Download as doc, pdf, or txt
Download as doc, pdf, or txt
You are on page 1of 2

Enabling LDAP on WebSphere Application

Server
You can set up the Lightweight Directory Access Protocol (LDAP) on WebSphere
Application Server.
Procedure
1. From the WebSphere Integrated Solutions Console, click Security > Global
security.
2. Apply the following security settings, and then click Apply and save the changes.
o

Enable administrative security: on

Enable application security: on

User account repository/Available realm definitions: standalone LDAP

registry
In the User account repository section, click Configure, and enter
information about the general properties:
Primary administrative user name: Your user ID

Server user identity: Automatically generated server identity

Host: Name of the LDAP server

Port: Port of the LDAP server. Default is 389.

Type of LDAP server: Custom

Search timeout: 120 seconds

Base distinguished name (DN): The base distinguished name of the


directory service

3. Click Test connection to make sure you can successfully connect to your LDAP
server.
4. In the Additional Properties section, click Advanced Lightweight Directory Access
Protocol (LDAP) user registry settings and provide the information in the
General Properties fields as follows:
Remember: Replace the objectclass values and use the values that your LDAP
administrator provided for configuring WebSphere Application Server.
o

User filter:
(&(uid=%v)(objectclass=inetOrgPerson))

Group filter:
(&(cn=%v)(|(objectclass=groupOfNames)(objectclass=posixGroup)))

User ID map:

*:uid
o

Group ID map:
*:cn

Group member ID map, where ibm is replaced with your ID:


ibm-allGroups:member;ibm-allGroups:uniqueMember

5. Click Apply and save the changes. Confirm each setting by


clicking Apply and Save on each screen.
6. Click OK to go back to the Global Security page.
7. Set Standalone LDAP registry as the current realm definition by clicking Set as
Current.
8. Stop and restart WebSphere Application Server.
9. After WebSphere Application Server restarts, validate the changes by logging on to
the Integrated Solutions Console.
Related information:
Configuring Jazz applications for LDAP
Configuring WAS with LDAP realm

You might also like