otmfaqForumsBlogsRegister
FAQMembers ListCalendarToday's PostsSearch


 Subscribe Blogs:RSS
 Subscribe Forums:RSS
 Follow New Posts:Twitter
OTMFAQ Home
OTMFAQ Blogs
OTMFAQ Forums
OTM Wiki

OTM SIG
OTM Wiki
MavenWire


Network Fitting OTM / G-Log into your network - including browsers, firewalls, reverse-proxies and SSO.

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old January 29th, 2008, 20:06
Junior Member
 
Join Date: Jan 2008
Posts: 2
Groans: 0
Groaned at 0 Times in 0 Posts
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
wlirio is on a distinguished road
OTM and LDAP (OID)

Hi,
We are trying to integrate OTM 5.5.3 with OID using the LDAP configuration.
On the documentation there is a section that talks about extending the LDAP directory to include the GLUSER Attribute.
Quote from Install Doc "
OTM requires that the user ID field be part of the Distinguished Name (at least externally to an LDAP
client). It also requires that each LDAP user object to be authenticated with OTM be populated with
the GLUSER attribute. The GLUSER attribute should not be part of the Distinguished Name."
End Quote

I am not sure what is the GLUSER.

Thanks,
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old January 30th, 2008, 18:46
chrisplough's Avatar
Site Moderator
 
Join Date: Jun 2006
Location: West Chester, PA
Posts: 1,167
Blog Entries: 8
Groans: 0
Groaned at 1 Time in 1 Post
Thanks: 143
Thanked 259 Times in 161 Posts
Rep Power: 10
chrisplough is a jewel in the roughchrisplough is a jewel in the roughchrisplough is a jewel in the rough
Send a message via AIM to chrisplough
Re: OTM and LDAP (OID)

Hello,

the GLUSER is the G-Log (OTM) UserID, in the form of DOMAIN.USERNAME -- for instance GUIEST.ADMIN or COMPANY.LOUISE.

Just a little advice as you start looking itno this, I'd highly recommend using SSO (single sign-on) instead of the LDAP integration. With LDAP, you need to keep two copies of the OTM user's password - one in OTM and one in your LDAP directory and they must always be in sync. Instead, with SSO, you just keep the password in your SSO's repository and OTM simply accepts the userID passed to it, without doing it's own authentication. OTM's security remains intact and it's much easier to use.

--Chris
__________________
Chris Plough
MavenWire

www.MavenWire.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old February 4th, 2008, 17:24
Junior Member
 
Join Date: Jan 2008
Posts: 2
Groans: 0
Groaned at 0 Times in 0 Posts
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
wlirio is on a distinguished road
Re: OTM and LDAP (OID)

Thank for clarifying the GLUser. Regarding SSO I read somewhere that OTM 5.5.3 does not support SSO which why I went the LDAP route.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old February 4th, 2008, 18:44
chrisplough's Avatar
Site Moderator
 
Join Date: Jun 2006
Location: West Chester, PA
Posts: 1,167
Blog Entries: 8
Groans: 0
Groaned at 1 Time in 1 Post
Thanks: 143
Thanked 259 Times in 161 Posts
Rep Power: 10
chrisplough is a jewel in the roughchrisplough is a jewel in the roughchrisplough is a jewel in the rough
Send a message via AIM to chrisplough
Re: OTM and LDAP (OID)

You're welcome. On the SSO side, I haven't seen any notes, but I can't imagine it not working in CU03, because some very high profile clients are using it.

--Chris
__________________
Chris Plough
MavenWire

www.MavenWire.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old February 12th, 2008, 17:26
Junior Member
 
Join Date: Dec 2007
Posts: 5
Groans: 0
Groaned at 0 Times in 0 Posts
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0
rsadani is on a distinguished road
Re: OTM and LDAP (OID)

We are also in similar stage of installing a access management tool for controlling access to service providers. We are planning to use Siteminder as a SSO tool for access management (with OTM 5.5.4)
Are there any specific advises around this?
Thanks
Ravindra
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old February 12th, 2008, 19:09
chrisplough's Avatar
Site Moderator
 
Join Date: Jun 2006
Location: West Chester, PA
Posts: 1,167
Blog Entries: 8
Groans: 0
Groaned at 1 Time in 1 Post
Thanks: 143
Thanked 259 Times in 161 Posts
Rep Power: 10
chrisplough is a jewel in the roughchrisplough is a jewel in the roughchrisplough is a jewel in the rough
Send a message via AIM to chrisplough
Re: OTM and LDAP (OID)

Ravindra,

Several OTM / G-Log clients have used Siteminder SSO with OTM without issue -- I wouldn't expect you to have any issues. Just keep in mind that you'll need to configure OTM to use both SSO and the Reverse Proxy (URL Prefix) configuration.

--Chris
__________________
Chris Plough
MavenWire

www.MavenWire.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to chrisplough For This Useful Post:
rsadani (February 12th, 2008)
  #7 (permalink)  
Old January 14th, 2010, 21:56
Junior Member
 
Join Date: Dec 2009
Posts: 8
Groans: 0
Groaned at 0 Times in 0 Posts
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
pawsspeedy is on a distinguished road
Re: OTM and LDAP (OID)

Hi Chris,

We are in the middle of our integration with OID and there is a question from our SSO team which i am seeking clarification for:

Oracle SSO(from Oracle 10g Application Server) Solution in our company is protected by a siteminder. OID(LDAP Server) doesn’t store passwords. So, LDAP Authentication against OID is not an option. However, we still offer SSO solution to various ERP and other middle tiers as a partner applications in Oracle SSO Space. In simple, module OSSO in Apache can be registered with 10gAS and used for SSO Authentication.
We don’t see this kind of Authentication mechanism in the Admin guide. We have looked for mod_osso.so file in Apache home but we could not find it. So, can we just download this module and register this middle tier as an Oracle SSO Partner application? Please suggest

Seeking for an answer to this. Thanks in advance
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old January 21st, 2010, 09:46
chrisplough's Avatar
Site Moderator
 
Join Date: Jun 2006
Location: West Chester, PA
Posts: 1,167
Blog Entries: 8
Groans: 0
Groaned at 1 Time in 1 Post
Thanks: 143
Thanked 259 Times in 161 Posts
Rep Power: 10
chrisplough is a jewel in the roughchrisplough is a jewel in the roughchrisplough is a jewel in the rough
Send a message via AIM to chrisplough
Re: OTM and LDAP (OID)

No - the SSO integration in OTM is achieved in a different manner.

When SSO is enabled, OTM accepts a User ID that can be passed via the HTTP Header or within the URL. When this is received, OTM automatically logs that user in, without presenting a login screen or doing other password authentication. OTM assumes that the SSO solution has already done the appropriate authentication.

I have seen OTM integrated with Siteminder in the past, so this configuration is definitely possible.

--Chris
__________________
Chris Plough
MavenWire

www.MavenWire.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old January 21st, 2010, 11:26
Junior Member
 
Join Date: Dec 2009
Posts: 8
Groans: 0
Groaned at 0 Times in 0 Posts
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
pawsspeedy is on a distinguished road
Re: OTM and LDAP (OID)

thanks chris for your help.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old February 8th, 2010, 00:50
Junior Member
 
Join Date: Dec 2009
Posts: 8
Groans: 0
Groaned at 0 Times in 0 Posts
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
pawsspeedy is on a distinguished road
Re: OTM and LDAP (OID)

Hi Chris,

For SSo integration with Siteminder we followed the following steps.

1) Installing od Siteminder webagent in the webserver (Apache) of OTM.
2) once this was done we set the protection policies in the Siteminder Policy server.

Now we are stuck as to how the users will be assigned roles. my confusion is if the UID and PWD are authenticated by SSO server then OTM needs to authorize the user. for authorisation we need to create users of the same UID inside OTM too, and when we create these users in OTM the system asks for the password to be entered too. should we enter the same password as is of the SSO ID or we can we give any password and OTM will bypass the same.

Thanks in advance.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

« Ldap | - »

Thread Tools
Display Modes

Posting Rules

Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 22:44.
Copyright © 2006-2009, Open Book Solutions LLC. All rights reserved.


Inactive Reminders By Icora Web Design

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40