Roles and LDAP groups

Post questions here relative to DataStage Enterprise/PX Edition for such areas as Parallel job design, Parallel datasets, BuildOps, Wrappers, etc.

Moderators: chulett, rschirm, roy

Post Reply
pechonb
Participant
Posts: 2
Joined: Wed Feb 21, 2007 10:45 am

Roles and LDAP groups

Post by pechonb »

Hi all,

I've just installed IBM Information Server 8.1 and I wonder if I have to keep independant user registries or use shared registries with LDAP.
Do you have any suggestions for me ?

To see impact of using LDAP, I decided to install a test server.
I tried to Configure LDAP as indicated in Administration Guide and all seems to be OK. When I grant roles to user, I can connect to web console.
If role is granted to a group where my account is member, this account seems to not inherite roles from group and I receive this message from login window : "User [xxxxxx] does not have the Suite User role."

Do you have any idea ?

Our LDAP Directory is Microsoft Active Directory.

Thanks.
pechonb
Participant
Posts: 2
Joined: Wed Feb 21, 2007 10:45 am

Post by pechonb »

Hi,

My problem is solved.
The problem was due to Base Distinguished Name syntax. All Attributes need to be upper cased. (DC=xx,DC=yy instead of dc=xx,dc=yy)

I hope this post will help someone.

Bye.
chulett
Charter Member
Charter Member
Posts: 43085
Joined: Tue Nov 12, 2002 4:34 pm
Location: Denver, CO

Post by chulett »

Thanks for posting that, I'm sure it will. Seems you were taking point on this one. :wink:
-craig

"You can never have too many knives" -- Logan Nine Fingers
JPalatianos
Premium Member
Premium Member
Posts: 306
Joined: Wed Jun 21, 2006 11:41 am

Post by JPalatianos »

Hi pechonb,

I have the same problem and was wondering where you changed the Base distinguished name to all Caps? Was this for the group?

Thanks -- John
U
Participant
Posts: 230
Joined: Tue Apr 17, 2007 8:23 pm
Location: Singapore

Post by U »

I am in the midst of trying to implement the same thing, and would appreciate some advice about how to map LDAP groups (Microsoft Active Directory) onto DataStage roles.

There is no advice on this in the DataStage Administrator manual or on-line help, and there does not appear to be any information within the Web Console for Information Server. (Is it just me, or is the help from this particular tool really sparse?)
Post Reply