|
|
Up |
|
|
  |
Author: david.mooredavid.moore
Date: Jan 18, 2007 03:38
Hi, Yes that example would fit. The background to this is that at the
moment we use iChain to protect lots of internal applications and we have
always used eamil address rather that UID for login credentials. I am
evaluating NAM as a replacement and a requirement would be to continue to
use email address.
|
| Show full article (0.79Kb) |
|
| |
no comments
|
|
  |
Author: kaikai
Date: Jan 18, 2007 03:18
Using AM to secure a site with smartcards. Everything works fine exept
when users use a long time (+5min) to enter information inn a web form on
the site. In the LAG logs i se the POST being re-directed for re-
authentication and the POST data is lost. The user ends up in the same
form but with no data inn it.
Where can i set the timeout for re-authentication ? This is only a
problem with POST method.
|
| |
|
| |
no comments
|
|
  |
Author: ericeric
Date: Jan 17, 2007 17:30
I'm having a strange problem that I think may be a bug.
I've setup a typical LAG proxy: https://www.sitename.com >> reverse
proxy >> http://www.othername.com - this works just fine. I'm
SSLiszing the http connection without any problem.
BUT
whenever I enable SSL from the LAG to the back-end website, I get the
following error:
Your request cannot be processed for this multi-homed web site because
the specified host could not be located.
Status Description: 500 Internal Server Error
Other related tidbits:
*The URLs for the Embedded Service Provider (Metadata, Health-Check,
Logout) also produce the Error 500.
*I've imported the various certificates for the back-end web server
*in /var/log/ics_dyn.log - there's this error: "No matching
accelerator child"
*In the proxy console/configured addresses and services it shows:
|
| Show full article (1.78Kb) |
|
no comments
|
|
  |
Author: g.flahertyg.flaherty
Date: Jan 14, 2007 14:42
We have access manager up and running for testing as a reverse proxy with
all parts running on one server. It works well when we configure an
accelerator with a single backend web server but as soon as we add a second
backend web sever to load balance we cannot get the accelerator to work.
The browser reports a redirect error and in the LAG log it shows 'Redirect
(Redirecting to LAG Broker url)' for all requests to the accelerator with a
302 error. We cannot find any information on this 'LAG Broker url' in the
documentation or anywhere else.
Any help would be much appreciated.
Guy Flaherty
|
| |
|
no comments
|
|
  |
Author: David GersicDavid Gersic
Date: Jan 4, 2007 13:29
On Wed, 03 Jan 2007 17:32:34 GMT, "Jared Jennings"
SPAMmyrealbox.com> wrote:
>David Gersic,
>
>>Yes, it's possible. That's essentially what they've said they're going
>>to do. Now it's just a matter of getting it to happen, then finding out
>>what it is we need to do to be able to do it.
>
>Actually that used to work in iChain. In Access Manager they removed
>support for NetIdentity.
I know. And they've said, at least here at NIU, that SP1 (around
December 2006) would have some kind of replacement for this
functionality, likely based on some kind of Kerberos thing.
Now, I'm just waiting to see code I can try. The rest of AM looks pretty
slick.
---------------------------------------------------------------------------
David Gersic dgersic_@ _niu.edu
I'm tired of receiving rubbish in my mailbox, so the E-mail address is
munged to foil the junkmail bots. Humans will figure it out on their own.
|
| |
|
no comments
|
|
  |
Author: Don HorsfallDon Horsfall
Date: Jan 2, 2007 09:21
Finally, I've got a solution.
I managed to get the pwm (Password Management) solution off of the
forge. ( http://forge.novell.com/modules/xfmod/project/?pwm)
This is a really clean solution and integrates nicely with AM. It does
require Java JDK 5 and tomcat 4 or 5. It won't run on Netware because
JDK 5 isn't available for Netware.
I built a SLES 10 box with JDK 5 and tomcat5 to run it on -- an
adventure in its own right -- and it works perfectly.
My last little glitch is getting tomcat 5 to start as a daemon at
boot. Put the working script into init.d, pointed to it from rc3.d,
but it doesn't start.
Oh, well.
Thanks all,
Don
|
| |
|
no comments
|
|
  |
Author: m_jonism_jonis
Date: Dec 29, 2006 06:26
> m_jonis,
>
>>
>>So would that not still require setting up a SLES box? Or do you mean
>>setup the LAG and run the password servlets on it?
>
> That I don't know. I would have to try it before I could say.
>
> If you don't want to wait for me, repost the question as a new question.
> Maybe someone else will see it.
>
>
Oh, no biggie for me. I'm just curiuos now is all. I still have to
setup the SLES 10 box anyway for User Application, so it's not wasted
time.
:)
|
| |
|
no comments
|
|
  |
Author: Jared JenningsJared Jennings
Date: Dec 22, 2006 08:21
Don Horsfall,
>I'm looking for suggestions for a password change url that lets the
>currently logging in user change his/her password with minimum
>interaction and then exits when it's done.
--
Jared Jennings - Data Technique, Inc.
Novell Support Forums Sysop
My Blog and Wiki with Tips, Tricks, and Tutorials
http://jaredjennings.org
|
| |
|
3 Comments |
|
  |
Author: Ryan KRyan K
Date: Dec 20, 2006 08:46
The On-box Identity Server (Identity Server on the Access Gateway) - There's
not much documentation on this feature, other than the fact that it's "not
currently supported in production environments". What's the story with
this? Is it it something that's going to be supported in the long-run?
Does it work? What are the disadvantages?
We're a school district who wishes to use access-manager. The load on NAM
would not be very much. It seems easy enough to use/configure, and we would
get it for a good price through SLA. If at all possible, we would like to
keep the number of servers required to a minimum, making the on-box IDS
somewhat attractive. My next option would be virtualization.
|
| |
|
1 Comment |
|
  |
|
|
  |
Author: thipbodee phasukthipbodee phasuk
Date: Dec 19, 2006 20:18
Hi all,
Does Anybody know how to apply the solution for using NAM+token to
work with the terminal service? The criteria need to apply those 2 things:
1. Anyone who sits in front of the server , doesn't need to use token to
login to the server, just need only the user and password. Or he can use his
own machine to login as the terminal client and using only with the user and
password ,too if he sit inside the server room.
2. But anyone outside the server room, they need to use both password and
token for authentication to the terminal server.
Please guide me. God bless you.
Thip
|
| |
|
no comments
|
|
|
|
|
|
|