Fallback to legacy administrator when AD is unavailable
book
Article ID: 92811
calendar_today
Updated On:
Products
CA Single Sign On Secure Proxy Server (SiteMinder)CA Single Sign On SOA Security Manager (SiteMinder)CA Single Sign-On
Issue/Introduction
We currently have SiteMinder v12.7 policy servers that use AD to authenticate administrators when they log in to the Web Admin UI. How can we configure the policy server to fallback to local SiteMinder administrators when the AD is unavailable? Have tried to create "legacy administrators" (with various options including "System" and "CA Single Sign-On Database" but this does not seem to permit login via the admin UI.
Environment
Release: Component: SMPLC
Resolution
Unfortunately this is not possible, see:
"Note: Legacy Administrators can access the Administrative UI when the policy store is configured as the source of administrator identities (the default). However, after an external administrator store is configured, Legacy Administrator accounts cannot access the Administrative UI."