Friday, January 12, 2007

SSO Between TIM and TAM

Well, this week we had some success. SSO now works well between TIM and TAM. This was relatively easy following the ITIM Information Center documentation. It really amounted to creating a TCP Junction from WebSeal to TAM, create an ACL and tweaking a few properties files on the TIM Server. Once we restarted WAS on the TIM server we were able to web to TIM via webseal and if I logged into TAM I was already authenticated to TIM. Cool. At this stage of the game I am easily impressed. :-)

Cool Tools to help manage ITIM

One of our friends at IBM let us in on these two handy tools for ITIM Administrators. The Graphical Configuration Editor (GCE) is an Eclipse based tool that will connect to your ITIM Server and download all of the objects, workflow, policies, etc... into an ICE Project. In the GCE you can develop your ITIM environment and then import your changes back into ITIM. This seems like a really good tool to use when testing things out in Development, then moving to Test region, and then again to Production. This way you do not have to do everything by hand multiple times as you move from development to production. This tool installs on Unix or Windows environments and is generally used on your development workstation.

The other tool ITIM DocTool must be installed directly on the ITIM Server. It works for Unix or Windows environments and will read your entire ITIM Configuration into either an HTML or an XML file. This is pretty cool, because if you walk into an environment you are unfamiliar with you can just run this tool and review the associated documentation to get an understanding of the environment. It's also a useful tool in tech support scenarios where IBM Tech Support needs to understand how things are set up.

You can find these tools at http://www-18.lotus.com/wps/portal/tim . It happens to be currently in the new column over on the right hand side of the web page and can be downloaded from there. BTW, there is a really nice flash demo of the GCE. I attached it here in the downloads.

Now the only problem I had was with the GCE. I installed it fine and can run the tool. Note that you must be using an IBM JRE for it to work. I could create a new project and specify the ITIM Server properties so that the GCE can connect to ITIM. However, when I click File -> Import then choose the project to import to, enter the user name and password for itim manager, the CGE connects to the ITIM Server then just stops. I cannot click Next as expected and there is a message in the dialog box that says "Properties.properties". See the screen below:


There is a log file available. If you Cancel the import dialog, then from the main GCE window click Help -> About GCE, then click Configuration Details there is a button for the error log:


So the error I'm getting is this:

!SESSION 2007-01-12 10:40:50.379 -----------------------------------------------
eclipse.buildId=unknown
java.fullversion=J2RE 1.5.0 IBM J9 2.3 Windows XP x86-32 j9vmwi3223-20060222a (JIT enabled)
J9VM - 20060220_05389_lHdSMR
JIT - 20060220_2133_r8
GC - 20060214_AA
BootLoader constants: OS=win32, ARCH=x86, WS=win32, NL=en_US
Command-line arguments: -os win32 -ws win32 -arch x86

!ENTRY 1.2.2 4 0 2007-01-12 10:56:52.553
!MESSAGE Unexpected Exception
!STACK 0
com.ibm.itim.apps.exception.AppProcessingException: Properties.properties
at com.ibm.itim.apps.UserAuthInfo.(UserAuthInfo.java:224)
at com.ibm.itim.apps.UserAuthInfo.(UserAuthInfo.java:205)


I started poking around the Server Configuration Properties and I noticed that there is a Server Type property. When you click that drop down there seems to be different types depending on which FixPack you are running on your ITIM.



I initially chose the item without a fixpack, even though I am running FixPack 28. FP28 isn't a choice in the Server Type property. I tried a few of the options and it did not make a difference. 1st of all I don't even know if this is my problem, but if it is then I guess I'll have to wait until IBM releases an update. It appears that you can't get support for either of these two tools because they are on an as is basis.

Monday, January 8, 2007

ITIM Self Care Examples

ITIM 4.6 installs with a self care application that you have to do some work with to set it up. On linux this should be in the /opt/IBM/itim/extensions/example/self_care directory. There is a readme.html file which is pretty good. I didn't have any problem at all getting this up and running following the instructions.

I will say though that when I self registered some users, I never received the emails that were supposed to be sent to each user. Not sure why. Also now that I enabled the challenge/response, every time I login to ITIM, I'm prompted to answer a challenge question. I'll have to play with this a bit yet.

I thought that this was going to be primarily a tool that existing users could use, but it also has self registration functionality already built in so a user can create a new identity. What would be cool is if TIM could automatically suspend or disable accounts that are not active after some specified amount of time or something. I can just see users creating tons of accounts over and over again as they can't remember what their user id was in the first place. Anyhow, it's worth taking a look.

TIM/TAM Helpful docs

A bit dated, but still very useful, this Identity and Access Management solutions document is a good read. Well it's not exactly the latest Dean Koontz novel, but as geek material goes it is pretty good. This will walk you through the entire process of design and implementation of a fairly simple ITIM and TAM solution.

http://www.redbooks.ibm.com/abstracts/sg246692.html?open

Also, if you have any Portal developers on staff then you may want to pass alonng these docs for using the ITIM API to develop password management and self care in Portal:

http://www-128.ibm.com/developerworks/tivoli/library/t-itimwsad/index.html
http://www-128.ibm.com/developerworks/tivoli/library/t-timapi/index.html
http://www-128.ibm.com/developerworks/tivoli/library/t-itimapi/index.html

Sunday, January 7, 2007

Planning your TIM/TAM Server Environment

If your trying to deploy TIM and TAM the one thing it seems you cannot get away from is lots of servers. If your doing your project for thousands of users then plan on setting up 3 environments:

Sandbox (development)
Test
Production

Sandbox

Your Sandbox environment is where you will do your initial development and testing. This does not require a lot of physical servers, but will require VMs so expect to make an investment in memory. The sandbox may contain a test version of many of your target resources even so it's not just TIM and TAM you have to consider. My sandbox is a Dell PowerEdge 2650. It's a Dual Xeon machine with 12GB RAM and 250GB RAID 5. The Host OS is Windows Server 2003 Enterprise Edition. VMWare GSX Server runs 12 VMs on this box. I figure on being able to run about 16 VMs max. Here's my list of sandbox servers:

TAM Policy Server (SLES 9, 1GB RAM, 10GB Virtual Disk)
TAM Authorization Server (SLES 9, 1GB RAM, 10GB Virtual Disk)
TAM WebSeal Server (SLES 9, 1GB RAM, 10GB Virtual Disk)
TAM WPM Server (SLES 9, 1GB RAM, 10GB Virtual Disk)
TDS Server 1 (SLES 9, 1GB RAM, 8GB Virtual Disk)
TDS Server 2 (SLES 9, 1GB RAM, 8GB Virtual Disk)
ITIM Server (SLES 9, 2GB RAM, 8GB Virtual Disk)
Active Directory Server 1 (Windows Server 2003 Std, 1GB RAM, 8GB Virtual Disk)
Active Directory Server 2 (Windows Server 2003 Std, 1GB RAM, 8GB Virtual Disk) *Also have Domino 6.5 installed for some testing
Novell eDirectory Server 1 (SLES 9, 1GB RAM, 8GB Virtual Disk)
Domino Server 1 (SLES 9, 1GB RAM, 8GB Virtual Disk)
TDI Server 1 (Windows 2000, 1GB RAM, 20GB Disk)

Test

The test environment needs to more closely mirror your production environment. In this environment you should be testing the processes and code developed in your sandbox against target resources that closely emulate production target resources. You may have test portal servers in this environment as well. This environment may also be a part of other peoples test environments. In my case the Portal Development Team will have to place their test Portal systems behind the TAM Test security environment. We will have to have the Test ITIM system provision users to the Test Portal and other Test resources that other departments use this way the other teams affected by TIM and TAM can work closely with us for testing before things get moved to production. I have not yet set this environment up yet, but when I do it might look something like this:

TAM Policy Server (SLES 9, 1GB RAM, 20GB Virtual Disk)
TAM Authorization Server (SLES 9, 1GB RAM, 20GB Virtual Disk)
TAM WebSeal Server 1 (SLES 9, 1GB RAM, 20GB Virtual Disk)
TAM WebSeal Server 2 (SLES 9, 1GB RAM, 20GB Virtual Disk)
TAM WPM Server (SLES 9, 1GB RAM, 20GB Virtual Disk)
TDS Server 1 (SLES 9, 1GB RAM, 40GB Virtual Disk)
TDS Server 2 (SLES 9, 1GB RAM, 40GB Virtual Disk)
ITIM Server (SLES 9, 1GB RAM, 20GB Virtual Disk)
ITIM LDAP (SLES 9, 1GB RAM, 40GB Virtual Disk)
ITIM DB Server (SLES 9, 2GB RAM, 40GB Virtual Disk)
TDI Server (Windows 2003 Std, 2GB RAM, 40GB Virtual Disk)

Other Servers - Test servers acting as managed resources or feeds belonging to other support teams could include Domino, WebSphere, Novell, Active Directory, and several others. These servers should be managed by the various support teams that support these systems in production.

Production

Since we are still doing the architecture project in our environment I'll post something about the production servers later. It will look a lot like the Test environment, however we will also be using load balancers for the items that are being clustered (TDS and WebSeal).

ITIM - Organization Design Tips #1 and #2

As I work with the pros trying to build our Identity and Access Management system one of my goals is to learn as much as possible along the way. The pros I'm referring to are top business partners like SCS and SPS or the guys/gals straight from the Tivoli Software group.

The first tips I've learned is regarding the ITIM Organization tree:

1.) It's all about admin - The tree needs to be designed based on who will be managing it. If you are delegating administration of the ITIM to departments, divisions, countries, cities or buildings then it makes sense to organize it in such a way that users are grouped into "administration containers".

2.) 1000 or less is best - ITIM will have performance and usability issues if you place more than 1000 or so users into a container. It's helpful to keep your containers under that number. So you may have to divide the users up. In my case we have thousands of users so we might be looking at 5 or 6 levels deep.

A good brain melting

It's been a while since I've posted, but the best excuse I can come up with is that my brain has been melting as I try to absorb all the technical and nontechnical issues with implementing TIM and TAM.

The last several weeks I've spent most of my days and nights reading mountains of documentation, taking Tivoli Web Courses and building a sandbox for testing and development. I've come across several items that I thought would be good topics for the blog, but I failed to follow through which is something I plan to work on.

The nontechnical part of architecting a TIM and TAM implementation can be a bit tougher than the technical stuff. I've spent a good deal of time in the last few weeks talking to application owners and HR people, electronic forms people to try and figure out what roles are already defined, what roles still need defining, where are we getting feeds from, how clean is the data coming in from those feeds, etc.... This can be mind numbing. The best advice I can pass along which has been passed along to me is Simplify. Try to temper the expectations, take the complex and break it down into simpler parts. Keep in mind that the Identity and Access Management system is an evolving system.