The goals is to be able to login with "siteminder" super user in both AdminUI’s. When having 2 AdminUI’s registered with "siteminder", it’s known that siteminder can be only used to login on 1 AdminUI (1).
At the end of the procedure, the following result should be seen:
Both Policy Servers share the same Policy Store:
ps.example.com
HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion\LdapPolicyStore=123262470
AdminDN= cn=admin,dc=example,dc=com; REG_SZ
PSRootDN= dc=example,dc=com; REG_SZ
Server= 192.168.1.1:389; REG_SZ
ps.example.net
HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion\LdapPolicyStore=123262470
AdminDN= cn=admin,dc=example,dc=com; REG_SZ
PSRootDN= dc=example,dc=com; REG_SZ
Server= 192.168.1.1:389; REG_SZ2
Additional administrators have been created:
AdminUI on ps.example.com has been registered with "adminuione";
AdminUI on ps.example.net has been registered with "adminuitwo".
First login in both AdminUI have been done with "adminuione" on ps.example.com and "adminuitwo" on ps.example.net.
The result is that "siteminder" super user can log in in both AdminUI’s at the same time.
AdminUI 12.8SP7 on RedHat;
Policy Server 12.8SP7 on RedHat;
To implement this, remove all existing administrator data except the siteminder one, create 2 new legacy administrators, register both AdminUI’s with each of the new legacy administrators, and finally login in both AdminUI’s with "siteminder" super user.
IMPORTANT: Ensure to have a full backup of the environment before doing this. Backup includes Policy Store data, AdminUI and Policy Server installed files folders.
Enter Option (#,F,B,X,P, or Q): 168
Enter Option (ALNFSQ): S
3-CA.SM::TrustedHost@24-xpsagent-<...>
(I) Name : "ps.example.net__0"
(C) Desc : "Generated by XPSRegClient"
6-CA.SM::TrustedHost@24-xpsagent-<...>
(I) Name : "ps.example.com__0"
(C) Desc : "Generated by XPSRegClient"
8-CA.SM::TrustedHost@24-xpsagent-<...>
(I) Name : "ps.example.com__1"
(C) Desc : "Generated by XPSRegClient"
Enter Option (#, +, -, B, X, Y, M, Q): 3
Enter Option (MJLRPWDAX+Q): D
DELETE SUCCESS.
Enter Option (#, +, -, B, X, Y, M, Q): 6
Enter Option (MJLRPWDAX+Q): D
DELETE SUCCESS.
Enter Option (#, +, -, B, X, Y, M, Q): 8
Enter Option (MJLRPWDAX+Q): D
DELETE SUCCESS.
Enter Option (#, +, -, B, X, Y, M, Q): Q
Enter Option (ALNFSQ): Q
Enter Option (#,F,B,X,P, or Q): P
Enter Option (#,F,B,X,P, or Q): Q
Enter Option (A,S,C,W,B,P or Q): A
2 - SiteMinder Administrative UI Directory User
SM-ADMIN-DIRECTORY
Used by the UI for authenticating administrators
3 - SMWAMUI:ps.example.com__0 [Legacy]
SM://<...>/SMWAMUI:ps.example.com__0
4 - SMWAMUI:ps.example.com__1 [Legacy]
SM://<...>/SMWAMUI:ps.example.com__1
5 - SMWAMUI:ps.example.net__0 [Legacy]
SM://<...>/SMWAMUI:ps.example.net__0
Enter Option (#NA or Q): 2
Enter Option (# or BVUDRAQ): D
DELETE SUCCESS.
2 - SMWAMUI:ps.example.com__0 [Legacy]
SM://<...>/SMWAMUI:ps.example.com__0
3 - SMWAMUI:ps.example.com__1 [Legacy]
SM://<...>/SMWAMUI:ps.example.com__1
4 - SMWAMUI:ps.example.net__0 [Legacy]
SM://<...>/SMWAMUI:ps.example.net__0
Enter Option (#NA or Q): Q
Enter Option (A,S,C,W,B,P or Q): P
Enter Option (A,S,C,W,B,P or Q):
Q
10:34:09,813 INFO [ims.Main] * Startup Step 30 : Attempting to start ApplicationContextInitializer plug-ins
10:34:09,867 INFO [ims.Main] ---- CA IAM FW Startup Sequence Complete. ----
(INFO) : [sm-xobfed-02577] Successfully loaded smobjadapter.
Preparing registration information, please wait...
Processing complete. Thank you for waiting.
Manage System and Domain Objects
Manage Users
Manage Keys and Password Policies
Register Trusted Hosts
10:55:14,144 INFO [ims.Main] * Startup Step 30 : Attempting to start ApplicationContextInitializer plug-ins
10:55:14,216 INFO [ims.Main] ---- CA IAM FW Startup Sequence Complete. ----
(INFO) : [sm-xobfed-02577] Successfully loaded smobjadapter.
Preparing registration information, please wait...
Processing complete. Thank you for waiting.
[3388/5920][Fri Sep 08 2023 11:43:12.461][SmPolicyServer.cpp:2036][INFO][sm-Server-00870] Journaling thread started, will delete commands older than 60 minutes
2023-09-08 11:27:08,277 INFO [ims.Main] (ServerService Thread Pool -- 103) * Startup Step 30 : Attempting to start ApplicationContextInitializer plug-ins
2023-09-08 11:27:08,308 INFO [ims.Main] (ServerService Thread Pool -- 103) ---- CA IAM FW Startup Sequence Complete. ----
(INFO) : [sm-xobfed-02577] Successfully loaded smobjadapter.
Preparing registration information, please wait...
Processing complete. Thank you for waiting.