<rss version="2.0">
<channel>
<title>novell.support.access-manager</title>
<link>http://www.nnseek.com/e/novell.support.access-manager/</link>
<description>Posts for novell.support.access-manager</description>
<lastBuildDate>Thu, 18 Jan 2007 03:38:44 PST</lastBuildDate>
  <image>
    <title>http://www.nnseek.com/</title>
    <link>http://www.nnseek.com/</link>
    <url>http://www.nnseek.com/img/64.png</url>
    <width>64</width>
    <height>64</height>
    <description>NNSeek</description>
  </image>
<item>
	<title><![CDATA[Re: Authentication Credentials]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/authentication_credentials_13880271t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/authentication_credentials_13880271t.html</link>
	<description><![CDATA[Hi, Yes that example would fit. The background to this is that at the <br>moment we use iChain to protect lots of internal applications and we have <br>always used eamil address rather that UID for login credentials.  I am <br>evaluating NAM as a replacement and a requirement would be to continue to <br>use email address.<br><br>> david.moore@<a href="http://peterblack.co.uk" rel="nofollow" class="url" target="_blank">peterblack.co.uk</a>,<br>> <br>> >to use the email address to identify the user rather than<br>> >username.  We are using edir as the id vault.<br>> <br>> Ahh I c.<br>> So for example, You are trying to authenticate to Exchange WebAccess. <br>You <br>> want to use user@<a href="http://domain.com" rel="nofollow" class="url" target="_blank">domain.com</a> not userID for the "username" field.<br>> <br>> Correct?<br>> <br>> -- <br>> Jared Jennings - Data Technique, Inc.<br>> Novell Support Forums Sysop<br>> My Blog and Wiki with Tips, Tricks, and Tutorials<br>> <a href="http://jaredjennings.org" rel="nofollow" class="url" target="_blank">http://jaredjennings.org</a><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/authentication_credentials_13880271t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/authentication_credentials_13880271m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 18 Jan 2007 03:38:44 PST</pubDate>
</item>
<item>
	<title><![CDATA[Problem with POST forms and timeout]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/problem_with_post_forms_and_timeout_13880527t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/problem_with_post_forms_and_timeout_13880527t.html</link>
	<description><![CDATA[Using AM to secure a site with smartcards. Everything works fine exept <br>when users use a long time (+5min) to enter information inn a web form on <br>the site. In the LAG logs i se the POST being re-directed for re-<br>authentication and the POST data is lost. The user ends up in the same <br>form but with no data inn it.<br><br>Where can i set the timeout for re-authentication ? This is only a <br>problem with POST method.<br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/problem_with_post_forms_and_timeout_13880527t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/problem_with_post_forms_and_timeout_13880527m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 18 Jan 2007 03:18:03 PST</pubDate>
</item>
<item>
	<title><![CDATA[Error 500 when enabling SSL from AG to website]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/error_500_when_enabling_ssl_from_ag_to_website_13880015t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/error_500_when_enabling_ssl_from_ag_to_website_13880015t.html</link>
	<description><![CDATA[I'm having a strange problem that I think may be a bug.<br><br>I've setup a typical LAG proxy: <a href="https://www.sitename.com" rel="nofollow" class="url" target="_blank">https://www.sitename.com</a>  >> reverse<br>proxy >> <a href="http://www.othername.com" rel="nofollow" class="url" target="_blank">http://www.othername.com</a> - this works just fine. I'm<br>SSLiszing the http connection without any problem.<br><br>BUT<br><br>whenever I enable SSL from the LAG to the back-end website, I get the<br>following error:<br><br>Your request cannot be processed for this multi-homed web site because<br>the specified host could not be located.<br><br>Status Description: 500 Internal Server Error<br><br><br><br>Other related tidbits:<br><br>*The URLs for the Embedded Service Provider (Metadata, Health-Check,<br>Logout) also produce the Error 500.<br><br>*I've imported the various certificates for the back-end web server<br><br>*in /var/log/ics_dyn.log - there's this error:  "No matching<br>accelerator child"<br><br>*In the proxy console/configured addresses and services it shows:<br><br>Configured Addresses and Services<br>TCP/IP Addresses Bound On This Server:<br>    <a href="http://127.0.0.1" rel="nofollow" class="url" target="_blank">127.0.0.1</a>, 172.20.11.207<br>Proxy will NOT generate cache information headers<br>Configured Services:<br>  HTTP Server Path Based Accelerator (child) for <a href="http://icon.cimcitynews.com" rel="nofollow" class="url" target="_blank">icon.cimcitynews.com</a><br>    Path starts with: (null)<br>    at TCP/IP address 172.20.11.207:443<br>    Filling from: TCP/IP address <a href="http://127.0.0.1:8080" rel="nofollow" class="url" target="_blank">127.0.0.1:8080</a><br>Unknown global service type 401.<br>  HTTP Server Path Based Accelerator (master) for [1]:<br>        Path starts with: (null)<br>    at TCP/IP address 172.20.11.207:443<br>    ** Error **  SSL Register error (-5) Processing Certificate Error<br><br>  HTTP Server Host Based Accelerator (master) for [0]:<br>    at TCP/IP address 172.20.11.207:443<br>  Identity Agent at all configured TCP/IP listeners<br><br><br><br>Clearly the error "SSL Register error (-5) Processing Certificate<br>Error" is probably the cause, however I haven't been able to find that<br>error anywhere...<br><br>Ideas?<br><br>thanks!<br><br>Eric<br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/error_500_when_enabling_ssl_from_ag_to_website_13880015t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/error_500_when_enabling_ssl_from_ag_to_website_13880015m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Wed, 17 Jan 2007 17:30:22 PST</pubDate>
</item>
<item>
	<title><![CDATA[Multiple webservers causes redirect loop]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/multiple_webservers_causes_redirect_loop_13439439t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/multiple_webservers_causes_redirect_loop_13439439t.html</link>
	<description><![CDATA[We have access manager up and running for testing as a reverse proxy with<br>all parts running on one server. It works well when we configure an<br>accelerator with a single backend web server but as soon as we add a second<br>backend web sever to load balance we cannot get the accelerator to work.<br>The browser reports a redirect error and in the LAG log it shows 'Redirect<br>(Redirecting to LAG Broker url)' for all requests to the accelerator with a<br>302 error. We cannot find any information on this 'LAG Broker url' in the<br>documentation or anywhere else.<br><br>Any help would be much appreciated.<br><br>Guy Flaherty<br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/multiple_webservers_causes_redirect_loop_13439439t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/multiple_webservers_causes_redirect_loop_13439439m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Sun, 14 Jan 2007 14:42:25 PST</pubDate>
</item>
<item>
	<title><![CDATA[Re: SSO from workstation]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/sso_from_workstation_12181455t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/sso_from_workstation_12181455t.html</link>
	<description><![CDATA[On Wed, 03 Jan 2007 17:32:34 GMT, "Jared Jennings"<br><jaredljenningsNO@<a href="http://SPAMmyrealbox.com" rel="nofollow" class="url" target="_blank">SPAMmyrealbox.com</a>> wrote:<br><br>>David Gersic,<br>><br>>>Yes, it's possible. That's essentially what they've said they're going<br>>>to do. Now it's just a matter of getting it to happen, then finding out<br>>>what it is we need to do to be able to do it.<br>><br>>Actually that used to work in iChain. In Access Manager they removed <br>>support for NetIdentity.<br><br>I know. And they've said, at least here at NIU, that SP1 (around<br>December 2006) would have some kind of replacement for this<br>functionality, likely based on some kind of Kerberos thing.<br><br>Now, I'm just waiting to see code I can try. The rest of AM looks pretty<br>slick.<br><br><br>---------------------------------------------------------------------------<br> David Gersic                                            dgersic_@<a href="http://_niu.edu" rel="nofollow" class="url" target="_blank">_niu.edu</a><br><br> I'm tired of receiving rubbish in my mailbox, so the E-mail address is<br> munged to foil the junkmail bots. Humans will figure it out on their own.<br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/sso_from_workstation_12181455t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/sso_from_workstation_12181455m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Jan 2007 13:29:57 PST</pubDate>
</item>
<item>
	<title><![CDATA[Re: Change password URL?]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11965903t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11965903t.html</link>
	<description><![CDATA[Finally, I've got a solution.<br><br>I managed to get the pwm (Password Management) solution off of the<br>forge. (<a href="http://forge.novell.com/modules/xfmod/project/?pwm" rel="nofollow" class="url" target="_blank">http://forge.novell.com/modules/xfmod/project/?pwm</a>)<br><br>This is a really clean solution and integrates nicely with AM. It does<br>require Java JDK 5 and tomcat 4 or 5. It won't run on Netware because<br>JDK 5 isn't available for Netware.<br><br>I built a SLES 10 box with JDK 5 and tomcat5 to run it on -- an<br>adventure in its own right -- and it works perfectly.<br><br>My last little glitch is getting tomcat 5 to start as a daemon at<br>boot. Put the working script into init.d, pointed to it from rc3.d,<br>but it doesn't start.<br><br>Oh, well.<br><br>Thanks all,<br><br>Don<br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11965903t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11965903m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Tue, 02 Jan 2007 09:21:34 PST</pubDate>
</item>
<item>
	<title><![CDATA[Re: Change password URL?]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11553487t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11553487t.html</link>
	<description><![CDATA[In article <c70lh.21487$jS4.3627@<a href="http://prv-forum2.provo.novell.com" rel="nofollow" class="url" target="_blank">prv-forum2.provo.novell.com</a>>, <br>jaredljenningsNO@<a href="http://SPAMmyrealbox.com" rel="nofollow" class="url" target="_blank">SPAMmyrealbox.com</a> says...<br>> m_jonis,<br>> <br>> ><br>> >So would that not still require setting up a SLES box?  Or do you mean<br>> >setup the LAG and run the password servlets on it?<br>> <br>> That I don't know. I would have to try it before I could say.<br>> <br>> If you don't want to wait for me, repost the question as a new question. <br>> Maybe someone else will see it.<br>> <br>> <br><br>Oh, no biggie for me.  I'm just curiuos now is all.  I still have to <br>setup the SLES 10 box anyway for User Application, so it's not wasted <br>time.<br><br>:)<br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11553487t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11553487m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Fri, 29 Dec 2006 06:26:15 PST</pubDate>
</item>
<item>
	<title><![CDATA[Re: Change password URL?]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11204815t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11204815t.html</link>
	<description><![CDATA[Don Horsfall,<br><br>>I'm looking for suggestions for a password change url that lets the<br>>currently logging in user change his/her password with minimum<br>>interaction and then exits when it's done.<br><br>Have you seen Novells Password Self Service?<br><a href="http://www.novell.com/documentation/password_management/index.html?page=/documentation/password_management/pwm_administration/data/bqf5d1r.html" rel="nofollow" class="url" target="_blank">http://www.novell.com/documentation/password_management/index.html?page=/documen...</a><br><br>Although, maybe you are just wanting to know the url to the password self <br>service so that users can change their password.....<br><br>-- <br>Jared Jennings - Data Technique, Inc.<br>Novell Support Forums Sysop<br>My Blog and Wiki with Tips, Tricks, and Tutorials<br><a href="http://jaredjennings.org" rel="nofollow" class="url" target="_blank">http://jaredjennings.org</a><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11204815t.html"><b>3</b> Comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/change_password_url_11204815m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Fri, 22 Dec 2006 08:21:30 PST</pubDate>
</item>
<item>
	<title><![CDATA[On-Box Identity Server (the unsupported option)]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/on_box_identity_server_the_unsupported_option_10936783t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/on_box_identity_server_the_unsupported_option_10936783t.html</link>
	<description><![CDATA[The On-box Identity Server (Identity Server on the Access Gateway) - There's <br>not much documentation on this feature, other than the fact that it's "not <br>currently supported in production environments".  What's the story with <br>this?  Is it it something that's going to be supported in the long-run? <br>Does it work?  What are the disadvantages?<br><br>We're a school district who wishes to use access-manager.  The load on NAM <br>would not be very much.  It seems easy enough to use/configure, and we would <br>get it for a good price through SLA.  If at all possible, we would like to <br>keep the number of servers required to a minimum, making the on-box IDS <br>somewhat attractive.  My next option would be virtualization. <br><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/on_box_identity_server_the_unsupported_option_10936783t.html"><b>1</b> Comment</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/on_box_identity_server_the_unsupported_option_10936783m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Wed, 20 Dec 2006 08:46:55 PST</pubDate>
</item>
<item>
	<title><![CDATA[need guide for terminal service]]></title>
	<guid>http://www.nnseek.com/e/novell.support.access-manager/need_guide_for_terminal_service_10873551t.html</guid>
	<link>http://www.nnseek.com/e/novell.support.access-manager/need_guide_for_terminal_service_10873551t.html</link>
	<description><![CDATA[Hi all,<br><br>       Does Anybody know how to apply the solution for using NAM+token to <br>work with the terminal service?  The criteria need to apply those 2 things:<br>1. Anyone who sits in front of the server , doesn't need to use token to <br>login to the server, just need only the user and password. Or he can use his <br>own machine to login as the terminal client and using only with the user and <br>password ,too if he sit inside the server room.<br>2. But anyone outside the server room, they need to use both password and <br>token for authentication to the terminal server.<br><br>Please guide me. God bless you.<br><br>Thip <br><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/novell.support.access-manager/">novell.support.access-manager</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/need_guide_for_terminal_service_10873551t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/novell.support.access-manager/need_guide_for_terminal_service_10873551m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Tue, 19 Dec 2006 20:18:55 PST</pubDate>
</item>
</channel>
</rss>