Connection from PS to AD LDS userStore for authentication
book
Article ID: 122168
calendar_today
Updated On:
Products
CA Single Sign On Secure Proxy Server (SiteMinder)CA Single Sign On SOA Security Manager (SiteMinder)CA Single Sign-On
Issue/Introduction
We'd like to know if the Policy Server can understand and map the return codes from LDAP AD-LDS into Siteminder smauthreason codes ?
Environment
Release: MSPSSO99000-12.8-Single Sign-On-for Business Users-MSP Component:
Resolution
Indeed, the Policy Server is capable of that out of the box.
But you have to pay attention to existing issue about this topic. Before the CR06, the Policy Server has issue to map correctly the returns codes from AD into the correct smauthreason allowing disable user to login among the others.
As such, we recommand you first to upgrade the Policy Server, Policy Store and AdminUI to the latest 12.52SP1CR09 version :
Defects Fixed in 12.52 SP1 CR09
00919679 DE335297 Policy Server incorrectly recognizes AD LDS user store as AD user store.
00882334 DE326287 Policy Server fails to log in users with AD LDS as the user directory.
More, the AD-LDS should return the same codes as the AD, as AD-LDS is based on the same technology as the AD :
Active Directory Lightweight Directory Services
Uses the same directory service technology as AD DS. There is a common framework for both the network operating system (NOS) services of AD DS and the application services of AD LDS, which increases reusability of design and code.