Lawson 10x/Ming.le + multiple domains?

 5 Replies
 0 Subscribed to this topic
 27 Subscribed to this forum
Sort:
Author
Messages
Jimmy Chiu
Veteran Member
Posts: 641
Veteran Member
    Multiple ldap search base, can it be done?

    I know we can do it with openldap in Lawson 9.x/LPS schema enabled multiple container search base etc.

    But my question is with Ming.le foundation/Lawson 10x, can it be done?

    John Henley
    Posts: 3353
      Which authentication option are you using -- Kerberos or LS as STS?
      if you're using LS as STS, then ldapbind doesn't change.
      Thanks for using the LawsonGuru.com forums!
      John
      Jimmy Chiu
      Veteran Member
      Posts: 641
      Veteran Member
        Can it be done using Kerberos?
        John Henley
        Posts: 3353
          Are you talking about multiple AD domains within a AD forest, multiple search containers within a single AD domain, or multiple AD servers within a single AD domain (i.e. for failover)?

          For the first option, I haven't tested it, but it should work, as long as the LSF/WebSphere and SharePoint/Workspace servers and their primary AD logon server are in the SAME AD domain.
          For users in AD domains in same forest (i.e. trusted domains), the trust relationship between them in AD is what allows them to authenticate, since both SharePoint and the delegation user specified in WebSphere can process the Kerberos ticket assuming the trust relationship is set up. (Authentication is handed via SharePoint/Workspace, and then the Kerberos ticket is forwarded to LSF/WebSphere, which uses a delegation user.)

          For the other options, since authentication is really done via SharePoint, regular SharePoint rules apply, so those should work as well.

          Again, I haven't tested any of these extensively, so can't say for sure.

          Hopefully that's what you asking...
          Thanks for using the LawsonGuru.com forums!
          John
          John Henley
          Posts: 3353
            P.S. why do you always ask such hard questions ?
            Thanks for using the LawsonGuru.com forums!
            John
            Jimmy Chiu
            Veteran Member
            Posts: 641
            Veteran Member
              LSF and Mingle server are on - abc.com
              "outside" trusted domain - 123.com
              another "outisde" trusted domain - xyz.com

              They are totally independent to each other besides being trusted.