You can configure IBM Security Key Lifecycle Manager users in
any of the LDAP repositories, such as IBM Security Directory Server or Microsoft Active Directory to
access IBM Security Key Lifecycle Manager server and call server APIs and
CLIs.
Procedure
- Add LDAP repository to the federated repository.
For the
instructions, see Adding LDAP repository to the federated repository.
-
Create the database for LDAP configuration.
- Open the DB2 command window.
- Run the following command to create the
database.
db2 create database USERDB31 using codeset UTF-8 territory US
-
Update the data source from the WebSphere Integrated Solutions Console with
jndi name jdbc/wimXADS. For the instructions, see Updating a data source from WebSphere Integrated Solutions Console.
-
Restart WebSphere® Application Server.
-
Copy db2jcc.jar and db2jcc_license_cu.jar from the DB2SKLMV301 folder to the
WAS_HOME/lib folder.
DB2SKLMV301 path:
- Windows
- drive:\Program Files\IBM\DB2SKLMV301\java
- Linux
- path/IBM/DB2SKLMV301/java
Default definition of
WAS_HOME variable is typically:
- Windows
- C:\Program Files\IBM\WebSphere\AppServer
- Linux
- /opt/IBM/WebSphere/AppServer
-
Create database-based repository to hold all the IBM Security Key Lifecycle Manager application groups. For the instructions, see
Creating a database-based repository.
- From WebSphere Integrated Solutions Console, add
security
role to user/group mapping and map administrator role to
klmGUICLIAccessGroup .
For the instructions, see Adding security user roles from WebSphere Integrated Solutions Console.
-
Restart WebSphere Application Server.
-
Add LDAP users to IBM Security Key Lifecycle Manager application
groups. For the instructions, see Adding LDAP users to IBM Security Key Lifecycle Manager application groups
-
Take the IBM Security Key Lifecycle Manager application backup. The
data in the database-based repository is also backed up.
What to do next
After LDAP is configured, you must run the subsequent tasks. For more information, see
Post-LDAP configuration tasks to support LDAP integration