IBM Support

IT21339: CAN'T CONNECT TO THE SPECTRUM CONTROL WEB GUI WITH LDAP USERS AFTER UPGRADING SPECTRUM CONTROL FROM 5.2.12 TO 5.2.14.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • After upgrading Spectrum Control from version 5.2.12 that had
    LDAP repository of type Sun/Oracle Directory Server configured
    in eWAS WebServer to SC 5.2.14, login with LDAP users is not
    possible anymore.
    Moreover, after reconfiguring LDAP using the template
    SunJavaSystemDirectory.xml, searching for LDAP groups does not
    work when trying to map roles in SC Web GUI.
    
    RECREATE STEPS:
    Install Spectrum Control version 5.2.12, configure LDAP
    repository of type Sun/Oracle Directory Server in eWAS WebServer
    and map a SC role (administrator/monitor) to an LDAP group that
    has some LDAP users as members.
    Login in SC Web GUI using an LDAP user that belongs to the LDAP
    group that has a SC role.
    Upgrade to SC 5.2.14.
    
    Temporary fix:
    After downloading the template SunJavaSystemDirectory.xml and
    configuring LDAP repository info,
    replace:
    <iplanetFilters
               
    userFilter="(&amp;(uid=%v)(objectclass=inetOrgPerson))"
               
    groupFilter="(&amp;(cn=%v)(objectclass=ldapsubentry))"
                userIdMap="inetOrgPerson:uid"
                groupIdMap="*:cn"
                groupMemberIdMap="nsRole:nsRole" />
    
    with:
    
            <iplanetFilters
    groupFilter="(&amp;(cn=%v)(objectclass=groupOfUniqueNames))"
    groupIdMap="*:cn"
    groupMemberIdMap="groupOfUniqueNames:uniqueMember"
    userFilter="(&amp;(uid=%v)(objectclass=inetOrgPerson))"
    userIdMap="inetOrgPerson:uid"/>
    
    Then upload the file to SC Web GUI in order to reconfigure LDAP
    and map roles to the LDAP group.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Control 5.2.x users                             *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * After upgrading Spectrum Control from version 5.2.12 (with   *
    * LDAP repository of type Sun/Oracle Directory Server          *
    * configured) to Spectrum Control 5.2.14, logging in with LDAP *
    * users is no longer possible.                                 *
    * In addition, after reconfiguring LDAP using the              *
    * SunJavaSystemDirectory.xml template, searching for LDAP user *
    * groups does not work when trying to map roles in Spectrum    *
    * Control Web GUI.                                             *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply fix maintenance when available                         *
    ****************************************************************
    

Problem conclusion

  • The fix for this APAR is targeted for both of the following:
    
    
    IBM Spectrum Control 5.2.15.1  |  fix pack  |
    5.2.15-TIV-TPC-FP0001  (Nov 2017)
    
    http://www.ibm.com/support/docview.wss?&uid=swg21320822
    
    The target dates for future fix packs do not represent a formal
    commitment by IBM. The dates are subject to change without
    notice.
    
    
    
    The fix for this APAR is targeted for the following release:
    
    IBM Spectrum Control 5.3.0  |  5.3.0-IBM-SC   (release target
    Aug 2018)
    
    http://www.ibm.com/support/docview.wss?&uid=swg21320822
    
    The target dates for future releases do not represent a formal
    commitment by IBM. The dates are subject to change without
    notice.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT21339

  • Reported component name

    TPC ADVANCED

  • Reported component ID

    5608TPCA0

  • Reported release

    52D

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-07-07

  • Closed date

    2017-10-03

  • Last modified date

    2018-06-07

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TPC ADVANCED

  • Fixed component ID

    5608TPCA0

Applicable component levels

[{"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SSNECY","label":"Tivoli Storage Productivity Center Advanced"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"52D"}]

Document Information

Modified date:
24 June 2022