations from customers demonstrating recent deployments where you will get the real scoop on what their projects were like, the good and the bad. This alone is worth the visit if you are planning a project with Tivoli software this year. Also, you can stop in the hands on labs and actually work directly with the software so that you can get a feel for how the product really works. The labs are staffed by the IBM education team and there are some really sharp people there who can work through the labs with you.
Pulse also has areas setup where you can "ask the experts" just about anything. These are basically casual "sit down and chat" spaces where you can be face to face with folks from the product development teams and ask questions. Nothing is too complicated that you cannot get an answer at Pulse.
Business Partners and 3rd party vendors setup shop in the showcase floor to show you how they implement the IBM solutions. You may get some really good ideas from these folks how best to leverage the IBM solutions as well as find help getting started with an implementation.
The technical sessions are a great way to get a look at some of the other products and solutions you may not have thought about before. There is something here for everyone from c-level folks right down to the hands on IT person so I recommend you come on out and see for yourself. It's well worth the expense.
BTW, the recreation is not all bad either. While I do not enjoy gambling, being in Vegas is a spectacle. The Pulse Palooza isn't a bad time either. Free beer!
Register for Pulse 2010 --> http://www-01.ibm.com/software/tivoli/pulse/
Get a look at what's going on at Pulse 2010 --> https://www-950.ibm.com/communities/service/html/communityview?communityUuid=dd8bf011-85af-48da-a4dd-21047a08c33e
Pulse represents a pretty large swath of products. Unlike Lotusphere which focuses Lotus and Portal, the Pulse conference covers all things Tivoli. There are over 300 products in the Tivoli brand so this conference is a bit different than Lotusphere. If you are into Asset Management or Performance and Monitoring, there are specific tracks for you. If you are interested in Security, there is a whole other track for you as well. Within each area, there are a number of presentations from customers demonstrating recent deployments where you will get the real scoop on what their projects were like, the good and the bad. This alone is worth the visit if you are planning a project with Tivoli software this year. Also, you can stop in the hands on labs and actually work directly with the software so that you can get a feel for how the product really works. The labs are staffed by the IBM education team and there are some really sharp people there who can work through the labs with you.
Pulse also has areas setup where you can "ask the experts" just about anything. These are basically casual "sit down and chat" spaces where you can be face to face with folks from the product development teams and ask questions. Nothing is too complicated that you cannot get an answer at Pulse.
Business Partners and 3rd party vendors setup shop in the showcase floor to show you how they implement the IBM solutions. You may get some really good ideas from these folks how best to leverage the IBM solutions as well as find help getting started with an implementation.
The technical sessions are a great way to get a look at some of the other products and solutions you may not have thought about before. There is something here for everyone from c-level folks right down to the hands on IT person so I recommend you come on out and see for yourself. It's well worth the expense.
BTW, the recreation is not all bad either. While I do not enjoy gambling, being in Vegas is a spectacle. The Pulse Palooza isn't a bad time either. Free beer!
Register for Pulse 2010 --> http://www-01.ibm.com/software/tivoli/pulse/
Get a look at what's going on at Pulse 2010 --> https://www-950.ibm.com/communities/service/html/communityview?communityUuid=dd8bf011-85af-48da-a4dd-21047a08c33e
Friday, January 8, 2010
TAM ESSO v8.1 - Are you ready for WebSphere?
Installing a standalone TAM ESSO IMS Server took about 2 hours to install including the database. That was version 8.0. IBM released version 8.1 this past December and I spent this week going through the upgrade process to see what will be in store for folks who want to jump right into the new stuff. It didn't take the whole week to do this upgrade, however I had to take it slow so that I could capture documentation for future reference.
The big news is that TAM ESSO v8.1 requires IBM WebSphere Application Server. When I first saw this I thought "ugggh". But the reality is that you had to know this was coming and it makes sense to run IBM's single sign on solution on their own application server.
This changes a lot though. First off, deployments will take a little longer. The fact is, even with the wizard installation tools, WAS is still a big pile of software to install. You also need IBM HTTP Server. Both need to be patched once you install them and you can't even patch the software until you download the patch installer first (IBM UpdateInstaller). But Windows shops should be used to that anyhow as you need install Microsoft's update software in order to get Windows updates.
First, is the upgrade worth it? Of course. If you want the best support for your software keep on the latest and greatest. Everyone has heard the same thing on a typical tech support phone call where the support guy asks,"What version of software are you running?" and you say, "1.2". No doubt the support guy will suggest you try the latest version. Sometimes it really comes down to which version has the fewest warts? Because you know that the latest version of software will have something wrong with it, but you hope the latest has fewer warts than the older version and lets face it, which version is getting the most attention?
The new version of TAM ESSO does not look any different than the prior release as far as the end user is concerned. But when you think about it, if TAM ESSO is doing it's job, the user does not even know it is there. All the user knows is that they login to Windows, launch their applications and they are magically signed in. Not much to see there. But, for the implementer or tech support team there is plenty to be happy about in the new release.
1.) IBM has opened up the doors to more 2 factor devices. Generic smart card support – this will leverage 3rd party products for smart card life cycle management and leverage windows smart card authentication for certificate authentication. Also Serial ID Service Provider Interface (SPI) has been introduced to allow any vendor with a serial ID device to integrate with TAM ESSO. BIO-Key support has been added which will also widen the choices of 2-factor devices supported.
2.) Wider platform coverage. Windows 7 is coming and shops already starting to buy machines with Windows 7 want to be sure AccessAgent will work. While IBM does not list Windows 7 specifically in the compatibility list, Kiosk support has been added for Vista and 64-bit Windows is supported for AccessAgent although there may be some issues with certain 3rd party strong authentication devices. Word on the street is that Windows 7 will show up on the list when it is Microsoft certified.
3.) New features in AccessStudio should make profiling a little easier. The undo button is a nice option we take for granted in Word documents. I like it in AccessStudio very much. Another really nice feature that was added is the ability to take an existing trigger and convert it to a different type. To me that's a welcome new enhancement. The ability to save your profile as an image was there in version 8.0.1, but it's listed as a new feature for 8.1. I like it nonetheless so thanks IBM. Enhanced logging messages are also a big help. Any time they make improvements to this area, I'll welcome it.
4.) Firefox finally! I knew a lot of people that were really turned off by the lack of support for Firefox. At first I was a little the same way, but I got used to using both IE and Firefox anyhow for reasons that have nothing to do with SSO. I look forward to working with Firefox in profiling.
Well, I'm off to another SSO project. Stay tuned for more on this later.
The big news is that TAM ESSO v8.1 requires IBM WebSphere Application Server. When I first saw this I thought "ugggh". But the reality is that you had to know this was coming and it makes sense to run IBM's single sign on solution on their own application server.
This changes a lot though. First off, deployments will take a little longer. The fact is, even with the wizard installation tools, WAS is still a big pile of software to install. You also need IBM HTTP Server. Both need to be patched once you install them and you can't even patch the software until you download the patch installer first (IBM UpdateInstaller). But Windows shops should be used to that anyhow as you need install Microsoft's update software in order to get Windows updates.
First, is the upgrade worth it? Of course. If you want the best support for your software keep on the latest and greatest. Everyone has heard the same thing on a typical tech support phone call where the support guy asks,"What version of software are you running?" and you say, "1.2". No doubt the support guy will suggest you try the latest version. Sometimes it really comes down to which version has the fewest warts? Because you know that the latest version of software will have something wrong with it, but you hope the latest has fewer warts than the older version and lets face it, which version is getting the most attention?
The new version of TAM ESSO does not look any different than the prior release as far as the end user is concerned. But when you think about it, if TAM ESSO is doing it's job, the user does not even know it is there. All the user knows is that they login to Windows, launch their applications and they are magically signed in. Not much to see there. But, for the implementer or tech support team there is plenty to be happy about in the new release.
1.) IBM has opened up the doors to more 2 factor devices. Generic smart card support – this will leverage 3rd party products for smart card life cycle management and leverage windows smart card authentication for certificate authentication. Also Serial ID Service Provider Interface (SPI) has been introduced to allow any vendor with a serial ID device to integrate with TAM ESSO. BIO-Key support has been added which will also widen the choices of 2-factor devices supported.
2.) Wider platform coverage. Windows 7 is coming and shops already starting to buy machines with Windows 7 want to be sure AccessAgent will work. While IBM does not list Windows 7 specifically in the compatibility list, Kiosk support has been added for Vista and 64-bit Windows is supported for AccessAgent although there may be some issues with certain 3rd party strong authentication devices. Word on the street is that Windows 7 will show up on the list when it is Microsoft certified.
3.) New features in AccessStudio should make profiling a little easier. The undo button is a nice option we take for granted in Word documents. I like it in AccessStudio very much. Another really nice feature that was added is the ability to take an existing trigger and convert it to a different type. To me that's a welcome new enhancement. The ability to save your profile as an image was there in version 8.0.1, but it's listed as a new feature for 8.1. I like it nonetheless so thanks IBM. Enhanced logging messages are also a big help. Any time they make improvements to this area, I'll welcome it.
4.) Firefox finally! I knew a lot of people that were really turned off by the lack of support for Firefox. At first I was a little the same way, but I got used to using both IE and Firefox anyhow for reasons that have nothing to do with SSO. I look forward to working with Firefox in profiling.
Well, I'm off to another SSO project. Stay tuned for more on this later.
Thursday, December 31, 2009
Subject Alternative Name with GSKit
Subject Alternative Name's (SANs) allow you to obtain a single SSL certificate to protect multiple hosts. So lets say you have two LDAP servers (server1 and server2) and you want to enable SSL, but you want to have clients reference only one DNS name (ldapserver) to connect to any of the LDAP servers. Likely you will have a load balancer of some kind in front of the LDAP. One way to do the Certificate Signing Request (CSR) is to specify "ldapserver" in the host name field and then specify "server1" as the SAN. The problem is IKeyMan doesn't have a way of including a SAN in the CSR.
This is not a problem for a couple of reasons. For one, you can use the command line tools with GSKit to create a CSR containing a SAN. While the GUI lacks this capability it seems the command line supports it:
gsk7cmd -cert -create -db /keys/tds.kdb -pw password -label junk -dn "cn=tds1,o=bigco,c=us" -san_dnsname tdswin1,tdssrv1 -expire 3653
The other option is to create the CSR using IKeyMan without the SAN. When you post the CSR certificate into the web form at Verisign or whatever other CA you choose, you should be able to use the CA form to specify the SAN. This way the signed version of the certificate you receive back from the CA will contain the SAN. IkeyMan supports receiving the signed certificate back into the key database with the SAN included so this will work fine. In fact this is the easiest way to do this. For your LDAP servers it is best to create the Key database using IKeyMan and issue the CSR from there. That way you can do the Receive Certificate operation later when you receive the signed certificate back from the CA.
Cheers!
This is not a problem for a couple of reasons. For one, you can use the command line tools with GSKit to create a CSR containing a SAN. While the GUI lacks this capability it seems the command line supports it:
gsk7cmd -cert -create -db /keys/tds.kdb -pw password -label junk -dn "cn=tds1,o=bigco,c=us" -san_dnsname tdswin1,tdssrv1 -expire 3653
The other option is to create the CSR using IKeyMan without the SAN. When you post the CSR certificate into the web form at Verisign or whatever other CA you choose, you should be able to use the CA form to specify the SAN. This way the signed version of the certificate you receive back from the CA will contain the SAN. IkeyMan supports receiving the signed certificate back into the key database with the SAN included so this will work fine. In fact this is the easiest way to do this. For your LDAP servers it is best to create the Key database using IKeyMan and issue the CSR from there. That way you can do the Receive Certificate operation later when you receive the signed certificate back from the CA.
Cheers!
Tuesday, December 22, 2009
TDS Web Admin Tool - Superuser
Be careful changing the credentials for this. When you login to the TDS Web Admin Tool and attempt to change either the user name or password for the superuser (default superadmin) I have seen cases where something got screwed up and the end result was to uninstall and re-install the TDS Web Admin Tool completely.
It seems that the tool is a little quirky if you try to change the user name and password at the same time. My best recommendation is to change the username, log out of the tool, then log back into the tool with your new user name and the original password. Then change the password for the user. Log out of the tool, then back in with the new user name and new password.
It seems that the tool is a little quirky if you try to change the user name and password at the same time. My best recommendation is to change the username, log out of the tool, then log back into the tool with your new user name and the original password. Then change the password for the user. Log out of the tool, then back in with the new user name and new password.
Monday, December 14, 2009
How much do you rely on the TDS Web Admin Tool?
I usually setup TDS as an enterprise LDAP, but usually as part of a larger security initiative such as Identity and Access Management. Since LDAP is the underlying user registry for ITIM and ITAM we typically do not use the TDS Web Admin tool for much more than some initial setup and configuration of the LDAP. Beyond that ITIM and ITAM have their own management tools.
But, if your goals for LDAP were simpler and you are not implementing an Identity Management solution, well you are limited to a few different tools to manage your LDAP directory:
Command Line tools such as ldapsearch, ldapadd, idsldapsearch, idsldapadd, etc....
TDS Web Admin Tool (GUI)
3rd Party tools such as Softerra's LDAP Administrator
Those who are new to LDAP in general and do not prefer to use command line tools, naturally gravitate to the TDS Web Admin Tool. In general its a pretty good tool and in TDS 6.2 it is much better than 6.0 for tasks such as setting up replication, but its still a bit buggy.
For example I ran into a problem recently where we had a boolean attribute configured as a mandatory attribute for our objectclass. Using TDS Web Admin Tool to create a new user entry results in an objectclass violation. Meanwhile using idsldapadd works just fine. It turned out to be a legitimate bug with a fix on the way, but there are other quirky issues with this tool.
Another problem I noticed in one case I have 5000 entries populated in the LDAP. If I navigate through the directory tree I can see the entries listed, but if I click on an entry it should open up the edit screen for that entry. Instead it does nothing at all. Yet, if I use the directory search tools in TDS Web Admin GUI I can find a specific entry and then click on the entry which correctly opens the edit screen for that same entry. Weird.
Another issue which I would consider a bug and I don't know if IBM will ever address this:
If I customize the LDAP Schema by using custom schema files I.e. V3.myschema.oc and V3.myschema.at, the Web Admin Tool does not acknowledge this and continues to drop stuff in V3.modifiedschema instead. TDS supports creating custom schema files by allowing you to reference the custom files in ibmslapd.conf. This is one way of keeping your custom schema organized neatly. In fact if you keep all of your custom attributes and classes in order by OID (assuming you are using a legitimately registered OID) then it makes it easy to know what OID to use next for any new attributes or classes. Also, if you have replicas, schema updates to the replicas is a simple matter of copying your updates schema files over to the replicas and restarting them.
Anyhow, most folks managing LDAP servers seem to prefer using 3rd Party tools if they need a good GUI style interface, but it would be nice if the Web Admin Tool was a little less buggy.
But, if your goals for LDAP were simpler and you are not implementing an Identity Management solution, well you are limited to a few different tools to manage your LDAP directory:
Command Line tools such as ldapsearch, ldapadd, idsldapsearch, idsldapadd, etc....
TDS Web Admin Tool (GUI)
3rd Party tools such as Softerra's LDAP Administrator
Those who are new to LDAP in general and do not prefer to use command line tools, naturally gravitate to the TDS Web Admin Tool. In general its a pretty good tool and in TDS 6.2 it is much better than 6.0 for tasks such as setting up replication, but its still a bit buggy.
For example I ran into a problem recently where we had a boolean attribute configured as a mandatory attribute for our objectclass. Using TDS Web Admin Tool to create a new user entry results in an objectclass violation. Meanwhile using idsldapadd works just fine. It turned out to be a legitimate bug with a fix on the way, but there are other quirky issues with this tool.
Another problem I noticed in one case I have 5000 entries populated in the LDAP. If I navigate through the directory tree I can see the entries listed, but if I click on an entry it should open up the edit screen for that entry. Instead it does nothing at all. Yet, if I use the directory search tools in TDS Web Admin GUI I can find a specific entry and then click on the entry which correctly opens the edit screen for that same entry. Weird.
Another issue which I would consider a bug and I don't know if IBM will ever address this:
If I customize the LDAP Schema by using custom schema files I.e. V3.myschema.oc and V3.myschema.at, the Web Admin Tool does not acknowledge this and continues to drop stuff in V3.modifiedschema instead. TDS supports creating custom schema files by allowing you to reference the custom files in ibmslapd.conf. This is one way of keeping your custom schema organized neatly. In fact if you keep all of your custom attributes and classes in order by OID (assuming you are using a legitimately registered OID) then it makes it easy to know what OID to use next for any new attributes or classes. Also, if you have replicas, schema updates to the replicas is a simple matter of copying your updates schema files over to the replicas and restarting them.
Anyhow, most folks managing LDAP servers seem to prefer using 3rd Party tools if they need a good GUI style interface, but it would be nice if the Web Admin Tool was a little less buggy.
Thursday, November 26, 2009
AccessStudio vanishes?
Anyone who has spent any considerable amount of time profiling applications must have noticed this. Your toiling away on a profile for hours, testing some password change workflow or something and suddenly AccessStudio just disappears into thin air. And at least the first time you saw this it was probably after having made numerous changes in the state machine without saving your work right? And to top it off, trying to simply re-launch AccessStudio wont help, because there are still pieces of it running somewhere in Windows voodoo land so it will complain if you attempt to run another test session. Chalk it up to yet another reason to re-boot your Windows machine.
Sorry, I have no solution, but am looking out for one. I have seen this problem in 8.0.0 and 8.0.1 so maybe the new 8.1 version will be better. I look forward to upgrading.
Sorry, I have no solution, but am looking out for one. I have seen this problem in 8.0.0 and 8.0.1 so maybe the new 8.1 version will be better. I look forward to upgrading.
Thursday, November 19, 2009
TAM ESSO and support for Java
TAM ESSO supports Java applications for sure, but if you haven't deployed it yet there are a few issues which you might need to be aware of.
First, when you install AccessAgent on a computer, the installer will try and find any instances of Java on the computer and will add support for that Java. After installing AccessAgent find the directories on your computer where Java is installed and you should see the following files at these locations:
\jre\lib\accessiblity.properties
\jre\lib\ext\jaccess.jar
\jre\lib\ext\EncAwtAgent.jar
Some applications may get installed with their own Java. If the AccessAgent installer does not detect that Java then you will have problems profiling the Java application and AccessAgent will not detect the profile for SSO.
If you wish to add support for the application after AccessAgent has already been installed there is a script which you can run located here:
C:\Program Files\Encentuate>JavaSupport>
For example lets say you have a Java application called "XYZ App" installed which has its own instance of Java under its own program directory. Launch the script specifying the location of the JRE:
C:\Program Files\Encentuate\JavaSupport>JVMSupport.vbs /d C:\Program Files\XYZ App\jre
Going forward you would probably want to have AccessAgent support this Java on any machines with this application installed without having to go to all of your workstations to run this script. The JVM paths can be specified at the time you install the AccessAgent on end user machines. The SetupHlp.ini contains parameters for specifying these JVM paths. This part is clearly documented in the TAM ESSO installation and administration guides, but I'll mention it here:
SetupHelp.ini parameters:
JVMInstallationDirectories
OldJVMInstallationDirectories
AccessAgent Seems Slow?
One thing that seems relevant here is that AccessAgent can appear noticeably slower when profiling or testing with Java applications. By default AccessAgent is logging all activity at LogLevel=3. This is a pretty good level for debugging. However, normally for production you probably do not need the logging to be at this level. AccessAgent performs considerably better at LogLevel=1 or 0. So if you see issues with the profiles appearing slow especially for Java applications, you may want to go ahead and drop that LogLevel down:
HKEY_LOCAL_MACHINE\SOFTWARE\Encentuate\DeploymentOptions\
BTW, if AccessAgent seems slow, it may not be the fault of the LogLevel or TAM ESSO at all. There are other outside factors which could affect the performance of AccessAgent including some antivirus, but in most cases you will not notice any change in performance of your desktops with TAM ESSO. With all that is going on it performs excellent.
First, when you install AccessAgent on a computer, the installer will try and find any instances of Java on the computer and will add support for that Java. After installing AccessAgent find the directories on your computer where Java is installed and you should see the following files at these locations:
\jre\lib\accessiblity.properties
\jre\lib\ext\jaccess.jar
\jre\lib\ext\EncAwtAgent.jar
Some applications may get installed with their own Java. If the AccessAgent installer does not detect that Java then you will have problems profiling the Java application and AccessAgent will not detect the profile for SSO.
If you wish to add support for the application after AccessAgent has already been installed there is a script which you can run located here:
C:\Program Files\Encentuate>JavaSupport>
For example lets say you have a Java application called "XYZ App" installed which has its own instance of Java under its own program directory. Launch the script specifying the location of the JRE:
C:\Program Files\Encentuate\JavaSupport>JVMSupport.vbs /d C:\Program Files\XYZ App\jre
Going forward you would probably want to have AccessAgent support this Java on any machines with this application installed without having to go to all of your workstations to run this script. The JVM paths can be specified at the time you install the AccessAgent on end user machines. The SetupHlp.ini contains parameters for specifying these JVM paths. This part is clearly documented in the TAM ESSO installation and administration guides, but I'll mention it here:
SetupHelp.ini parameters:
JVMInstallationDirectories
OldJVMInstallationDirectories
AccessAgent Seems Slow?
One thing that seems relevant here is that AccessAgent can appear noticeably slower when profiling or testing with Java applications. By default AccessAgent is logging all activity at LogLevel=3. This is a pretty good level for debugging. However, normally for production you probably do not need the logging to be at this level. AccessAgent performs considerably better at LogLevel=1 or 0. So if you see issues with the profiles appearing slow especially for Java applications, you may want to go ahead and drop that LogLevel down:
HKEY_LOCAL_MACHINE\SOFTWARE\Encentuate\DeploymentOptions\
BTW, if AccessAgent seems slow, it may not be the fault of the LogLevel or TAM ESSO at all. There are other outside factors which could affect the performance of AccessAgent including some antivirus, but in most cases you will not notice any change in performance of your desktops with TAM ESSO. With all that is going on it performs excellent.
Monday, November 16, 2009
Change Listening Ports on your IMS Server
TAM ESSO IMS Server listens on ports 80 and 443 by default. Typically this is perfectly fine. However, you may have a situation in which you need to change these default ports and it is not well documented how to do this.
1.)Edit the server.xml file located at:\Encentuate\IMSServer8.x.x.x\conf
The following is an excerpt from my server.xml file. The lines to change are in bold. In my case I changed the default listening port to 89 and the redirect and connector port to 1443.
Connector
port="89"
minProcessors="5"
maxProcessors="400"
enableLookups="false"
redirectPort="1443"
acceptCount="100"
debug="0"
server="EWS/2.0"
connectionTimeout="20000"
useURIValidationHack="false"
disableUploadTimeout="true"
algorithm="IbmX509"
Connector
port="1443"
minProcessors="400"
maxProcessors="800"
enableLookups="false"
acceptCount="100"
debug="0"
scheme="https"
secure="true"
useURIValidationHack="false"
disableUploadTimeout="true"
clientAuth="false"
keystoreFile="ims/certs/keystore/ssl_keystore"
SSLImplementation="encentuate.tomcat.EncentuateSslImpl"
algorithm="IbmX509"
keyAlias="ims"
sslProtocol="SSL_TLS"
ciphers="SSL_RSA_WITH_RC4_128_MD5,SSL_RS
2.)Edit the accessAnywhere.properties file at:\Encentuate\IMSServer8.x.x.x\ims\config
Modify the port setting in the following stanza:
# The IMS Server's SSL port
IMS_SERVER_SSL_PORT=1443
3.)Restart the IMS Server for changes to take effect.
1.)Edit the server.xml file located at
The following is an excerpt from my server.xml file. The lines to change are in bold. In my case I changed the default listening port to 89 and the redirect and connector port to 1443.
Connector
port="89"
minProcessors="5"
maxProcessors="400"
enableLookups="false"
redirectPort="1443"
acceptCount="100"
debug="0"
server="EWS/2.0"
connectionTimeout="20000"
useURIValidationHack="false"
disableUploadTimeout="true"
algorithm="IbmX509"
Connector
port="1443"
minProcessors="400"
maxProcessors="800"
enableLookups="false"
acceptCount="100"
debug="0"
scheme="https"
secure="true"
useURIValidationHack="false"
disableUploadTimeout="true"
clientAuth="false"
keystoreFile="ims/certs/keystore/ssl_keystore"
SSLImplementation="encentuate.tomcat.EncentuateSslImpl"
algorithm="IbmX509"
keyAlias="ims"
sslProtocol="SSL_TLS"
ciphers="SSL_RSA_WITH_RC4_128_MD5,SSL_RS
2.)Edit the accessAnywhere.properties file at
Modify the port setting in the following stanza:
# The IMS Server's SSL port
IMS_SERVER_SSL_PORT=1443
3.)Restart the IMS Server for changes to take effect.
Saturday, October 10, 2009
Another Quirk with Tivoli Common Reporting...
Just thought I would mention this. The report package you download for Tivoli Common Reporting may produce an error like the following:
Error CTGTRD040E

To get around this I unzipped the report file and re-zipped it using WinRAR. For some reason TCR 1.1.1 has a problem with some zip files. Something about not liking directory names as zip file entries. Anyhow, WinRAR did the trick.
Error CTGTRD040E

To get around this I unzipped the report file and re-zipped it using WinRAR. For some reason TCR 1.1.1 has a problem with some zip files. Something about not liking directory names as zip file entries. Anyhow, WinRAR did the trick.
Can't find TAMeB Reports?
Just in case you are hunting and pecking for reports for TAMeB using Tivoli Common Reporting, I assume you've seen the documentation for auditing TAMeB. It's only 500+ pages. :-)
The basic idea is that you will first install Tivoli Common Reporting (integrated in the WebSphere Integrated System Console). Then you need to download the reports from the support web site. Why they don't simply include these with TAM is a mystery. Oh and good luck finding them by searching reports, or audit reports, etc.... If you search for "Operational Reports" you will find them. Go figure.
Anyhow the link to the reports:
http://www-01.ibm.com/support/docview.wss?rs=638&context=SSPREK&q1=operational+reports&uid=swg21303439&loc=en_US&cs=utf-8&lang=en
The basic idea is that you will first install Tivoli Common Reporting (integrated in the WebSphere Integrated System Console). Then you need to download the reports from the support web site. Why they don't simply include these with TAM is a mystery. Oh and good luck finding them by searching reports, or audit reports, etc.... If you search for "Operational Reports" you will find them. Go figure.
Anyhow the link to the reports:
http://www-01.ibm.com/support/docview.wss?rs=638&context=SSPREK&q1=operational+reports&uid=swg21303439&loc=en_US&cs=utf-8&lang=en
Tuesday, August 4, 2009
TDI 7 - Eclipse anyone?
So I think that most of us using TDI over the past few years can say mostly good things about the product. Personally it's one of my favorite tools in the Tivoli Security stack being largely a non-developer type I feel empowered when I make cool things work with it. However most people would also agree that the products implementation of Swing might be a bit off. Just weird stuff like if you have a pop up window and you hit the enter key you expect the OK button to depress. And sometimes resizing windows is a little weird. I've even had to close the tool kit and reopen it sometimes just to make things work.
All that is pretty much gone with the new TDI 7.0. Oh and I believe there is a fix pack out already. I'm just starting to play with this new version. It takes some getting used to if your not comfortable with eclipse, but I look forward to working with it.
BTW, there is a pretty cool tutorial out there you can check out:
http://sites.google.com/site/tdi7islive/
Nice job who ever took the time to do this!
All that is pretty much gone with the new TDI 7.0. Oh and I believe there is a fix pack out already. I'm just starting to play with this new version. It takes some getting used to if your not comfortable with eclipse, but I look forward to working with it.
BTW, there is a pretty cool tutorial out there you can check out:
http://sites.google.com/site/tdi7islive/
Nice job who ever took the time to do this!
Wednesday, July 8, 2009
Risk - ignore, accept, mitigate, insure
Tivoli security professionals are pretty much in the Risk Mitigation business. Any organization who has any identity information in house on employees, customers, or partners will at some point address the risk of losing this information. And subsequently they will ask:
"What's the chance of losing that information?"
"What's the cost to us if that information gets lost?"
"What should we do about it?"
The answers are undoubtedly, ignore the risk, accept the risk, mitigate against that risk, or just buy some extra insurance.
Organizations large and small are thinking about how important it is to deprovision accounts that are no longer needed. Doing this via e-mail is not going to work well. This is one main reason Identity Management systems exist.
These latest security breaches illustrate the headaches organizations face when they fail to ensure that their former employees are removed from accessing their IT systems:
http://datalossdb.org/incidents/2152-unauthorized-access-by-a-former-employee-exposes-names-addresses-and-social-security-numbers-of-past-and-present-employees
And this one was even more brazen by an American Express employee. Holy crap $1 million. This guy had a good job watching over the systems that hold data for many of us. I'm not sure how you prove that a laptop which is reported stolen wasn't really stolen. This dude should go to jail for a long time.
http://www.kpho.com/money/19936013/detail.html
"What's the chance of losing that information?"
"What's the cost to us if that information gets lost?"
"What should we do about it?"
The answers are undoubtedly, ignore the risk, accept the risk, mitigate against that risk, or just buy some extra insurance.
Organizations large and small are thinking about how important it is to deprovision accounts that are no longer needed. Doing this via e-mail is not going to work well. This is one main reason Identity Management systems exist.
These latest security breaches illustrate the headaches organizations face when they fail to ensure that their former employees are removed from accessing their IT systems:
http://datalossdb.org/incidents/2152-unauthorized-access-by-a-former-employee-exposes-names-addresses-and-social-security-numbers-of-past-and-present-employees
And this one was even more brazen by an American Express employee. Holy crap $1 million. This guy had a good job watching over the systems that hold data for many of us. I'm not sure how you prove that a laptop which is reported stolen wasn't really stolen. This dude should go to jail for a long time.
http://www.kpho.com/money/19936013/detail.html
Why hire consultants?
I have always thought of myself as a consultant. Perhaps I'm just a people pleaser, not to the extreme that I'm compulsive or anything, but that I genuinely like to help others. I can recall the days when DOS 5 was a huge deal. I was networking computers using ArcNet, LANTastic and Novell 3. A 386 DX2/66 with 4MB of RAM was smoke'n fast.
I recall some of the best advice I got from a guy named John Posey (John if your still out there thanks for all your help). He said, "Chuck, run out and buy yourself a DOS book." The past mystery of my Commodore 64 seemed silly once I read that DOS book. It was clear to me then that if one could read, one could do this technology stuff. Oh how things have gotten so complicated.
So, why should you hire consultants?
1.) Well, look I understand all you geeks out there who are highly skilled can certainly figure all this stuff out yourself. Like I just said, if you can read, you'll get there eventually. But, the bottom line is there just isn't time for everyone to know everything. Take TIM, TAMeB, TFIM, TAM ESSO, TCIM, TSOM, and the rest of the Tivoli Security products. If you want to implement any one of these or some of them, you can certainly buy the software, read the manuals and go for it. The fact is though, it doesn't always work like the manual says. So, you may have to do it a few times until its right. And that's OK. But, businesses today are more concerned with ensuring that the technology is solving business needs. They are not necessarily interested in making you an expert at installing Tivoli software. That perhaps is better left to consultants.
2.) Good consultants are in this game because they like to help people. At least that's the experience I have seen with the colleagues I work with. And the objective is to enable customers to be self sufficient in steady state maintainability of the products and solutions.
3.) We really have seen many use cases, configurations and different applications of these software products so you can save a ton of time in the planning phases of your projects by using consultants.
4.) Consultants in the security business have a lot of friends doing the same thing which can help in getting the right skills on the job. Solutions using enterprise software like Tivoli will often require many different skills. There will rarely be one guy/gal who can do it all. Although I've worked with some amazingly bright people in this business, there are usually multiple people involved in average Identity Management projects. Utilizing a good consulting group will help you succeed. For Tivoli, an IBM Business Partner is key for a couple reasons:
a.) IBM Business Partners have unique relationships with IBM which helps to deliver solutions most cost effectively.
b.) IBM Business Partners can bring versatile project management skills to your project which may involve IBM and Non-IBM products and solutions
c.) IBM Business Partners can bring low cost resources into your project as well as subcontracted IBM resources which helps to drive down the cost of your project while maintaining a strong IBM presence in the success of the project
d.) IBM Business Partners have a vested interest in seeing the IBM solution succeed.
5.) Good consultants will pass on their experience and knowledge to you. I tend to share as much as I know because I believe in educating people, I will also learn some new things. Every good project should have some time dedicated to knowledge transfer, but even when that dedicated time is not there, you will still learn a lot from a good consultant.
6.) Consultants save you time and money in the long run. Lets face it, time is money. If a project is being managed properly, there will be some realistic goals and objectives. If the goal is say 6 months from now we will have xyz product installed and configured and you already have a full time job, then how likely will you meet that goal? Hire the consultant and get the job done.
I recall some of the best advice I got from a guy named John Posey (John if your still out there thanks for all your help). He said, "Chuck, run out and buy yourself a DOS book." The past mystery of my Commodore 64 seemed silly once I read that DOS book. It was clear to me then that if one could read, one could do this technology stuff. Oh how things have gotten so complicated.
So, why should you hire consultants?
1.) Well, look I understand all you geeks out there who are highly skilled can certainly figure all this stuff out yourself. Like I just said, if you can read, you'll get there eventually. But, the bottom line is there just isn't time for everyone to know everything. Take TIM, TAMeB, TFIM, TAM ESSO, TCIM, TSOM, and the rest of the Tivoli Security products. If you want to implement any one of these or some of them, you can certainly buy the software, read the manuals and go for it. The fact is though, it doesn't always work like the manual says. So, you may have to do it a few times until its right. And that's OK. But, businesses today are more concerned with ensuring that the technology is solving business needs. They are not necessarily interested in making you an expert at installing Tivoli software. That perhaps is better left to consultants.
2.) Good consultants are in this game because they like to help people. At least that's the experience I have seen with the colleagues I work with. And the objective is to enable customers to be self sufficient in steady state maintainability of the products and solutions.
3.) We really have seen many use cases, configurations and different applications of these software products so you can save a ton of time in the planning phases of your projects by using consultants.
4.) Consultants in the security business have a lot of friends doing the same thing which can help in getting the right skills on the job. Solutions using enterprise software like Tivoli will often require many different skills. There will rarely be one guy/gal who can do it all. Although I've worked with some amazingly bright people in this business, there are usually multiple people involved in average Identity Management projects. Utilizing a good consulting group will help you succeed. For Tivoli, an IBM Business Partner is key for a couple reasons:
a.) IBM Business Partners have unique relationships with IBM which helps to deliver solutions most cost effectively.
b.) IBM Business Partners can bring versatile project management skills to your project which may involve IBM and Non-IBM products and solutions
c.) IBM Business Partners can bring low cost resources into your project as well as subcontracted IBM resources which helps to drive down the cost of your project while maintaining a strong IBM presence in the success of the project
d.) IBM Business Partners have a vested interest in seeing the IBM solution succeed.
5.) Good consultants will pass on their experience and knowledge to you. I tend to share as much as I know because I believe in educating people, I will also learn some new things. Every good project should have some time dedicated to knowledge transfer, but even when that dedicated time is not there, you will still learn a lot from a good consultant.
6.) Consultants save you time and money in the long run. Lets face it, time is money. If a project is being managed properly, there will be some realistic goals and objectives. If the goal is say 6 months from now we will have xyz product installed and configured and you already have a full time job, then how likely will you meet that goal? Hire the consultant and get the job done.
Tuesday, June 30, 2009
Changing LDAP Suffix
Of course when building an LDAP it's best practice to choose wisely and carefully your LDAP structure to minimize any ugly rework later. This is a no brainer. But, I've been working on setting up a demo test system for TFIM. And, as I am not a web developer I'm going to use the demo apps that come with Tivoli Federated Identity Manager 6.1. But this Federation demo assumes that there are specific configurations done in your LDAP first.
Now, I already had a working TAMeB system with TDS and WAS, etc.... So I wanted to use what I had to minimize the work in setting up TFIM. I built another TAMeB environment to act as my partner site as well. Installing TFIM and creating the Federation domain was no problem. Even creating the Federation agreements and exporting both sides was straight forward. But when it came to configuring TAM for TFIM I ran into an unforeseen snag at the point where this program wants to configure for the demo apps:
tam:/opt/IBM/FIM/tools/tamcfg # java -jar ./tfimcfg.jar -action tamconfig -cfgfile /opt/pdweb/etc/webseald-default.conf
...
Press 1 for Next, 2 for Previous, 3 to Repeat, C to Cancel: 1
Perform configuration for demo application (y/n): y
Checking for DN cn=elain,o=identityprovider,dc=com.
FBTTAC062E Error checking for the DN cn=elain,o=identityprovider,dc=com in the user registry:
HPDMG0761W The entry referred to by the Distinguished Name (DN) must be a person entry.
You may need to create this registry entry manually or use the itfim-pre-install-tool.jar to create it for you.
Press 1 to Repeat, 2 for Previous, C to Cancel:
So, I really didn't consider that the demo apps for TFIM would be relying on specific users to exist in TAM/LDAP and even a specific LDAP structure. This is sort of lame. I need these demo apps for my testing, yet I'm forced to have a specific set of users and LDAP design. Annoying.
I set to work making the necessary changes to my LDAP, however one problem was that my suffix was already dc=ca,dc=com and the LDAP will not allow me to create a new object for the demo "o=identityprovider,dc=com". This means I need a new suffix at dc=com which the LDAP will not allow since a suffix already exists containing dc=com. No worries, I figure I'll just do a db2ldif and export my users and groups, etc... (TAM is using these already), then blow out the LDAP, delete the existing suffix and create a new one "dc=com", then just add the "dc=ca" domain under the suffix and finally do a ldif2db.
This all worked right up until I realized that the ACLs do not go back into the LDAP. The db2ldif utility will capture the ACLs and they will be right there in your LDIF file, but for some reason when you use the ldif2db these ACLs do not go back into the LDAP. Additionally I tried a bulkload with the -A and still no ACLs. I know that I must be missing something. Rather than spend a lot of time troubleshooting this I ended up configuring the ACLs for TAM manually on my "dc=com" object so that I could get back to business. If anyone knows what I may have missed, feel free to let me know.
Regards
Now, I already had a working TAMeB system with TDS and WAS, etc.... So I wanted to use what I had to minimize the work in setting up TFIM. I built another TAMeB environment to act as my partner site as well. Installing TFIM and creating the Federation domain was no problem. Even creating the Federation agreements and exporting both sides was straight forward. But when it came to configuring TAM for TFIM I ran into an unforeseen snag at the point where this program wants to configure for the demo apps:
tam:/opt/IBM/FIM/tools/tamcfg # java -jar ./tfimcfg.jar -action tamconfig -cfgfile /opt/pdweb/etc/webseald-default.conf
...
Press 1 for Next, 2 for Previous, 3 to Repeat, C to Cancel: 1
Perform configuration for demo application (y/n): y
Checking for DN cn=elain,o=identityprovider,dc=com.
FBTTAC062E Error checking for the DN cn=elain,o=identityprovider,dc=com in the user registry:
HPDMG0761W The entry referred to by the Distinguished Name (DN) must be a person entry.
You may need to create this registry entry manually or use the itfim-pre-install-tool.jar to create it for you.
Press 1 to Repeat, 2 for Previous, C to Cancel:
So, I really didn't consider that the demo apps for TFIM would be relying on specific users to exist in TAM/LDAP and even a specific LDAP structure. This is sort of lame. I need these demo apps for my testing, yet I'm forced to have a specific set of users and LDAP design. Annoying.
I set to work making the necessary changes to my LDAP, however one problem was that my suffix was already dc=ca,dc=com and the LDAP will not allow me to create a new object for the demo "o=identityprovider,dc=com". This means I need a new suffix at dc=com which the LDAP will not allow since a suffix already exists containing dc=com. No worries, I figure I'll just do a db2ldif and export my users and groups, etc... (TAM is using these already), then blow out the LDAP, delete the existing suffix and create a new one "dc=com", then just add the "dc=ca" domain under the suffix and finally do a ldif2db.
This all worked right up until I realized that the ACLs do not go back into the LDAP. The db2ldif utility will capture the ACLs and they will be right there in your LDIF file, but for some reason when you use the ldif2db these ACLs do not go back into the LDAP. Additionally I tried a bulkload with the -A and still no ACLs. I know that I must be missing something. Rather than spend a lot of time troubleshooting this I ended up configuring the ACLs for TAM manually on my "dc=com" object so that I could get back to business. If anyone knows what I may have missed, feel free to let me know.
Regards
Wednesday, June 3, 2009
Which product version do you have?
The Tivoli security products contain several components and middleware making it sometimes difficult to know exactly what versions and fix packs you are at for all of the pieces. Also, you may only need this information once in a while maybe for troubleshooting a problem or planning some upgrade or change to the environment. So you ask, "what was that command again to determine the version of TIM, TAM, WAS, TDI, etc...? And as usual for every piece of the puzzle the commands or procedure for determining the versions and fix packs are different. Then, finding this information on the IBM Support site or the Information Center for some pieces is difficult. You would think that for each product the first chapter of the Problem Determination Guide would start with "How to determine your product version and fix pack level". NOT!
I'm simply listing here the results of my hour and 1/2 of internet searches here to hopefully save time when I need this info again. There are by the way some very good IBM Wiki sites for this info. I've listed some below. It's crazy though that these Wiki's did not show up in my searches of the IBM Support site.
Check Version Info for TDS 5.2
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21268258&loc=en_US&cs=utf-8&lang=en
Example:
rpm –qa | grep ldap
rpm –qa | grep db2
rpm –qa | grep gsk
ls –l /usr/ldap/bin
ibmslapd -V
If the Web Administration Tool is installed and configured please collect the output of:
ls -l /usr/ldap/idstools/IDSWebApp.war
Check for version info for TDS 6.0
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21268261&loc=en_US&cs=utf-8&lang=en
Example:
rpm -qa | grep -i ldap
rpm -qa | grep -i db2
rpm -qa | grep -i gsk
ibmslapd -V
idsilist -a
If the Web Administration Tool is installed and configured collect the output from:
./opt/ibm/ldap/V6.0/idstools/deploy_IDSWebApp.sh -v
Check for version info for TDS 6.1
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21268263&loc=en_US&cs=utf-8&lang=en
Example:
/opt/ibm/ldap/V6.1/bin/idsversion
rpm -qa | grep -i gsk
idsilist -a
If you are using DB2 v9.1 or higher issue the following command:
/usr/local/bin/db2ls
Otherwise issue:
rpm -qa | grep -i db2
If the Web Administration Tool is installed and configured, please collect the following:
/opt/IBM/ldap/V6.1/idstools/deploy_IDSWebApp -v
Check version of the TDS Web Admin Tool (Any version)
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21320615&loc=en_US&cs=utf-8&lang=en
Check for Version of WebSphere
http://www-01.ibm.com/support/docview.wss?rs=638&context=SSPREK&q1=version&uid=swg21306756&loc=en_US&cs=utf-8&lang=en
Example:
versionInfo.sh in the app_server_root\bin directory.
Check for version info for TAMeB
http://www.ibm.com/software/info/testinfo.jsp?uid=IC000043
Example:
pdversion
Check for version info for TIM
http://www.ibm.com/developerworks/wikis/display/tivoliim/Determining+Product+Fixpack+Levels
From the TIM Admin Console, open the "About" page
Example:
Server name: secperf12
Version: 5.0.0.3
Build number: 200809241018
Maintenance level: IF0014
Build date: September 24 2008
Build time: 10:18:08 GMT-05:00
Check for version info for GSKit
http://www.ibm.com/developerworks/wikis/display/tivoliim/Determining+IBM+GSKit+Fixpack+Level
Check for version info for TDI 6.0
http://www.ibm.com/developerworks/wikis/display/tivoliim/Determining+IBM+Tivoli+Directory+Integrator+Fixpack+Level
Check for version info for TDI 6.1
http://www-01.ibm.com/support/docview.wss?uid=swg21302983
Example:
Unix/Linux -
1) cd /usr/ibm/common/acsi/bin
2) //source the setenv.sh
. /var/ibm/common/acsi/setenv.sh
3) //run the listIU.sh
./listIU.sh | grep -i tdiserversiu
Check for version info for TIM Agents
http://www-01.ibm.com/support/docview.wss?rs=644&context=SSTFWV&dc=DA420&dc=DA480&dc=DA490&dc=DA430&dc=DA410&dc=DB600&dc=DA400&dc=D600&dc=D700&d
c=DB520&dc=DB510&dc=DA500&dc=DA470&dc=DA4A20&dc=DA460&dc=DA440&dc=DB550&dc=DB560&dc=DB700&dc=DB530&dc=DA4A10&dc=DA4A30&dc=DB540&q1=version&uid=s
wg21140454&loc=en_US&cs=utf-8&lang=en
Example:
Run agentCfg -> Configuration Settings
I'm simply listing here the results of my hour and 1/2 of internet searches here to hopefully save time when I need this info again. There are by the way some very good IBM Wiki sites for this info. I've listed some below. It's crazy though that these Wiki's did not show up in my searches of the IBM Support site.
Check Version Info for TDS 5.2
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21268258&loc=en_US&cs=utf-8&lang=en
Example:
rpm –qa | grep ldap
rpm –qa | grep db2
rpm –qa | grep gsk
ls –l /usr/ldap/bin
ibmslapd -V
If the Web Administration Tool is installed and configured please collect the output of:
ls -l /usr/ldap/idstools/IDSWebApp.war
Check for version info for TDS 6.0
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21268261&loc=en_US&cs=utf-8&lang=en
Example:
rpm -qa | grep -i ldap
rpm -qa | grep -i db2
rpm -qa | grep -i gsk
ibmslapd -V
idsilist -a
If the Web Administration Tool is installed and configured collect the output from:
./opt/ibm/ldap/V6.0/idstools/deploy_IDSWebApp.sh -v
Check for version info for TDS 6.1
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21268263&loc=en_US&cs=utf-8&lang=en
Example:
/opt/ibm/ldap/V6.1/bin/idsversion
rpm -qa | grep -i gsk
idsilist -a
If you are using DB2 v9.1 or higher issue the following command:
/usr/local/bin/db2ls
Otherwise issue:
rpm -qa | grep -i db2
If the Web Administration Tool is installed and configured, please collect the following:
/opt/IBM/ldap/V6.1/idstools/deploy_IDSWebApp -v
Check version of the TDS Web Admin Tool (Any version)
http://www-01.ibm.com/support/docview.wss?rs=767&context=SSVJJU&q1=version&uid=swg21320615&loc=en_US&cs=utf-8&lang=en
Check for Version of WebSphere
http://www-01.ibm.com/support/docview.wss?rs=638&context=SSPREK&q1=version&uid=swg21306756&loc=en_US&cs=utf-8&lang=en
Example:
versionInfo.sh in the app_server_root\bin directory.
Check for version info for TAMeB
http://www.ibm.com/software/info/testinfo.jsp?uid=IC000043
Example:
pdversion
Check for version info for TIM
http://www.ibm.com/developerworks/wikis/display/tivoliim/Determining+Product+Fixpack+Levels
From the TIM Admin Console, open the "About" page
Example:
Server name: secperf12
Version: 5.0.0.3
Build number: 200809241018
Maintenance level: IF0014
Build date: September 24 2008
Build time: 10:18:08 GMT-05:00
Check for version info for GSKit
http://www.ibm.com/developerworks/wikis/display/tivoliim/Determining+IBM+GSKit+Fixpack+Level
Check for version info for TDI 6.0
http://www.ibm.com/developerworks/wikis/display/tivoliim/Determining+IBM+Tivoli+Directory+Integrator+Fixpack+Level
Check for version info for TDI 6.1
http://www-01.ibm.com/support/docview.wss?uid=swg21302983
Example:
Unix/Linux -
1) cd /usr/ibm/common/acsi/bin
2) //source the setenv.sh
. /var/ibm/common/acsi/setenv.sh
3) //run the listIU.sh
./listIU.sh | grep -i tdiserversiu
Check for version info for TIM Agents
http://www-01.ibm.com/support/docview.wss?rs=644&context=SSTFWV&dc=DA420&dc=DA480&dc=DA490&dc=DA430&dc=DA410&dc=DB600&dc=DA400&dc=D600&dc=D700&d
c=DB520&dc=DB510&dc=DA500&dc=DA470&dc=DA4A20&dc=DA460&dc=DA440&dc=DB550&dc=DB560&dc=DB700&dc=DB530&dc=DA4A10&dc=DA4A30&dc=DB540&q1=version&uid=s
wg21140454&loc=en_US&cs=utf-8&lang=en
Example:
Run agentCfg -> Configuration Settings
Subscribe to:
Posts (Atom)
