Unable to install LSF patch after LDAP SSL config; LDAP SSL

 3 Replies
 0 Subscribed to this topic
 27 Subscribed to this forum
Sort:
Author
Messages
Shasidhar Vemireddy
Basic Member
Posts: 14
Basic Member
    I recently switched our Lawson and LBI to use completly SS including all ldap calls going over on LDAPS protocol porrt 636, our LDAPBIND is also set to SSL. The application and LBI are working well since past few months since the upgrade. A week ago I got ready to apply my first LSF post patch after SSL configuration. As you are already aware when u install patch using Lawson java installer it validates if ldap is running, it is failing here. The error ii see is unable toc onnect to server port 636. Port connectivity is good , I pretty sure the problem is with SSL. Tivoli LDAP is not trusting the connection coming from the installer. The application and LBI works fine .. I just cannot get it to work for Installer. ANy insight is much appreciated. I have even checked the install.cfg and the ldap parameters all point to LDAPS, SSL etc.

    As a work around to install patch , I have port 389 still open which helps me with the install and nothing else, I would like to get the patch install working with port 636. Lawson says it should work and the ask me to contact LPS. Any help is appreciated.
    Jimmy Chiu
    Veteran Member
    Posts: 641
    Veteran Member
      Can you use a third party ldap browser and connect to Tivoli via SSL port?
      Shasidhar Vemireddy
      Basic Member
      Posts: 14
      Basic Member
        Yes, i tried with JXplorer I was able to connect to LDAP  thru port 636. However when i try to apply a LCT patch on the server .. like

        $JAVA_HOME/bin/java -jar LCT patch .. it fails at ldap validation says unable to connect port 636.
        Jimmy Chiu
        Veteran Member
        Posts: 641
        Veteran Member
          Can you check your ssoconfig to see if the SSOP service is set to: "Use HTTPS always". It may have been set to "Use HTTPS for login only"