Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

LDAP authentication for local build forge users

Hello,

is there a way to use LDAP to verify the password for a local user id? The email property of the user should be used for the LDAP lookup.  

Thanx, Steffen

0 votes



3 answers

Permanent link
 Yes.
http://pic.dhe.ibm.com/infocenter/bldforge/v7r1m3/index.jsp?topic=%2Fcom.ibm.rational.buildforge.doc%2Ftopics%2Fadmin_ldap_about.html

Look at the section for LDAP domain properties.  It goes over how to connect BF to the LDAP server, then when a user logs in with their LDAP creds, a matching BF user is generated and the validation of that users credentials is given to the LDAP server.  You can also set up mappings between your BF access groups and the LDAP groups.

~Spencer

0 votes


Permanent link
Spencer,

thank you very much for pointing us the documentation. Base on this document we were able to configure the build forge access with IBM bluepages. Unfortunately we still have an issue.  We configured blupages as LDAP host and set the Search Base, Groups Search Base and so on. With this a user can logon using intranet user id / password.
With the initial logon a local build forge user id is created. This id can be later assigned to access groups and the user can work with build forge. There are two problems with this approach:
  • each owner on an intranet id can logon (we have circumvented this by setting a default access group guest, but still this creates dummy users)
  • We have a tool to automate the user management. This tool manages user id on several servers / applications. For build forge we can't use this because the workflow would be something like this:
    • update blue group
    • wait for user first time log in to build forge
    • update access groups with new user id.
      the work flow is not straight forward.
We are looking for a LDAP / Blupages config which allows to use the intranet ID/password but does not has the limitation listed before. May be you can send us a sample or describe how this is done in your group. Thanks in advance.

Kind regards, Steffen

0 votes

Comments

I don't think you can black or white list users from the LDAP domain.  If the credentials are good, the user will be created.  The guest access group is probably the best solution here.  As far as the blue group problem, you can map access groups to LDAP groups, so you can automate what access groups a user will be assigned to when they log in.  That would be the best solution for the other user management issue.  Then you could update a bluegroup, have the user login and then they would automatically be added to which ever access groups map to the bluegroups they belong to.  Also this would keep valid bluepages users who aren't in project bluegroups from seeing anything they shouldn't see.


~Spencer


Permanent link
Hi Spencer,

I tried to map LDAP groups to access groups. When setting "Map Access Groups:" to ON I can't no longer logon to the build forge console. Any idea what could be wrong?

Thanx, Steffen

0 votes

Comments

Mapping the access groups shouldn't affect logging on unless it precludes you from ANY valid access group.  Do you not have a default access group for all users?


~Spencer 

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details

Question asked: Jan 30 '14, 3:53 a.m.

Question was seen: 7,814 times

Last updated: Feb 12 '14, 8:43 a.m.

Confirmation Cancel Confirm