View Full Version: Ldaps

LawsonTalk > LSF 9.0 (NEW!!) > Ldaps



Title: Ldaps
Description: Configure LSF9 using LDAPS


vemi007 - April 4, 2008 08:54 PM (GMT)
I have LSF 9.0.0.3 running on UNIX Solaris 10 machine and on the same server we have our LAwson LDAP running on Tivoli Directory server. The ssoconfig data store settings were initially configured during upgrade to connect to "ldap://server:389" but i would like to change that to "ldaps://server:636" so that all connections to TDS use SSL, this is for audit compliance, i have followed article KB 543230 but there is something outside the article that needs to be configured that i am not aware. As one successfully implemented ldaps ?

Milo - April 8, 2008 09:21 PM (GMT)
We use MS-ADAM running on a separate Windows box. Works fine.

Two problems to avoid:

In KB # 543230 they tell you to run SSOCONFIG. In SSOCONFIG, do not save if you hit the Backspace key. Saving SSOCONFIG info with an embedded backspace will destroy integrity and force you to reinstall LSF9.

Never run LDAPBIND. That's a Lawson-only utility. (I did, and the fact that I'm still alive proves that it's not always fatal to the dumb bunny who does it. It is fatal to the LDAP install.)

Good luck!! :disco:

schroncd - April 9, 2008 02:15 PM (GMT)
THANK YOU MILO!!!!!

It's good to finally see someone with real integrity on this board make a statement like that about LDAPBIND. Not that's it's a "Lawson Only" command, but that it requires an in depth understanding of the LDAP structure and the way Lawson uses it before you hit the <ENTER> key.

It is NOT a command you can run "just to see what it does" - and even those of us who are SURE of what we are doing never do it without at least 2 good backups.

It's definitely a "measure twice, cut once" command.




Hosted for free by InvisionFree