Content Platform Engine, Version 5.2.1              

Creating directory service user (AD LDS)

A directory service account that Content Platform Engine uses to connect to the directory server.

About this task

Procedure

  1. Create the following directory server account:
    Directory service (bind) user account (Active Directory Lightweight Directory Service) (AD LDS, formerly known as ADAM)
    Unique identifier
    cpe_service_user
    Description
    Provide the fully qualified distinguished name of cpe_service_user as the directory service bind user name while running Configuration Manager and also when you run the Administration Console for Content Platform Engine Directory Configuration Wizard.
    cpe_service_user performs the following roles:
    • Acts as the bind user specified by the application server to search through realms to authenticate a user when the user logs in to a Content Platform Engine client.
    • Acts as the user specified in the GCD that searches users and groups to authorize access to a specific FileNet® P8 object after a user has been authenticated.

    Provide the fully qualified distinguished name of cpe_service_user as the LDAPBindDN while running Configuration Manager and also when you run the Administration Console for Content Platform Engine Directory Configuration Wizard. Available for viewing and modifying in the Administration Console for Content Platform Engine Directory configuration tab.

    The Directory Service User cannot be accessed using referrals.

    Minimum required permissions
    An AD LDS user account that Content Platform Engine uses to connect to a single Microsoft AD LDS partition. To configure this, perform the following steps:
    1. Start ADAM ADSI Edit under Start > All Programs > ADAM.
    2. Connect to the partition. Expand partition in left-hand pane and click the CN=Roles node.) Be sure you have selected the CN=Roles container in the partition not under the CN=Configuration.)
    3. In the right-hand pane right-click the CN=Readers group and select Properties.
    4. In the Attributes list double-click the “member” attribute.
    5. Click Add ADAM Account.
    6. Enter the full DN of the user to be designated as the service user while running the Content Platform Engine installation program, and click OK.
    7. Click OK and click OK again.
  2. Icon representing the worksheet Record this value in your customized Installation and Upgrade Worksheet. To find this property, search the worksheet for instances of cpe_service_user.


Last updated: March 2016
p8ppi208.htm

© Copyright IBM Corporation 2013, 2016.