Limit Search by Category:     Advanced search
Browse by category:

Using LDAP Authentication to Log into GWAVA QMS

Add comment
Views: 3287
Votes: 9
Comments: 0
Posted: 17 Aug, 2007
by: Maughan E.
Updated: 10 Jun, 2010
by: Quintero R.
Alternatively, if you do not use LDAP, but use single sign-on. This article will work as well. Skip the steps about setting up the LDAP server. Simply set your Post Offices to High Security and check the eDirectory box. Now GroupWise will allow users access to GroupWise based on their eDirectory password rather than their GroupWise password.

DISABLE LDAP ON THE GWIA

1.     If you run a GWIA on the same server as a POA, then LDAP must be disabled on the GWIA. This sounds incorrect, but it is necessary. The POA will handle the LDAP authentication. The GWIA will ask the POA if the username and password provided to it is correct. The POA will then contact the LDAP server, check the username and password, and respond back to the GWIA. 

2.     LDAP can be disabled from ConsoleOne, in the properties of the GWIA, under the LDAP tab. However, to be sure, open the SYS:\SYSTEM\GWIA.CFG and remove or comment out the /LDAP and /LdapThreads switches.

3.     Completely unload the GWIA, and reload.

DEFINE THE LDAP SERVER

To define an LDAP server, do the following:

1.     Open ConsoleOne and connect to the primary domain.

2.     Go to Tools, GroupWise System Operations, LDAP Servers


 



3.     If LDAP is already configured in your environment, simply click edit and verify the settings with the steps below. If LDAP is not currently configured, it is recommended that you remove these objects, and create a new one, or choose one and edit. It’s always nice to remove the existing ones if not previously configured, and create a new object with a generic name.  If you have multiple Post Offices, you can then have all of them point to this one server object.


 

4.     Place a description of desired, if you use SSL enable this and enter the appropriate key file.

5.     Enter the IP address where the LDAP server is located. Don’t use a loopback.

6.     Enter the port. It should be 389 by default if not using SSL, if/when you enable SSL the port should be 636.

7.     Select Bind as the authentication method to enforce your defined policies.

8.     Click Select Post Offices.


 

9.     Select the Post Offices in your system that will be configured to use LDAP. Likely this will be all of them.

 
ENABLE LDAP AT THE POST OFFICE
 

1.    Open the properties of the POST OFFICE, not the POA.


 

2.    Click the GROUPWISE tab and select SECURITY.


 


3.    Set the security to High and check the LDAP Authentication option.


 

NOTE: LDAP username and password is only necessary if you are using the compare method. Bind is recommended in this documentation. Consult the Novell documentation for further assistance.

4.     Click Select Servers, and move the post offices over to the Selected Servers section side.

 
MODIFY YOUR LDAP GROUP OBJECT
 

There is just one necessary change in order for LDAP to function with GroupWise. 

The LDAP server must allow clear-text passwords. By default, eDirectory is not setup to allow clear-text passwords. This sounds like a security breach, and should be protected with SSL. This documentation sets up LDAP in a non-SSL environment. You will need to go back and enable SSL to protect passwords between the POA and eDirectory.

1.    Edit the LDAP Group <server_name> object in you eDirectory tree.

2.    On the LDAP Group General properties, make sure that the Allow Clear Text Passwords option is checked.

3.    If you do not have the correct snap-ins, go to the OTHER tab, open the attribute labeled Allow Clear Text Passwords, and change the value from false to true.

4.    Apply the changes.

5.    At the server prompt type “unload nldap”, then “load nldap"

TEST FUNCTIONALITY

1.    Pick a user in your system.

2.    Go to the post office that they are in

Highlight their object and open the properties of it

On the GROUPWISE tab, change the password to something different than the eDirectory password is.

NOTE: If you are thinking “hmmm…isn’t this the same as the eDirectory password?” This is not correct. eDirectory and GroupWise are two distinct and different databases. They can be linked. However, both eDirectory and GroupWise contain passwords for a user.   Setting the Post Office to High Security tells the Post Office to use LDAP (or eDirectory) for authentication rather than what is contained within the GroupWise system.

5.     Now log out of your GroupWise Client and attempt to re-login. You can quickly tell if LDAP is working properly by which password allows you to login. If it is the newly reset GroupWise password this is NOT working right, and is NOT using the LDAP server for authentication. Check to make sure Clear text passwords is enabled and security is set to High.

Now try your eDirectory password. This should allow you to login. If it does, you have setup LDAP authentication correctly.

6.     Finally, go to your QMS webpage, enter your full email address as the username, and enter the LDAP password. You should be logged in. Using the GroupWise password will fail login.

NOTE: Alternatively, if you do not use LDAP, but use single sign-on. This article will work as well. Skip the steps about setting up the LDAP server. Simply set your Post Offices to High Security and check the eDirectory box. Now GroupWise will allow users access to GroupWise based on their eDirectory password rather than their GroupWise password.

Others in this Category
document Digest Report Stopped Getting Delivered
document After Migrating GWAVA to a New Server, The Digest Report Uses The Old Server's Address
document Cannot Access Quarantine or Release Messages From Digest Outside of the Network
document Unable to Login to QMS as Admin, Login Fails
document Cannot Access QMS After a Restart of GWAVA
document After Running a Rebuild Getting 'Page Cannot be Displayed'
document How To Mass Delete Messages From the Quarantine
document Recreating QMS databases
document Users getting duplicate digest reports.
document Able to log in to QMS as the Admin, but not as a user
document Users Unable to Log in to QMS
document Users Cannot Login to Quarantine Manager
document QMS Log showing Malformed database, or file is encrypted or is not in database
document Running a GWAVAQMS Sync on Linux
document Access denied or session expired messages when users try to login to QMS
document Removed Address Space on GWAVA4QMS, Running Thread DigestSchd
document Quarantine Database is Malformed, or Missing Messages. Rebuild QMS Without Mail Flow Interruption.
document Quarantine Database Failed A Nightly Integrity Check
document Messages in QMS with 'unrecognized subject'
document Testing QMS authentication through GWIA
document Troubleshooting the GWAVA Digest (e-mail Archive Report)
document Changing 'Quarantine Manager' link under home pages
document Messages Being Quarantined That Shoudn't Be
document Can't Login To QMS (Admin)
document QMS showing it is 'Closed for Maintenance'
document How to Quarantine All Mail (Global Quarantine)
document Getting a blank page when trying to access the QMS
document QMS Database Corruption (build 100 and earlier)
document QMS Error: The quarantine reported that the requested message does not exist in the system.
document Unable to login to QMS as admin or a user. User field being populated with numbers.
document Upgrade to QMS2 how-to/troubleshooting guide
document Force QMS2 upgrade
document no such table: t_Tokens after upgrading to QMS2
document How To Release a Digest manually in QMS2
document Login as a user to QMS times out
document Number in QMS login box
document Preventing Database Corruption
document How to Change the 'Manage my Quarantine' link
document Users unable to see messages in the QMS, after admin added them on the Users tab
document One User not Getting Digests as Well as not Seeing Any Messages in Their Own QMS
document Timestamp on Quarantined Messages Wrong
document QMS Creates the Digest Report, but it Never Reaches the Inbox
document Slow browser or browser script errors
document Seeing Only a Certain Amount of Messages in the QMS
document Some QMS mail not viewable as a user
document Migrate QMS Data to a GWAVA 4 SMTP Appliance (Linux)
document Admin. of multiple users QMS without giving admin rights/Managed Addresses
document Change the amount of messages viewed on each page.
document Digest releases but does not show up in clients mailbox
document Unable to Find Released Messages in QMS
document Change QMS Authentication Server
document Automatically delete messages from Quarantine.
document Remove messages from users QMS but not from the Administrators QMS
document How can I Prevent a User From Creating new Accounts in QMS?
document How to Exclude a GW Account From Getting a Digest Report
document QMS Unloading by Itself
document QMS is Reindexing After Restarting GWAVA on Linux
document How to rebuild QMS in a cluster environment
document How to Configure Exchange to Allow AUTH LOGIN to work
document Migrate QMS Data to a GWAVA 4 SMTP Appliance
document How can I Change the Amount of Days Before an Account for QMS Expires?
document Increase Mail in Digest Report
document How to add users to the QMS user list
document Quarantined Messages To A Distribution List
document Cannot Login to QMS because of Cookies
document QMS User Unable to Release a Specific Message from the QMS
document Not all events show up in Digest
document How To Log Into QMS as a User When Not Using GroupWise?
document How To Follow Messages/Digests Released From QMS
document How To Follow Messages That Are Sent To Quarantine
document Removed Address Space on GWAVAQMS, Running Thread InQueueManager
document How to Enable Digests to Certain Users
document How to setup a centralized QMS for multiple GWAVA servers
document QMS Login Via Built-In GWAVA Credentials
document How to View a List of Messages That Were Blocked for a Certain Event and Released.
document How to Keep a Copy of ALL Messages for a Specific User
document How to Follow a Message Through GWAVA Logs to Make Sure it Was Released
document Getting an "Application not Found" Error When Trying to Release From a Digest Report.
document If a User Releases a Message, That Has Multiple Recipients, From Their Quarantine, Will it be Released to All The Recipients?
document If a Message, that has Multiple Recipients, is Deleted by a User From Their Quarantine, is it Removed From All the Recipients' Quarantine?
document Getting a Script Error When Trying to Access the QMS.
document Users Unable to Login to the QMS after Moving GW and GWAVA to a New Server



RSS