121 lines
7.6 KiB
HTML
121 lines
7.6 KiB
HTML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE html
|
|
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
|
<html lang="en-us" xml:lang="en-us">
|
|
<head>
|
|
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
|
|
<meta name="security" content="public" />
|
|
<meta name="Robots" content="index,follow" />
|
|
<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
|
|
<meta name="DC.Type" content="task" />
|
|
<meta name="DC.Title" content="Troubleshoot domain controller connection problems" />
|
|
<meta name="DC.Relation" scheme="URI" content="rzalvtrblshoot.htm" />
|
|
<meta name="copyright" content="(C) Copyright IBM Corporation 2002, 2006" />
|
|
<meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 2002, 2006" />
|
|
<meta name="DC.Format" content="XHTML" />
|
|
<meta name="DC.Identifier" content="rzalvtrblcncttodmnctlr" />
|
|
<meta name="DC.Language" content="en-us" />
|
|
<!-- All rights reserved. Licensed Materials Property of IBM -->
|
|
<!-- US Government Users Restricted Rights -->
|
|
<!-- Use, duplication or disclosure restricted by -->
|
|
<!-- GSA ADP Schedule Contract with IBM Corp. -->
|
|
<link rel="stylesheet" type="text/css" href="./ibmdita.css" />
|
|
<link rel="stylesheet" type="text/css" href="./ic.css" />
|
|
<title>Troubleshoot domain controller connection problems</title>
|
|
</head>
|
|
<body id="rzalvtrblcncttodmnctlr"><a name="rzalvtrblcncttodmnctlr"><!-- --></a>
|
|
<!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script>
|
|
<h1 class="topictitle1">Troubleshoot domain controller connection problems</h1>
|
|
<div><div class="section"><p>A number of factors can contribute to connection problems when
|
|
trying to connect to the domain controller. Use the following table to determine
|
|
how to resolve potential domain controller connection problems. </p>
|
|
|
|
<div class="tablenoborder"><a name="rzalvtrblcncttodmnctlr__troubletable"><!-- --></a><table cellpadding="4" cellspacing="0" summary="" id="rzalvtrblcncttodmnctlr__troubletable" frame="border" border="1" rules="all"><caption>Table 1. Common EIM domain controller connection problems
|
|
and solutions</caption><thead align="left"><tr><th align="center" valign="top" width="52.55102040816326%" id="d0e21"><strong>Possible problem</strong></th>
|
|
<th align="center" valign="top" width="47.44897959183674%" id="d0e24"><strong>Possible solutions</strong></th>
|
|
</tr>
|
|
</thead>
|
|
<tbody><tr><td valign="top" width="52.55102040816326%" headers="d0e21 ">You can not connect to the domain controller when using iSeries™ Navigator
|
|
to manage EIM.</td>
|
|
<td valign="top" width="47.44897959183674%" headers="d0e24 ">Domain controller connection information may by incorrectly
|
|
specified for the domain that you want to manage. Complete these steps to
|
|
verify domain connection information: <ul><li>Expand <span class="uicontrol">Network-->Enterprise Identity Mapping-->Network->Domain
|
|
Management</span>. Right-click the domain that you want to manage and
|
|
select <span class="uicontrol">Properties</span>.</li>
|
|
<li>Verify that the name of the <span class="uicontrol">Domain controller</span> is
|
|
correct and that <span class="uicontrol">Parent DN</span>, if specified, is correct. </li>
|
|
<li>Verify that <span class="uicontrol">Connection</span> information for the domain
|
|
controller is correct. Ensure that the <span class="uicontrol">Port</span> number
|
|
is correct. If <span class="uicontrol">Use secure connection (SSL or TLS)</span> is
|
|
selected, the directory server must be configured to use SSL. Click <span class="uicontrol">Verify
|
|
Connection</span> to verify that the you can use the specified information
|
|
to establish a connection to the domain controller successfully.</li>
|
|
<li>Verify that the user information in the <strong>Connect to Domain Controller</strong> panel
|
|
is correct.</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
<tr><td valign="top" width="52.55102040816326%" headers="d0e21 ">The operating system or applications can not connect
|
|
to the domain control to access EIM data. For example, EIM mapping lookup
|
|
operations performed on behalf of the system are failing. This may be happening
|
|
because the EIM configuration is incorrect on the system or systems.</td>
|
|
<td valign="top" width="47.44897959183674%" headers="d0e24 "> Verify your EIM configuration. Expand <span class="uicontrol">Network-->Enterprise
|
|
Identity Mapping-->Configuration</span> on the system that you are trying
|
|
to authenticate with. Right-click the <span class="uicontrol">Configuration</span> folder
|
|
and select <span class="uicontrol">Properties</span> and verify the following:<ul><li><strong>Domain </strong> page:<ul><li>The domain controller name and port numbers are correct.</li>
|
|
<li>Click <span class="uicontrol">Verify Configuration</span> to verify that the domain
|
|
controller is active.</li>
|
|
<li>The local registry name is specified correctly</li>
|
|
<li>The Kerberos registry name is specified correctly.</li>
|
|
<li>Verify that <span class="uicontrol">Enable EIM operations for this system</span> is
|
|
selected.</li>
|
|
</ul>
|
|
</li>
|
|
<li><strong>System user </strong> page:<ul><li>The specified user has sufficient <a href="rzalveservereimauths.htm#rzalveservereimauths">EIM
|
|
access control</a> to perform a mapping lookup, and the password is valid
|
|
for the user. See the online help to learn more about the different types
|
|
of user credentials.<div class="note"><span class="notetitle">Note:</span> If you have changed the password for the specified
|
|
system user in the directory server, you must change the password here as
|
|
well. If these passwords do not match, then the system user can not perform
|
|
EIM functions for the operating system and mapping lookup operations fail. </div>
|
|
</li>
|
|
<li>Click <span class="uicontrol">Verify Connection</span> to confirm that the user
|
|
information specified is correct.</li>
|
|
</ul>
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
<tr><td valign="top" width="52.55102040816326%" headers="d0e21 ">Configuration information appears to be correct but
|
|
you can not connect to the domain controller.</td>
|
|
<td valign="top" width="47.44897959183674%" headers="d0e24 "><ul><li>Ensure that the directory server that acts as the EIM domain controller
|
|
is active. If the domain controller is an iSeries server, you can use iSeries Navigator
|
|
and follow these steps: <ol><li>Expand <span class="uicontrol">Network > Servers > TCP/IP</span>.</li>
|
|
<li>Verify that the Directory Server has a status of <strong>Started</strong>. If the
|
|
server is stopped, right-click <span class="uicontrol">Directory Server</span> and
|
|
select <span class="uicontrol">Start...</span></li>
|
|
</ol>
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
After you verify connection information and that the directory server
|
|
is active, try to connect to the domain controller by following these steps:</div>
|
|
<ol><li><span>Expand <span class="uicontrol">Network > Enterprise Identity Mapping > Domain
|
|
Management</span>. </span></li>
|
|
<li><span>Right-click the EIM domain to which you want to connect and select <span class="uicontrol">Connect...</span>.</span></li>
|
|
<li><span>Specify the user type and the required user information that should
|
|
be used to connect to the EIM domain controller. </span></li>
|
|
<li><span>Click <strong>OK</strong>.</span></li>
|
|
</ol>
|
|
</div>
|
|
<div>
|
|
<div class="familylinks">
|
|
<div class="parentlink"><strong>Parent topic:</strong> <a href="rzalvtrblshoot.htm" title="Use this information to learn about common problems and errors that you may encounter when you configure and use EIM as well as potential solutions for them">Troubleshoot Enterprise Identity Mapping</a></div>
|
|
</div>
|
|
</div>
|
|
</body>
|
|
</html> |