Authenticate Users through External Directory Services

You can externally authenticate IBM® Sterling Control Center Monitor users by using LDAP accessible directories.

You can validate users in IBM Sterling Control Center Monitor by using its internal store of user IDs and passwords, or by using Lightweight Directory Access Protocol (LDAP) accessible directories, such as OpenLDAP™, IBM Tivoli® Directory Server, and Microsoft Active Directory™. This external authentication is accomplished by using an IBM Sterling External Authentication Server. Users who are configured for external authentication do not have to maintain their passwords in IBM Sterling Control Center Monitor. Users that are not configured for external authentication are validated with IBM Sterling Control Center Monitor internal store of user IDs and passwords.

To authenticate users through external directory services in IBM Sterling Control Center Monitor, you need to complete the following tasks:
  1. Configure users for external authentication.
  2. Configure IBM Sterling Control Center Monitor for connections with Sterling External Authentication Server.
  3. Configure Sterling External Authentication Server for connections with IBM Sterling Control Center Monitor.
  4. Configure secure connections between Sterling External Authentication Server and IBM Sterling Control Center Monitor.
IBM Sterling Control Center Monitor is able to use LDAP accessible directories to validate the credentials of users that connect to the engine by using any of the following supported interfaces:
  • IBM Sterling Control Center Monitor console
  • IBM Sterling Control Center Monitor web console
  • IBM Sterling Control Center Monitor batch creation utility
  • Java™ based Node Configuration Application Programming Interface (CCNCAPI).
  • REST API Interactive Console
  • REST API Reference

In addition, when users use any of the web services for IBM Sterling Control Center Monitor, the engine also uses external authentication to validate their credentials if their IBM Sterling Control Center Monitor user ID is configured to do so.