IBM i , WAS 7.0 ; Local System User -"You are using a directory service that is not writable. User roles cannot be modified"
6 answers
If you are using WAS as the application server, the user's repository permission is not controlled in JTS. From your description, you are using OS users and groups management in WAS. Then you need to add the user into the OS level group which you used to may to JazzUsers group in WAS application level security.
You can refer to the following links about the user management with WAS:
https://jazz.net/help-dev/clm/index.jsp?topic=%2F%2Fcom.ibm.jazz.install.doc%2Ftopics%2Fc_manage_users_fed_realm.html
https://jazz.net/library/article/604
Hi Saskiumar,
we are using RTC since version 2 on our IBM-i.
We have taken the following steps the enrol users to RTC.
We enabled security in WAS with the usergroup JAZZUSER mapped to i-series user JAZZUSER
On system-i each user we want to include to the RTC-User group has in the additional groupprofile the profile jazzuser.
This soulution works for us.
Comments
I am still not able to get through this..
Hi Saskiumar,
to 1 the value must be local system and realname ist the name of your i-series
to 2 you have to apply security roles for user and groups for each apllication.
to 3 there is no need to configure anything.
With this configuration you should be able to login to RTC with i-Series users if the i-Series have a groupprofile like JAZZUSER
I hope this help you to login to RTC with i-series User
Comments
We are able to login using IBM i profile (PGMR)... but whenever we log-in using a regular this profile (JAZZUSER group profile), https://dev_ibmi:9443/ccm/admin shows "ADMIN" name on top right corner. The "view my profile license " shows as JazzAdmins, DWAdmin and Jazzuser.. but this regular user profile znd it should have only "jazzuser" authority, and it shouldn't allow to create jazz local users and other Admin functions.
- Enable administrative security - Checked
- Enable application security -Checked
- Java 2 security - unchecked
- User account repository - Local operating system
- General Properties
- Primary administrative user name : MYPROFILE
- Automatically generated server identity selected
- LTPA
- Use realm-qualified user names -Checked
Enterprise Applications > ccm.war > Security role to user/group mapping
Select | Role | Special subjects | Mapped users | Mapped groups |
---|---|---|---|---|
JazzAdmins | None |
SMANI
JTSADMIN |
JAZZADMINS
QPGMR |
|
JazzDWAdmins | None |
SMANI
JTSADMIN |
JAZZDWADMS
QPGMR |
|
JazzUsers | None |
SMANI
JTSADMIN SMANTEMP |
JAZZUSERS
QPGMR |
|
JazzGuests | None |
SMANI
JTSADMIN |
JAZZGUESTS
|
|
JazzProjectAdmins | None |
SMANI
JTSADMIN |
JAZZPJADMS |