on 05-08-2014 12:37 AM
Hi All,
We are trying to configure SunOne LDAP to sap portal 7.31. we already configuring to MSADS LDAP and it works fine.
I created a custom datasource file and added both the LDAP details and configured according to a procedure available on help.sap.com ( configuration of Multiple LDAP data sources). After that we bounced our system. I can able to see the LDAP entry under user administration - ALL Data Sources. but when i try to search a user, it says "no element found".
SunOneLDAP Details:
hierarchy : flat with read only
server name: xyz
server port : secured port number
username: created a service user id in LDAP which has read only permissions
password : xxxxxx
user path : OU=USERS,O=xyz.com
group path: n/a ( ldap doesnt maintain groups)
imported the ldap certificates in our sap portal system.
all the above properties are entered in custom xml file with both ldap details:
Please let me know if i am missing any other configuration,
Thanks,
Vinay
Hello Vinay,
when configuring multiple Ldap directories, There are a number of prerequisities that you need to
consider.
For example, One prerequisite for Multi domains is that logon IDs must be unique across mutliple LDAP datasources. This will cause issue if duplicate IDs exist.
Please see the following Documentation and notes for more information on this.
Examples of Data Source Configuration Files - Identity Management - SAP Library
Example: Configuration of Multiple LDAP Data Sources - Identity Management - SAP Library
1618342 - Multiple LDAP Datasources - Active Directories where logon IDs
are not unique
762419 - Multi-Domain Logon Using Microsoft Active Directory
Please have a look at the above notes which documet this and also tells
you what to do in these situations.
Regards,
David
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi David,
Sorry for replying late.
I verified with both our MSADS and ODSEE LDAP folks and User Logonid's are uniqure across directory services. I looked into 1618342 note, it can only be applied if we dont have a unique user ids.
But anyhow i will try applying this sapnote and will see if this resolves the issue.
and i have also gone through the help.sap.com links which you have provided. I am doing exactly what its mentioned in there.
I tried using unsecured port too, but it doesn't work either.
one more thing, for group path, ODSEE doesnt maintain any groups, so in my xml file, i removed this line:<ume.ldap.access.base_path.group>xyz </ume.ldap.access.base_path.group>.
I just mentioned the userpath details.
I will update after i apply sap note.
Thanks,
Vinay
Hi David
The sapnote doesnt work either. Checked the Logs , ran the diagtool trace, nothing helps.
when i select the entry of ODSEE LDAP from the dropdown in useradmin and try to do some search like m*, it says " last search exceeded the size limit of the server, search result is incomplete".
there was one sap note 1878353-UME search doesnt return any LDAP user. There was a bug, and asked us to apply the patches based on our portal version. This is not relevant to our portal version 7.31 sp11 , we are on latest sp level.
I read the help.sap.com, two to three times, doing exactly what it was mentioned for multiple ldap configuration.
Even opened the oss message with SAP, because ODSEE is certified by SAP according to the note.
but they are saying its not a support issue, its a consulting issue.
Thanks
Vinay
Hi Vinay,
First of all, Please confirm that the Sun One Ldap server iscertified and supported for use with SAP
You can refer to the following note
Note 983808 - Certified LDAP servers.
If the LDAP server you are trying to use is not certified, it has not been tested by SAP and there may be issues.
Regards,
David
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
93 | |
10 | |
10 | |
9 | |
9 | |
7 | |
6 | |
5 | |
5 | |
4 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.