Tivoli® Access Manager secure domains can contain more than one authorization server. Having multiple authorization servers is useful for providing a failover capability as well as improving performance when the volume of access requests is large.
Property | Default | Relevant command | Description |
---|---|---|---|
Websphere Application Server node name | * |
|
Specify a single node or enter an asterisk (*) to run the configuration task on all of the application server instances including the deployment manager, node agents, and servers. |
Tivoli Access Manager Policy Server | Default port: 7135 |
|
Enter the name of the Tivoli Access Manager policy server and the connection port. Use the format, policy_server : port. The policy server communication port is set at the time of Tivoli Access Manager configuration. |
Tivoli Access Manager Authorization Server | Default port: 7136 |
|
Enter the name, port, and priority of each configured Tivoli Access Manager authorization server. Use the format auth_server : port : priority. The authorization server communication port is set at the time of Tivoli Access Manager configuration. You can specify more than one authorization server by separating the entries with commas. Having more than one authorization server configured is useful for failover and performance. The priority value is the order of authorization server use. For example: auth_server1:7136:1,auth_server2:7137:2. A priority of 1 is still required when you use a single authorization server. |
Websphere Application Server administrator's distinguished name |
|
Enter the full distinguished name of the security primary administrator ID for WebSphere® Application Server as created in Creating the security administrative user for Tivoli Access Manager. For example: cn=wasadmin,o=organization,c=country | |
Tivoli Access Manager user registry distinguished name suffix |
|
Enter the suffix that you have set up in the user registry to contain the user and groups for Tivoli Access Manager. For example: o=organization,c=country | |
Tivoli Access Manager administrator's user name | sec_master |
|
Enter the Tivoli Access Manager administration user ID that you created when you configured Tivoli Access Manager. This ID is usually sec_master. |
Tivoli Access Manager administrator's user password |
|
Enter the password that is associated with the Tivoli Access Manager administration user ID. | |
Tivoli Access Manager security domain | Default |
|
Enter the name of the Tivoli Access Manager security domain that is used to store users and groups. If a security domain is not already established at the time of Tivoli Access Manager configuration, click Return to accept the default. |
Embedded Tivoli Access Manager listening port set | 8900:8999 |
|
WebSphere Application Server needs to listen on a TCP/IP port for authorization database updates from the policy server. More than one process can run on a particular node and machine so a list of ports is required for the processes. Enter the ports that are used as listening ports by Tivoli Access Manager clients, separated by a comma. If you specify a range of ports, separate the lower and higher values by a colon. For example, 7999, 9990:9999. |
Defer | No |
|
Set this option to yes if you want to defer the configuration of the management server until the next restart. Set the option to no if you want the configuration of the management server to occur immediately. Managed servers are configured on their next restart. |
Force | No |
|
Set this value to yes if you want to ignore errors during the unconfiguration process and allow the entire process to complete. Set the value to no if you want errors to stop the unconfiguration process. This option is especially useful if the environment needs to be cleaned up and problems are occurring that do not allow the entire cleanup process to complete successfully. |