STEP 6. Configuring IBM AD Manual Resolution Service
Follow the configuration steps that are needed to have up and running IBM® AD Manual
Resolution Service:
1. Configure the parameters that are present in the conf.yaml file
Important: The configuration of the following parameters is not mandatory.
It is recommended to follow below steps only in case that you had previously configured these
parameters and you performed an upgrade to the latest version of IBM AD product.
On the machine where IBM AD Manual Resolutions Service is
installed, go to <IBM ADDI Installation Folder>/IBM Application Discovery Manual
Resolutions Service/conf/ and make sure that the conf.yaml is
present. If the conf.yaml file is not present in the /conf
folder, go to <IBM ADDI Installation Folder>/IBM Application Discovery Manual
Resolutions Service/sample-conf/ and copy the conf.yaml file in the
/conf folder. Open the conf.yaml file by using a text
editor and enter the desired values for the parameters that are detailed below.
Note: The parameters
are represented in YAML as mappings that consist of a parameter key and the
value that is associated to that key. The format of the mapping is the parameter key represented by
a string, which is terminated by a trailing colon that is followed by a space. The value for that
parameter key is represented by a string that follows the key's colon and space.
Example:
my_parameter: my_value
- Add the port of IBM AD Configuration
Server.
## Coordination and Configuration Server port ## default 2181 ccs.server.port: 2181
- Set the https parameter as follows:
- If the https parameter is set to false, a non-secured communication is
used.
#if communication should be secured with TLS https: false
- If the https parameter is set to true, a secured communication is used.Note: This step implies the use of certificates. If you want to set the communication to be secured, make sure that a certificate authority issues a signed certificate (.crt) and a private key for the certificate (.key).
#if communication should be secured with TLS https: true
Note: If the https parameter is set to true, an additional step needs to be performed. Locate startServer.bat file under <IBM ADDI Installation Folder>/IBM Application Discovery Manual Resolutions Service/ and replace the following line:
with:set tlsoptions=
Where:SET keystorepath=<"path_to_keystore"> SET keystorepass=<"password_of_keystore"> set tlsoptions=-Djavax.net.ssl.keyStore="%keystorepath%" -Djavax.net.ssl.keyStorePassword="%keystorepass%"
- Path to keystore is the path to the keystore that holds the certificate for IBM AD Manual Resolutions Service.
- Keystore password is the keystore password.
- If the https parameter is set to false, a non-secured communication is
used.
- Leave blank the line where the authSrv
parameter is present if Authentication Server (DEX)
is not needed.
Otherwise, set the authSrv parameter as follows:#authentication server URL authSrv:
- If the value of the https parameter is set to true, add the URL of Authentication Server (DEX) where authSrv
parameter is present. Authentication Sever (DEX) that belongs
to the IBM AD package is used. For more information, see STEP 4. (Optional) Configuring Authentication Server (DEX).
Example:
#authentication server URL authSrv: https://WIN-ASK7V692EKB.ferdinand2.com:7600/dex
- If the value of the https parameter is set to false and the Authorization and Authentication feature is
enabled, add the URL of Authentication Server (DEX). Example:
#authentication server URL authSrv: http://WIN-ASK7V692EKB.ferdinand2.com:7600/dex
- If the value of the https parameter is set to true, add the URL of Authentication Server (DEX) where authSrv
parameter is present. Authentication Sever (DEX) that belongs
to the IBM AD package is used. For more information, see STEP 4. (Optional) Configuring Authentication Server (DEX).
Example:
- The default value of the disableAuth parameter
is true. Leave the default value if Authentication Server (DEX) is not
needed.
Otherwise, set the disableAuth parameter to false. The false value keeps enabled the authentication.#disable authentication/authorization. allow all files to be sent disableAuth: true
#disable authentication/authorization. allow all files to be sent disableAuth: false
2. Make IBM AD Manual Resolution Service available in IBM AD Configuration Server
The IBM AD Manual Resolution Service manages the manually added resolutions and it is mandatory to be configured if you want to use Callgraph-based analyzes (graphs or reports).
After IBM AD Manual Resolutions Service is up and running,
go to IBM AD Configuration Server and make IBM AD Manual Resolutions Service available for the other IBM AD components as follows:
- Access Manual Resolutions Service settings page is displayed. , and go to . The
- If necessary, you can modify the path where the journal files are
created. The path where these files are generated is separated from the project's path and needs to
be accessible only for IBM AD Manual
Resolution Service. Once a
project is imported, a folder with the same name is generated in the related path and it hosts all
the files that are needed to manage dynamic call resolutions.
Example:
C:\AD\Resolutions
- Optionally, the main path where the manual resolutions are created for each project, can be overwritten. Click Add, select the target project, and add the path where the manual resolutions are created for the target project.
- Click Save.
3. Restart IBM AD Manual Resolution Service
- On Windows
- Once the configuration is done, go to the Dashboard tab, in IBM AD
Configuration Server, click the menu button of Manual Resolutions Service, and select Restart Service.Note: Wait until the service is restarted, this can take a few minutes to complete.
- If the service does not start, check the manualres.log file under <IBM ADDI Installation Folder>/IBM Application Discovery Manual Resolutions Service/log folder.
- Once the configuration is done, go to the Dashboard tab, in IBM AD
Configuration Server, click the menu button of Manual Resolutions Service, and select Restart Service.