<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8518653425045114792</id><updated>2011-11-28T05:15:20.691+05:30</updated><category term='IBM'/><category term='directory server crash'/><category term='webseal'/><category term='SMS'/><category term='Objectgrid'/><category term='tivoli common reporting'/><category term='reconfigure policy server'/><category term='common auditng and reporting service'/><category term='MPS failover'/><category term='node agent'/><category term='Policy Server failover'/><category term='synchronization'/><category term='websphere application server'/><category term='master policy server'/><category term='tivoli access manager'/><category term='Tivoli'/><category term='reconfigure webseal'/><category term='Laxmanareddy'/><category term='eventxml'/><category term='Session Management Server'/><category term='Cluster'/><category term='WebSphere'/><category term='cars'/><title type='text'>Tivoli Access Manager</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>21</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-7622180069887766666</id><published>2011-03-02T01:10:00.001+05:30</published><updated>2011-03-02T01:14:24.503+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='synchronization'/><category scheme='http://www.blogger.com/atom/ns#' term='websphere application server'/><category scheme='http://www.blogger.com/atom/ns#' term='node agent'/><title type='text'>WebSphere - Node synchronization status shows as question mark</title><content type='html'>In this case you need to manually synchronize the node with Deployment Manager/NDM.&lt;br /&gt;&lt;br /&gt;Go to node bin directory and run the following command. Please make sure nodeagent and node is stopped.&lt;br /&gt;&lt;br /&gt;syncNode.sh 'deployment Manager Host Name' 'soap Connector Port-8879' -username wasadmin -password 'password'&lt;br /&gt;&lt;br /&gt;Start nodeagent and see if the synchronization status is green. Then start the node.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-7622180069887766666?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/7622180069887766666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=7622180069887766666' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/7622180069887766666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/7622180069887766666'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2011/03/websphere-node-synchronization-status.html' title='WebSphere - Node synchronization status shows as question mark'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-6139166360929567743</id><published>2010-08-26T03:16:00.000+05:30</published><updated>2010-08-26T03:16:56.344+05:30</updated><title type='text'>Reconfigure WebSEAL after the crash</title><content type='html'>You might run into a situation where the server on which WebSEAL instance is configured just crashes or gets rebuilt without an opportunity to unconfigure the WebSEAL instance.&lt;br /&gt;&lt;br /&gt;WebSEAL reconfiguration will fail with the following error:&lt;br /&gt;&lt;br /&gt;HPDMG0759W   The user name already exists in the registry.&lt;br /&gt;&lt;br /&gt;You need to delete the user from TAM registry with user name "default-webseald-&lt;instance-name&gt;" before you can reconfigure WebSEAL instance.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-6139166360929567743?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/6139166360929567743/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=6139166360929567743' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/6139166360929567743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/6139166360929567743'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2010/08/reconfigure-webseal-after-crash.html' title='Reconfigure WebSEAL after the crash'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-1891023513716950863</id><published>2010-08-24T03:12:00.001+05:30</published><updated>2010-08-24T03:12:29.902+05:30</updated><title type='text'>WebSEAL SSO Configuration with SAP Portal</title><content type='html'>Steps involved in configuration of SSO between SAP Portal and WebSEAL:&lt;br /&gt;&lt;br /&gt;1. Install AMWeb ADK and AMWeb RTE on WebSEAL&lt;br /&gt;2. Download platform specific sapseculib and sapssoext libraries from SAP &lt;br /&gt;3. Download verify.pse from the SAP Portal environment and copy to the WebSEAL box&lt;br /&gt;4. Update WebSEAL configuration file with necessary properties:&lt;br /&gt;&lt;br /&gt;Please refer to this link for more information&lt;br /&gt;&lt;br /&gt;http://www.ibm.com/developerworks/tivoli/library/t-authsaptam/index.html&lt;br /&gt;&lt;br /&gt;Considerations:&lt;br /&gt;&lt;br /&gt;1. SAP has stopped supporting 32-bit libraries, so configuring SSO on WebSEAL 32-bit is at your own risk. The solution may work but you will not get support from SAP :)&lt;br /&gt;&lt;br /&gt;2. Code that IBM has provided has a method implementation missing: getSSOLibrary. You will need to implement this method on your own.&lt;br /&gt;&lt;br /&gt;Happy SSOing :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-1891023513716950863?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/1891023513716950863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=1891023513716950863' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1891023513716950863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1891023513716950863'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2010/08/webseal-sso-configuration-with-sap.html' title='WebSEAL SSO Configuration with SAP Portal'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-944182932881045357</id><published>2010-08-24T03:05:00.000+05:30</published><updated>2010-08-24T03:05:39.741+05:30</updated><title type='text'>TAM on Suse Linux</title><content type='html'>Tivoli Access Manager works on Suse Linux 32-bit operating system. On 64-bit operating system, all components except WebSEAL are supported. Though you can install WebSEAL on 64-bit, all the libraries that it uses internally are 32-bit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-944182932881045357?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/944182932881045357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=944182932881045357' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/944182932881045357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/944182932881045357'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2010/08/tam-on-suse-linux.html' title='TAM on Suse Linux'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-5372108063763481576</id><published>2009-07-03T04:19:00.007+05:30</published><updated>2009-07-14T07:28:42.538+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='reconfigure policy server'/><category scheme='http://www.blogger.com/atom/ns#' term='directory server crash'/><category scheme='http://www.blogger.com/atom/ns#' term='reconfigure webseal'/><category scheme='http://www.blogger.com/atom/ns#' term='tivoli access manager'/><title type='text'>Policy Server reconfiguration in the event of Directory Server crash</title><content type='html'>In the event of ITDS crash, Policy Server can not be unconfigured using pdconfig. Use /opt/PolicyDirector/sbin/PDMgr_unconfig to unconfigure Policy Server. Authorization server can be reconfigured once Policy server is up. Please refer to my post below on reconfiguring WebSEAL in such event.&lt;br /&gt;&lt;br /&gt;Components such as Web Portal Manager and others need not be unconfigured. Check the username of the user account used during initial configuration. Create the user with same user credentials on Policy Server. Web Portal Manager should work as expected after this.&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://rcm.amazon.com/e/cm?t=tivaccmanblo-20&amp;o=1&amp;p=26&amp;l=ur1&amp;category=computers_accesories&amp;banner=1SKRXV416ZYVKCEGXQR2&amp;f=ifr" width="468" height="60" scrolling="no" border="0" marginwidth="0" style="border:none;" frameborder="0"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-5372108063763481576?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/5372108063763481576/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=5372108063763481576' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5372108063763481576'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5372108063763481576'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2009/07/policy-server-reconfiguration-in-event.html' title='Policy Server reconfiguration in the event of Directory Server crash'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-1298484739473591589</id><published>2009-07-02T03:52:00.004+05:30</published><updated>2009-07-02T04:08:33.038+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='webseal'/><category scheme='http://www.blogger.com/atom/ns#' term='master policy server'/><category scheme='http://www.blogger.com/atom/ns#' term='cars'/><category scheme='http://www.blogger.com/atom/ns#' term='tivoli common reporting'/><category scheme='http://www.blogger.com/atom/ns#' term='eventxml'/><category scheme='http://www.blogger.com/atom/ns#' term='tivoli access manager'/><category scheme='http://www.blogger.com/atom/ns#' term='common auditng and reporting service'/><title type='text'>All About Common Auditing and Reporting Service</title><content type='html'>Common Auditing and Reporting Service(CARS) is capable of collecting events from Master Policy Server and WebSEAL and can process the data so that reports can be viewed through Tivoli Common reporting package or any other third party reporting products.&lt;br /&gt;&lt;br /&gt;CARS can be deployed in clustered and non clustered environments. Installation and configuration of  CARS is not straight forward and there are few steps that need to be verified/corrected post CARS configuration to ensure it functions as expected.&lt;br /&gt;&lt;br /&gt;CARS is better known to work on AIX because its an IBM component and they probably unit test their code on AIX :)&lt;br /&gt;&lt;br /&gt;Here are few things that we need to verify post CARS Configuration:&lt;br /&gt;&lt;br /&gt;1. Ensure stored procedures run properly. From DB2 command line, execute the stored procedures to make sure they are running properly&lt;br /&gt;2. Run Test Connection on eventxml data source. In a clustered environment, its important that the data source connection is successful on both nodes.&lt;br /&gt;3. Make sure DB2 client is installed on both the nodes in a clustered environment&lt;br /&gt;4. If MPS/WebSEAL tries to talk to CARS over SSL:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Ensure that  CARS application roles are mapped to the user id that MPS and WebSEAL use to communicate to CARS.&lt;/li&gt;&lt;li&gt; After running amauditcfg on MPS and WebSEAL, verify if clientPassword is set in the config file( clientUsername, clientPassword, key database path, stash file path are mandatory if MPS/WebSEAL tries to talk to CARS over SSL).&lt;/li&gt;&lt;li&gt; Ensure application security is enabled on the deployment manager profile where CARS cluster resides.&lt;/li&gt;&lt;/ul&gt;Happy auditing :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-1298484739473591589?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/1298484739473591589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=1298484739473591589' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1298484739473591589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1298484739473591589'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2009/07/all-about-common-auditing-and-reporting.html' title='All About Common Auditing and Reporting Service'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-1032083487613792517</id><published>2009-03-16T17:52:00.004+05:30</published><updated>2009-03-16T18:00:02.336+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Laxmanareddy'/><category scheme='http://www.blogger.com/atom/ns#' term='Objectgrid'/><category scheme='http://www.blogger.com/atom/ns#' term='IBM'/><category scheme='http://www.blogger.com/atom/ns#' term='WebSphere'/><category scheme='http://www.blogger.com/atom/ns#' term='Cluster'/><category scheme='http://www.blogger.com/atom/ns#' term='Tivoli'/><category scheme='http://www.blogger.com/atom/ns#' term='SMS'/><category scheme='http://www.blogger.com/atom/ns#' term='Session Management Server'/><title type='text'>Session Management Server on WebSphere cluster</title><content type='html'>When installing and configuring Session Management Server(SMS) installation on WebSphere cluster, make sure you consider the following things:&lt;br /&gt;1. Make sure to upgrade the objectgrid package which comes with WebSphere to the supported version. Please refer to Tivoli Access Manager release notes for the objectgrid version and fixpack details&lt;br /&gt;2. On the WebSphere servers, If there are WebSphere profiles other than cluster member nodes, make sure you stop all of them. Only the WebSphere Dmgr profile and its associated cluster member nodes should be running.&lt;br /&gt;3. Even after installation and configuration, if you start the profiles other than WebSphere Dmgr and its member nodes first, then SMS console and its associated components will thrown the following exception and will fail to work:&lt;br /&gt;"com.tivoli.am.sms.DSessException: The Session Management Server has encountered an error and was unable to complete the operation"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-1032083487613792517?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/1032083487613792517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=1032083487613792517' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1032083487613792517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1032083487613792517'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2009/03/session-management-server-on-websphere.html' title='Session Management Server on WebSphere cluster'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-4688729234511407382</id><published>2008-07-22T13:40:00.005+05:30</published><updated>2009-07-14T07:22:38.643+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Policy Server failover'/><category scheme='http://www.blogger.com/atom/ns#' term='MPS failover'/><title type='text'>Configure Policy Server failover in non-AIX operating systems</title><content type='html'>Policy Server failover is achieved using HACMP on AIX environment. How do you configure failover in operating systems other than AIX such as Windows.&lt;br /&gt;&lt;br /&gt;One of the ways that I could see is:&lt;br /&gt;&lt;br /&gt;1. Take nortan ghost of MPS machine and on a new machine with the same OS configuration, extract the ghost.&lt;br /&gt;&lt;br /&gt;2. Keep the second machine disconnected from network. This machine will have same hostname as the primary MPS machine.&lt;br /&gt;&lt;br /&gt;3. On a periodic basis, take MPS backup from primary using pdbackup command and restore the backup on second machine(call it backup machine).&lt;br /&gt;&lt;br /&gt;4. In the event of primary MPS failure, disconnect primary from network and connect backup MPS machine to network.&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://rcm.amazon.com/e/cm?t=tivaccmanblo-20&amp;o=1&amp;p=13&amp;l=ur1&amp;category=wireless&amp;banner=0SESQPYNEXXSWMYDWG02&amp;f=ifr" width="468" height="60" scrolling="no" border="0" marginwidth="0" style="border:none;" frameborder="0"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-4688729234511407382?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/4688729234511407382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=4688729234511407382' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/4688729234511407382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/4688729234511407382'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2008/07/best-way-to-setup-policy-server.html' title='Configure Policy Server failover in non-AIX operating systems'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-1302615004133559375</id><published>2007-05-01T15:26:00.000+05:30</published><updated>2007-05-01T15:33:19.805+05:30</updated><title type='text'>Why we chose TAM over SAM ?</title><content type='html'>There are lot of competitive advantages of TAM over SAM and vice versa. I dont want to discuss all that at the moment :)&lt;br /&gt;&lt;br /&gt;Sun Access Manager (SAM) installable is not available on AIX platform. You know the reason. Dont you ?  :) Okay, here it is:&lt;br /&gt;&lt;br /&gt;IBM has a proprietary JRE for AIX platform. Sun Access Manager works only with Sun's JRE not any other.&lt;br /&gt;&lt;br /&gt;And if your production environment is AIX, you dont have an option but to choose TAM over SAM.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-1302615004133559375?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/1302615004133559375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=1302615004133559375' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1302615004133559375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/1302615004133559375'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/05/why-we-chose-tam-over-sam.html' title='Why we chose TAM over SAM ?'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-2633135398958406599</id><published>2007-04-18T16:25:00.001+05:30</published><updated>2009-07-14T07:29:05.023+05:30</updated><title type='text'>What is Authorization Server ?</title><content type='html'>Authorization Server is a client side replica of Policy Server. It needs to be installed with Access Manager Java Runtime environment. It caches policy server data and synchronizes it on a regular basis. Even though Policy Server goes down, Authorization server still serves your requests.&lt;br /&gt;&lt;br /&gt;However there is a limitation on the data that authorization server can provide. Authorization server API provides ways of accessing basic attributes of user, group and ACL. PDPrincipal object is one such example API. For using Authorization API, developers have to first create&lt;br /&gt;PDAuthorizationContext and supply that as input to any authorization API. If you want to create user or group, you need to go through Policy Server API.&lt;br /&gt;&lt;br /&gt;With TAM 6.0, Authorization and Policy Server API are clubbed into one and are called Access Manager Application Development Kit(AMADK). com.tivoli.pd.jazn API are specific to Authorization server in AMADK.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://rcm.amazon.com/e/cm?t=tivaccmanblo-20&amp;o=1&amp;p=20&amp;l=ur1&amp;category=wireless&amp;banner=1RWF4VASSX63F46H0702&amp;f=ifr" width="120" height="90" scrolling="no" border="0" marginwidth="0" style="border:none;" frameborder="0"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-2633135398958406599?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/2633135398958406599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=2633135398958406599' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2633135398958406599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2633135398958406599'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/04/what-is-authorization-server.html' title='What is Authorization Server ?'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-7981609207254685558</id><published>2007-04-18T16:09:00.000+05:30</published><updated>2007-04-24T18:54:00.658+05:30</updated><title type='text'>Tivoli Policy Server data backup/restore</title><content type='html'>&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;b&gt;To backup/restore Tivoli configuration&lt;/b&gt;&lt;/strong&gt; &lt;/p&gt;&lt;p&gt; This is to backup/restore TAM configuration data which is not stored in LDAP&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;pdbackup     –action backup&lt;/p&gt;&lt;p&gt;                      –list /opt/PolicyDirector/etc/pdinfo.lst  &lt;/p&gt;&lt;p&gt;                     –path /data/tivoli/backup                     &lt;/p&gt;&lt;p&gt; –file pdbackup&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;Once the above command is executed, we can find an archive file by name pdbackup.tar under the folder /data/tivoli/backup.&lt;/p&gt;&lt;p&gt;To restore use the same command with -action restore option.&lt;/p&gt;&lt;strong&gt;&lt;b&gt;To backup/restore Tivoli Policy Server configuration&lt;/strong&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This is to take backup of tivoli policy server configuration. We can either user idsdb2ldif  or idsdbback.&lt;br /&gt;&lt;br /&gt;      &lt;u&gt;Approach I&lt;/u&gt;&lt;br /&gt;               a) Use command "idsdb2ldif" to take ldif backup - It takes  backup of ldap schema files &amp; backup ibmslapd.conf files.&lt;br /&gt;               b) Use command "idsldif2db" for data restore.&lt;br /&gt;                     &lt;br /&gt;      &lt;u&gt;Approach II&lt;/u&gt;&lt;br /&gt;             "idsdbback"  for backup and "idsdbrestore" to restore. For this to work, the software  versions and setup on both machines should be same.&lt;br /&gt;&lt;br /&gt;      1. If data size is not much, use "idsdb2ldif" and "idsldif2db" approach.&lt;br /&gt;      2. It is suggested to use both approaches (idsdb2ldif  or idsdbback )&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-7981609207254685558?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/7981609207254685558/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=7981609207254685558' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/7981609207254685558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/7981609207254685558'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/04/tivoli-policy-server-data-backuprestore.html' title='Tivoli Policy Server data backup/restore'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-6879226686642274880</id><published>2007-04-18T13:32:00.002+05:30</published><updated>2009-07-14T07:30:32.875+05:30</updated><title type='text'>My two cents on Tivoli Directory Server Clustering</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Directory server clustering&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It is advised that directory server and DB2 should reside on the same machine to eliminate network latency. Directory server is optimized to work with DB2 so it’s advised that Directory server be configured with DB2 not any other databases like Oracle.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;strong&gt;&lt;u&gt;Master-Slave configuration&lt;/u&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For reliability, both master and slave should ideally reside on different servers using their own database instances. This configuration is recommended for high availability in addition to reliability.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Without Load Balancer&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In a master-slave environment without a load balancer, all requests are routed to the master directory server. Policy server can be made aware of the Slave LDAP Server by putting the configuration (Slave hostname and port) in the ldap.conf file available in &lt;policy&gt;/etc. Once replication is setup, there is a default periodic interval for scheduled replication. There is an option to override and do a manual force replication. Slave can be upgraded as Master in event of failure. This is a manual process and no automated scripts are available as a part of the product.&lt;br /&gt;&lt;br /&gt;TAM can differentiate between read and write updates to LDAP. One can separately configure a set of replicas for read type of operations and another set for read/write operations. Also, priority can be set for the LDAP servers in the ldap.conf file.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;With Load balancer (Websphere Edge Server)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In a master-slave environment without a load balancer, all write operations are channeled to master directory server. Reads are load balanced between master and slave. A scheduled replication process takes care of replicating the master data into the slave database. In event of failure of the master directory server, the load balancer channels all reads to the slave, writes are not allowed on the slave and would fail eventually. In case of master being down, slave has to be manually configured as master (takes about 10-15 minutes of downtime) to allow writes. Failover for read is automated in this case. To avoid write operations getting lost, we need to implement some kind of queuing mechanism to preserve the write operations. There is a lag between the write to the master and the replication from master to slave. As a result it is quite possible that a write immediately followed by a read might not see the updated data.&lt;br /&gt;&lt;br /&gt;Replication can be scheduled through TDS Web Admin tool / command line utility. Policy Server can be made aware of the Slave through the ldap.conf file. Slave can be upgraded as Master if so needed.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;strong&gt;Questions&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;How to configure policy server for two directory server instances in case Directory server is clustered?&lt;br /&gt;&lt;em&gt;Answer:&lt;/em&gt; The ldap master &amp; slave replica hostnames and ports need to be mentioned in the ldap.conf file. The replicas can be configured as read-only or read-write.&lt;br /&gt;&lt;br /&gt;In a Master-Slave directory server cluster scenario, if master goes down and if manually bring up slave as Master, will Policy Server pick fall back on this automatically?&lt;br /&gt;&lt;em&gt;Answer:&lt;/em&gt; In this scenario we can configure the both the ldap replicas in the Policy Server ldap.conf file as read-write with a priority. The Master has to have a much higher priority than the slave so that read-write requests will almost always go to the LDAP master. In event of a failure, the policy server will then talk to the slave. The catch would be to ensure that the slave promotes to master before Policy server talks to slave. Thus, recommended setup is a Master-Master setup if timing is very critical.&lt;br /&gt;&lt;br /&gt;What is the utility which will replicate data between master and slave?&lt;br /&gt;&lt;em&gt;Answer:&lt;/em&gt; There is no separate utility to replicate master and slave. This replication is available through Tivoli Directory Server Web Administration tool.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;strong&gt;&lt;u&gt;Master-Master configuration&lt;/u&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Both Masters should ideally reside on different servers using their own databases.&lt;br /&gt;For High Availability, it is recommended that both the masters reside on separate physical machines. This configuration thus needs separate database instances for both the masters.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Without Load Balancer&lt;br /&gt;&lt;/strong&gt;- Not Applicable -&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;With Load balancer (Websphere Edge Server)&lt;/strong&gt;&lt;br /&gt;All reads/writes are load balanced between the Master servers. A scheduled sync up process replicates data to and from the masters (increasing network usage). Policy server is configured with two master servers. It is highly likely that user might not see the data just inserted/updated.&lt;br /&gt;Since, both replicas are masters, the writes can be handled by both the replicas. But it is a good practice to ensure that writes still go to one of the masters and only in the event of a failure, it fails over to the other master. This is to ensure lesser network bandwidth &amp;amp; IO. Load balancer will be configured to have higher priority to one of the masters. The other master just ‘listens’ to replication till it becomes a master.&lt;br /&gt;&lt;br /&gt;Hence, there needs to be two-way replication so as to keep both the masters in-sync. Policy server can be made aware of the two masters by adding appropriate parameters in the ldap.conf file.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Policy server clustering&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Policy server can be clustered only using OS clustering (HACMP option in IBM AIX servers). The Policy server clustering feature is only supported on AIX (via HACMP).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://rcm.amazon.com/e/cm?t=tivaccmanblo-20&amp;o=1&amp;p=48&amp;l=ur1&amp;category=books&amp;banner=1TMV8K3VH35ZYYB9ARG2&amp;f=ifr" width="728" height="90" scrolling="no" border="0" marginwidth="0" style="border:none;" frameborder="0"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-6879226686642274880?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/6879226686642274880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=6879226686642274880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/6879226686642274880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/6879226686642274880'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/04/little-bit-of-tivoli-clustering.html' title='My two cents on Tivoli Directory Server Clustering'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-2460330230635864707</id><published>2007-04-06T14:39:00.000+05:30</published><updated>2007-04-06T14:43:38.565+05:30</updated><title type='text'>Solution to AJAX problem with WebSEAL</title><content type='html'>To make AJAX calls work properly, WebSEAL junctions needs to be created with scripting support.&lt;br /&gt;&lt;br /&gt;PDAdmin Command prompt - Create the WebSEAL junction with scripting support ie using the -j option&lt;br /&gt;&lt;br /&gt;Web Portal Manager  - check on "Enable scripting support" under scripting support tab in junction creation screen.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-2460330230635864707?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/2460330230635864707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=2460330230635864707' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2460330230635864707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2460330230635864707'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/04/solution-to-ajax-problem-with-webseal.html' title='Solution to AJAX problem with WebSEAL'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-3171871397817259973</id><published>2007-03-29T15:23:00.000+05:30</published><updated>2007-03-29T15:34:13.008+05:30</updated><title type='text'>Configure Tivoli Access Manager for multiple suffixes</title><content type='html'>During configuration of tivoli we create a suffix and tivoli access manager by default associates the following three ACLs to the suffix:&lt;br /&gt;&lt;br /&gt;1.cn=securitygroup,secauthority=default&lt;br /&gt;2.cn=ivacld-servers,cn=securitygroups,secauthority=default&lt;br /&gt;3.cn=remote-acl-users,cn=securitygroups,secauthority=default&lt;br /&gt;&lt;br /&gt;When we create another suffix and want tivoli access manger to recognize it, we need to add these ACLs manually through Directory Server Admin Console.&lt;br /&gt;&lt;br /&gt;Login in to Directory Server Admin Console - Goto Directory Management - Click on Manage Entries - Select the suffix that is created - Expand the 'Select Action' dropdown and select Edit ACL -Click on Non-Filtered ACLs - add the above ACLs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-3171871397817259973?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/3171871397817259973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=3171871397817259973' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/3171871397817259973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/3171871397817259973'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/configure-tivoli-access-manager-for.html' title='Configure Tivoli Access Manager for multiple suffixes'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-5879265141176554424</id><published>2007-03-07T12:10:00.000+05:30</published><updated>2007-03-07T12:35:09.571+05:30</updated><title type='text'>HPDMG0769E error</title><content type='html'>HPDMG0769E There were insufficient LDAP access privileges to allow Tivoli Access Manager to create and delete entries in the registry.&lt;br /&gt;&lt;br /&gt;Cause:  This error may happen if Policy Server configuration in LDAP is disturbed.&lt;br /&gt;&lt;br /&gt;Solution: Unconfigure and configure Policy Server using pdconfig.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-5879265141176554424?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/5879265141176554424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=5879265141176554424' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5879265141176554424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5879265141176554424'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/hpdmg0769e-error.html' title='HPDMG0769E error'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-2268378731213851859</id><published>2007-03-06T13:10:00.000+05:30</published><updated>2007-03-06T13:32:34.004+05:30</updated><title type='text'>What if Policy Server crashes ?</title><content type='html'>In development environment, Policy server instance is centrally located. JRTE,ADK and WebSEAL instances are installed and configured on development machines to point to Policy Server.&lt;br /&gt;&lt;br /&gt;When Policy Server crashes for whatsoever reasons, WebSEAL, AMADK instances can not be unconfigured and configured to a new Policy Server instance. It throws a message saying "policy server instance not available". we can not uninstall WebSEAL or AMADK with out unconfiguration. In such cases, following steps will help you to configure WebSEAL and AMADK instances.&lt;br /&gt;&lt;br /&gt;1. Take pd.sth and pd.kdb from /var/PolicyDirector/keytab folder (in Linux) or equivalent as per Operating System.&lt;br /&gt;2. Copy them to /Tivoli/PolicyDirector/keytab on development machines. If these files are already there, overwrite them with files which you copied from central Policy Server&lt;br /&gt;3. Open ldap.conf and pd.conf on development machine at /Tivoli/PolicyDirector/etc folder. Replace old policy server machine name with new policy server machine name.&lt;br /&gt;4. Go to Tivoli Access Manager - configuration window. Click on unconfigure WebSEAL. It will prompt for sec_master password after which it should unconfigure successfully.&lt;br /&gt;5. Repeat Step 4 for AMADK as well.&lt;br /&gt;6. Now you can configure AMADK and WebSEAL to latest Policy Server instance.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-2268378731213851859?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/2268378731213851859/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=2268378731213851859' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2268378731213851859'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2268378731213851859'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/what-is-policy-server-crashes.html' title='What if Policy Server crashes ?'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-5491657053607073105</id><published>2007-03-05T15:28:00.000+05:30</published><updated>2007-03-05T15:29:52.121+05:30</updated><title type='text'>Web Portal Manager 6 - Object space Copy/Paste</title><content type='html'>Copy/Paste of object space doesnt work in Tivoli Access Manager Web Portal Manager 6.0.  You need to download and install Fix pack 4 to make it work.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-5491657053607073105?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/5491657053607073105/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=5491657053607073105' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5491657053607073105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5491657053607073105'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/web-portal-manager-6-object-space.html' title='Web Portal Manager 6 - Object space Copy/Paste'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-5987315036254004838</id><published>2007-03-05T14:47:00.000+05:30</published><updated>2007-04-08T10:56:52.547+05:30</updated><title type='text'>Specify computer name during Tivoli installation, not IP</title><content type='html'>During the installation of IBM Tivoli Access Manager's components such as JRTE, AMADK and WebSEAL , please specify Tivoli Policy Server machine name not IP. Please make sure you put an entry against that name in your hosts file under WINDOWS\system32\drivers\etc.&lt;br /&gt;&lt;br /&gt;If you dont do this, policy server API calls will take considerably more time than usual.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-5987315036254004838?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/5987315036254004838/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=5987315036254004838' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5987315036254004838'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/5987315036254004838'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/specify-computer-name-during-tivoli.html' title='Specify computer name during Tivoli installation, not IP'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-3727472624510866476</id><published>2007-03-05T13:22:00.000+05:30</published><updated>2007-03-05T14:31:48.389+05:30</updated><title type='text'>Problem with DB2 used by Directory Server</title><content type='html'>If you install DB2 as the Database for IBM Directory server, make sure you change DB2 password before you restart it for the first time. Otherwise, Directory server fails to start and there is no way to figure out why its not starting.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-3727472624510866476?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/3727472624510866476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=3727472624510866476' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/3727472624510866476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/3727472624510866476'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/problem-with-db2-used-by-directory.html' title='Problem with DB2 used by Directory Server'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-2286178813314797052</id><published>2007-03-05T13:19:00.001+05:30</published><updated>2009-07-14T07:31:14.149+05:30</updated><title type='text'>WebSEAL session gets reset when used with AJAX</title><content type='html'>When you configure an application on Websphere application server 6.1 to a WebSEAL junction, requests to all resources inside the application go through WebSEAL via WebSEAL Junction. When user is authenticated and when XMLHTTPRequest object is used for asynchronous request/response in a JSP, HTTP session (JSESSIONID from WAS 6.1) is reset. As a result of that, custom session objects are lost. It looks like WebSEAL session id (PD-H-SESSION-ID) also is getting reset. Eventually, user is thrown back to login page for re-authentication.&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://rcm.amazon.com/e/cm?t=tivaccmanblo-20&amp;o=1&amp;p=48&amp;l=ur1&amp;category=books&amp;banner=0835KA0M3CYPVY7X8MR2&amp;f=ifr" width="728" height="90" scrolling="no" border="0" marginwidth="0" style="border:none;" frameborder="0"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-2286178813314797052?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/2286178813314797052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=2286178813314797052' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2286178813314797052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2286178813314797052'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/webseal-session-gets-reset-when-used.html' title='WebSEAL session gets reset when used with AJAX'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8518653425045114792.post-2993750789175920081</id><published>2007-03-05T10:59:00.000+05:30</published><updated>2007-03-05T13:19:04.723+05:30</updated><title type='text'>WebSEAL installation issue on Windows XP</title><content type='html'>WebSEAL installation fails on Windows XP.  It gives the following error:&lt;br /&gt;&lt;br /&gt;"The WebSEAL instance 'default' failed to configure".&lt;br /&gt;&lt;br /&gt;Not to panic. Just do that following.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. Open webseald-default.conf in the C:\Program Files\Tivoli\PDWeb\etc subdirectory.&lt;br /&gt;2. Locate the [webseal-config] stanza, and change the value of the "status" parameter from "partial" to "config"&lt;br /&gt;3. Click "Refresh" in the Access Manager WebSEAL Configuration window. The status for the default instance should now show as "Stopped".&lt;br /&gt;4. Open the Services application from the Start / Control Panel / Administrative Tools menu.&lt;br /&gt;Update the Log on properties of the "Access Manager WebSEAL-default" service, so that the service runs under the local Administrator account.&lt;br /&gt;&lt;br /&gt;Once you do this, You will be able to start the "Access Manager WebSEAL-default" service successfully. For more details:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www-128.ibm.com/developerworks/tivoli/library/t-tamxp/index.html"&gt;http://www-128.ibm.com/developerworks/tivoli/library/t-tamxp/index.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8518653425045114792-2993750789175920081?l=tivoliaccessmanager.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tivoliaccessmanager.blogspot.com/feeds/2993750789175920081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8518653425045114792&amp;postID=2993750789175920081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2993750789175920081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8518653425045114792/posts/default/2993750789175920081'/><link rel='alternate' type='text/html' href='http://tivoliaccessmanager.blogspot.com/2007/03/webseal-installation-issue-on-windows.html' title='WebSEAL installation issue on Windows XP'/><author><name>Laxman R</name><uri>http://www.blogger.com/profile/01484048219032493288</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_iSvTQUlw1ac/Szs6tG2R8eI/AAAAAAAAHPI/8urmgiZ29yg/S220/DSC01877.JPG'/></author><thr:total>0</thr:total></entry></feed>
