LBI authentication against ADAM

 6 Replies
 0 Subscribed to this topic
 22 Subscribed to this forum
Sort:
Author
Messages
Anne-Marie
Basic Member
Posts: 7
Basic Member
    hi,

    We try to setup LBI authentication against ADAM.
    We use advanced ldap/msad settings.

    Our ADAM contains groups and members for example G_LBIAdmins.
    After making the changes in the configurationAssistant, we restart IBM websphere. 
    The next step is to do an Authentication test in the InstallValidator.
    But we never pass this test.
    Always the same error :
    (security:3004) Login failed. The userid or password entered is not valid, or the specified user does not have access to this application

    The userId is a member of the administrative role.

    Had anyone the same experience and a solution for this ?

    Thx.
    mark.cook
    Veteran Member
    Posts: 444
    Veteran Member
      What is set up in the configuration assitant? We have had this running for years and added DSSO configuration so users in Lawson don't have to re-sign into LBI.

      Ours is set up to Lawson Single Sign On, I believe your should be set to just LDAP but the options here is where we ran into some issues in the past.
      Anne-Marie
      Basic Member
      Posts: 7
      Basic Member
        We use LBI with M3.
        We have no DSSO, no single sign on.
        In the install validator I have chosen MS Active Directory.
        Also tried LDAP, with no success
        Lisa Hodges
        Advanced Member
        Posts: 29
        Advanced Member
          Are you trying to use the same password that you use for Lawson? If so, then if you install DSSO, it should work. We have dsso installed, but our Lawson portal uses our active directory for authentication, so LBI goes through Lawson security (on ADAM) which is bound to our AD for the password.
          Anne-Marie
          Basic Member
          Posts: 7
          Basic Member
            Some progress made.
            Interesting information found on mylawson.com at the GetSupport/HotTopics
            LBI authentication and configuration with M3 systems.
            this is the link to the presentation, but there is als a webex.
            http://www.lawson.com/www..._with_M3_systems.pdf

            At this moment Users and Roles are synchronised from our ldap ADAM.
            But, ...
            still not able to logon to LBI or run the InstallationValidator.
            (security:3004) Login failed. The userid or password entered is not valid, or the specified user does not have access to this application

            Greg Moeller
            Veteran Member
            Posts: 1498
            Veteran Member
              Check to make sure the user that you specified (when installing LBI originally) - sysconfig.xml 'Resource Manager User Name' is a member of whichever group you specified in sysconfig.xml for 'LBI User Group'
              Anne-Marie
              Basic Member
              Posts: 7
              Basic Member
                Finally solved !

                The problem was related to ADAM.
                The LBI-users needed more authority on the ADAM itself to authenticate.