Copy ESS Users from One Environment to Another

 7 Replies
 0 Subscribed to this topic
 27 Subscribed to this forum
Sort:
Author
Messages
Chris12
Veteran Member Send Private Message
Posts: 150
Veteran Member

 

Hi All .... I am currently researching how to copy ESS Users from one Lawson environment to another!

I saw a lot of threads about this but was not sure of the best way.

Essentially, we are on LSF 9.0.1.11 (AIX and TDS ).

We use an on-line privileged identity in LAUA

So therefore all of your ESS users are mapped to the ONLINE account.  

The issue would stem from copying the users in RM security from one environment to another ...

I asked Lawson but they told me that was not support.

Thanks in advance ..

 

Carl.Seay
Veteran Member Send Private Message
Posts: 109
Veteran Member
I would recommend the process outlined in the LSF Upgrade Guide: Export LDAP (ldifgen), Export SSOP and PROD_EMPLOYEE Service and Identities (ssoconfig), Import LDAP, Modify file then import Services. Using the LDAP utilities will copy the user RM record, but you'll need to copy any Identities separately.

Importing is a pretty dangerous process, so make sure to get a full backup of your TDS LDAP and $LAWDIR\system files.
Kwane McNeal
Veteran Member Send Private Message
Posts: 479
Veteran Member
Chris,
It's pretty straight forward. It isn't supported for this purpose, but it is documented by Infor in th Landmark install guide.

There is an option for ldifgen that will dump *all* the RMData branch from LDIFGEN to XML. That command is ldifgen ldapdatatoxml -f ....

From there you'd need to manually strip the non EMSC related entries. Also important to strip system entries, or you could break your target environment badly.

After that, the rest is standard Lawson: ssoconfig for the indentities, etc.

Kwane
Kwane McNeal
Veteran Member Send Private Message
Posts: 479
Veteran Member
Grrr, virtual keyboards. It's 'ldapdatatoxml' not 'ldapdatatoxml'. I corrected the original post also
Chris12
Veteran Member Send Private Message
Posts: 150
Veteran Member
Thanks for the updates ... So this sounds like it is do-able ... But tricky ???
I will check out the LANDMARK installation guide
TJ Mann
Veteran Member Send Private Message
Posts: 70
Veteran Member
less tricky and dangerous way, i used:

idsldapsearch to get ESS or MSS users from prod to build my loadusers file, then loadusers -f.
Chris12
Veteran Member Send Private Message
Posts: 150
Veteran Member
I like loading the users back with the loadusers command ...
I will play around with a method to build the file.

Thanks so much .... Please keep em coming
John Henley
Send Private Message
Posts: 3351
You can also use ProcessFlow's ResourceQuery node to retrieve the users and their identities.
Combine that with ProcessFlow Integrator File node to write out the file for loadusers.
Note that if you have a lot of users (e.g. tens of thousands) this can be prohibitively slow.
Thanks for using the LawsonGuru.com forums!
John