Chat now with support
Chat with Support

Identity Manager 9.0 LTS - LDAP Connector for IBM RACF Reference Guide

Pre-installation information

Read the information in this section before you install the RACF LDAP connector.

Detailed information about this topic

User and group identifier

The LDAP implementation for RACF uses the racfid attribute to store the user name in a user object and the group name in a group object. The object containing the attribute defines whether it is referring to a user or a group.

RACF system users

RACF creates three special or system users that can be listed with an LDAP call. They are iicerta, iimulti, and iisitec. These system users cannot be altered by the connector through an LDAP call, so they are filtered by the connector. For example, when returning a list of all users in the RACF database, these three users will not be listed.

How to initialize and configure the RACF LDAP connector

NOTE: The following sequence describes how you configure a synchronization project if the Synchronization Editor is in expert mode.

To set up initial synchronization project for RACF

  1. Start the Synchronization Editor and log in.

  2. From the start page, select Start a new synchronization project

    This starts the Synchronization Editor project wizard.

  3. On the Choose target system page, select RACF LDAP Connector.

  4. On the System access page, click Next.

  5. On the Create system connection page, select Create new system connection.

  6. On the system connection wizard start page, click Next.

  7. On the Network page:

    1. In the Server field, enter the DNS name or IP address of your mainframe server.

    2. In the Port field, enter the port number.

    3. Click Test to ensure the server is accessible.

    4. The Tivoli Directory Server for z/OS supports LDAP v3. Enter the number 3 in the Protocol version

    5. If SSL is to be used, select the Use SSL check box.

  8. On the Authentication page:

    • For basic authentication, do the following:

      1. Set the Authentication method to Basic.

      2. In the Credentials section, enter the full DN and password of the administrator account on your RACF system.

      3. Click Test to check that the credentials are valid.

    • For external (client certificate) authentication, do the following:

      1. Set the Authentication method to External.

      2. In the Client Certificate section, enter the 40 character SHA1 thumbprint of the locally stored client certificate to be used for authentication.

        This thumbprint can be obtained from the Microsoft Management Console snap-in for managing certificates.

        NOTE: The certificate must be installed in the Personal area of the Current User certificate store.

      3. Click Test to check that the credentials are valid.

    The schema is loaded from the RACF system.

  9. On the Search options page:

    1. In the Base DN for searches drop-down list, select the correct base DN for your system.

    2. Clear the Use paged search check box.

  10. On the System attributes page, in the Revision properties section, clear the createTimestamp and modifyTimestamp entries by double-clicking them.

  11. Click Finish.

    This takes you back to the Synchronization Editor project wizard.

  12. On the One Identity Manager connection page, enter the database connection data.

    This loads the RACF schema into One Identity Manager. Wait for this to complete.

  13. On the Select project template page, select Create blank project.

  14. On the General page, enter a display name for your synchronization project and set a scripting language if required.

  15. Click Finish.

  16. Select Activate project.

Related topics
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating