Sun Java System Identity Synchronization for Windows 1 2004Q3 Installation and Configuration Guide |
Chapter 5
Installing Connectors and Directory Server PluginsThis chapter provides instructions for installing the Identity Synchronization for Windows Connectors and Directory Server Plugins. The information is organized as follows:
Identity Synchronization for Windows uses Connectors to synchronize user passwords between directory sources, and uses subcomponents to enhance the Connector’s change-detection and bidirectional synchronization support.
Before You BeginBefore starting the Connector/Directory Server Plugin installation process, you should be aware of the following:
- Close the Console before starting the installation process. If the Console is open when you are installing a Connector or the Plugin, the program perceives a conflict about which component is adding configuration data to the server and generates an error message.
- You must install the Directory Server Plugin on every Directory Server machine in your deployment that stores users to be synchronized; which includes masters, replicas, and hubs.
- Active Directory Connectors do not have subcomponents.
- Windows NT Connectors and subcomponents are installed simultaneously.
- You can install Directory Server or Active Directory Connectors on the same machine where you installed Core or you can install Connectors on another machine. (The Windows NT Connector must be installed on the Primary Domain Controller (PDC) of the domain being synchronized.)
- You must run the installation program each time you install a Connector or a Directory Server Plugin.
Running the Installation ProgramUse the following procedure to restart and run the installation program. You will repeat these steps each time you install a Connector or a Directory Server Plugin:
- Re-run the installation program on the machine where you want to install the Connector, as follows:
- On Solaris: Change to the installer directory and then type ./runInstaller.sh to execute the installation program.
- On Windows: Change to the installer directory and then type setup.exe to execute the installation program.
- When the Welcome screen is displayed, read the information provided and then click Next to proceed to the Software License Agreement panel.
- Read the license agreement, then select
- The Sun Java System Directory Server panel is displayed. Specify the configuration directory location as follows:
- Configuration Directory Host: Enter the fully qualified domain name (FQDN) of a Sun Java System Directory Server instance (affiliated with an Administration Server) where Identity Synchronization for Windows configuration information is stored. You must specify the same instance that you specified during the Core installation.
- Configuration Directory Port (Defaults to port 389): Specify a port for the configuration directory. You can leave the port set to the default or change to a different, available port.
To enable SSL (Secure Socket Layer) between Core and the configuration directory, enable the Secure Port option and specify an SSL port (default SSL port is 636). Enabling this option prevents sensitive information from being passed in the clear over the network.
- Configuration Root Suffix: Select the root suffix that you specified during the Core installation from the menu. The Identity Synchronization for Windows configuration will be stored in this root suffix.
- Click Next to open the Configuration Directory Credentials panel.
- Enter the configuration directory Administrator’s user ID and password.
- If you specify admin as the user ID, you will not be required to specify the User ID as a DN.
- If you use any other user ID, then you must specify the ID as a full DN.
For example, cn=Directory Manager.
Note
These credentials will be sent without encryption unless you enabled SSL in Step 4.
- Click Next to open the Configuration Password panel where you must enter the configuration password you specified when you installed Core.
Also, if Core has not been installed on this machine, you will be prompted to provide the location of the Java Home directory (see (more...) ).
- When you are finished, click Next.
Note
At this point, the installation process becomes specific to the Directory Server Plugin or the type of Connector you are installing.
- To install a Connector, proceed to Installing Connectors.
- To install a Directory Server Plugin, proceed to Installing Directory Server Plugins.
Installing ConnectorsThis section explains how to install the three types of Identity Synchronization for Windows Connectors, as follows
Installing the Directory Server Connector
After completing the steps described in Running the Installation Program, the Connector Configuration panel displays.
Figure 5-1 Selecting the Directory Server Connector
The Select components to install list contains only those Connector components that have not yet been installed. For example, after you install the Directory Server Connector (dc=example,dc=com in Figure 5-1), the program will remove the entry from the list pane.
The following table contains some example directory source entries:
Table 5-1 Directory Source Examples
Directory Source
Example Entry
Sun Java System Directory Server
dc=example,dc=com
Windows Active Directory
example.com
Windows NT SAM
EXAMPLE
To install the Directory Server Connector:
- Enable the button next to the Directory Server Connector component and then click Next.
The Directory Server Connector Credentials panel is displayed (Figure 5-2).
Figure 5-2 Entering Directory Server Connector Credentials
Note
The program automatically completes the User DN fields with your fully qualified Directory Manager distinguished name, but you can change the information if necessary.
Enter the following information:
- Primary Directory Server User DN: If necessary, change the default user DN by entering a fully qualified Directory Manager distinguished name.
- Primary Directory Server Password: Enter your Directory Manager password.
If you are using a secondary master, the Secondary Directory Server User Name and Password fields will be active. The program automatically completes the Directory Manager DN field with the same entries provided for the Primary Directory Server User DN and Password fields. You can change this information if necessary.
The program will verify that the Directory Server was prepared and ready to synchronize data. When you prepared Directory Server ((more...) ), the program creates an account that the Connector will use to connect to Directory Server (for example, uid=PSWConnector,suffix).
- Click Next to proceed to the Connector Port Configuration pane.
Figure 5-3 Specifying the Connector Local Host and Port
- Enter the Fully Qualified Local Host Name with the domain and an available port number where the Connector will listen. (Specifying a port already in use will result in an error message.)
The Directory Server Plugin needs access to the configuration information you saved in the Console. To get this information, the Plugin communicates with the Directory Server Connector, through a server socket on this port. Additionally, the Plugin logs messages over this channel so the messages will go to the central log.
- Click Next and the Ready to Install pane is displayed to provide information about the Connector’s installation location and how much disk space is required for the installation. When you are ready, click the Install Now button.
Figure 5-4 Ready to Install Pane
The Connector installation is accomplished in two steps:
- An Installing pane is displayed, with a progress bar, while the program installs the binaries.
- Next, the Component Configuration pane displays. A progress bar is displayed because this step takes several minutes to complete.
Note
If you did not close the Console before starting the installation, the following warning displays (Figure 5-5). Click Reset in the Console to reload the Connector’s configuration settings.
Figure 5-5 Configuration Warning Dialog Box
When both steps are complete, an Installation Summary pane is displayed.
- Click the Details button if you want to review the installation log.
- On Solaris: Installation logs are written to /var/sadm/install/logs/
- On Windows: Installation logs are written to the %TEMP% directory, which is usually a subdirectory of the Local Settings folder located under
C:\Documents and Settings\Administrator
- Click Next and the “To Do list” panel (Figure 5-6) displays to indicate which steps you have completed successfully and which steps remain.
Figure 5-6 To Do List
- When you are done with the panel, click Finished.
After installing the Directory Server Connector, you can install other Connectors and/or Directory Server Plugins that you configured when you configured resources (Chapter 4):
- Install additional Directory Server Connectors: Restart the installation program (using the instructions in Running the Installation Program) and then repeat Step 1 through Step 7.
- Install an Active Directory Connector: Go to Installing an Active Directory Connector.
- Install a Windows NT Connector: Go to Installing the Windows NT Connector.
- Install the Directory Server Plugin: Go to Installing Directory Server Plugins.
Installing an Active Directory Connector
After completing the steps described in Running the Installation Program, the Component Type Selection panel displays.
Note
After you install the Directory Server Connector and if you have other configured Connectors to install, the installation program will give you the option of installing the Connectors or installing the Directory Server Plugin before you see the Connector Configuration pane (Figure 5-7).
Figure 5-7 Selecting the Connector
The component list contains only those Connector components that have not yet been installed. For example, if you already installed the Directory Server Connector (dc=example,dc=com in this case), it will not be listed.
To install an Active Directory Connector:
- Enable the Connector button and click Next.
The Connector Configuration panel displays (see Figure 5-8).
Figure 5-8 Selecting the Active Directory Connector
The Select components to install list contains only those Connector components that have not yet been installed. For example, after you install the Directory Server Connector (dc=example,dc=com in this case), the program will remove the entry from this list pane.
- Enable the button next to the Active Directory component and then click Next.
The Ready to Install pane is displayed (Figure 5-9) to provide information about the Connector’s installation location and how much disk space is required for the installation.
Figure 5-9 Ready to Install Pane
- When you are ready, click the Install Now button.
An Installing pane is displayed, with a progress bar, while the program installs the binaries, and then an Installation Summary pane is displayed to confirm the installation is finished.
- Click the Details button if you want to review the installation log.
- On Solaris: Installation logs are written to /var/sadm/install/logs/
- On Windows: Installation logs are written to the %TEMP% directory, which is a subdirectory of the Local Settings folder located under
C:\Documents and Settings\Administrator
- Click Next and the “To Do list” panel is displayed (Figure 5-10) to indicate which steps you have completed successfully and which steps remain.
Figure 5-10 To Do List
- When you are done with the panel, click Finished to exit the installation program.
After installing the Active Directory Connector, you can install other Connectors and/or Directory Server Plugins that you configured when you configured resources (Chapter 4):
- Install additional Active Directory Connectors: Restart the installation program (see Running the Installation Program) and then repeat Step 1 through Step 6.
- Install a Windows NT Connector: Go to Installing the Windows NT Connector.
- Install additional Directory Server Connectors: Restart the installation program (using the instructions in Running the Installation Program) and then repeat Step 1 through Step 7.
- Install the Directory Server Plugin: Go to Installing Directory Server Plugins.
Installing the Windows NT Connector
Note
You must install the Windows NT Connector on the Primary Domain Controller (PDC) of the domain you configured.
After completing the steps described in Running the Installation Program, the Connector Configuration panel displays.
To install a Windows NT Connector and the NT subcomponent(s):
- Enable the Windows NT Connector button and click Next.
- When the Connector Port Configuration pane is displayed, enter the Fully Qualified Local Host Name with the domain and an available port number where the Connector will listen. (Specifying a port already in use will result in an error message.)
The Directory Server Plugin needs access to the configuration information you saved in the Console. To get this information, the Plugin communicates with the Windows NT Connector, through a server socket on this port. Additionally, the Plugin logs messages over this channel so the messages will go to the central log.
- When you are done, click Next.
The Ready to Install pane is displayed to provide information about the Connector’s installation location and how much disk space is required.
- When you are ready, click the Install Now button.
The Connector installation is accomplished in two steps:
- An Installing pane is displayed, with a progress bar, while the program installs the binaries.
- Next, the Component Configuration pane displays. A progress bar is displayed because this step takes several minutes to complete.
Note
If you did not close the Console before starting the installation, a warning displays (see Figure 5-5). Click Reset in the Console to reload the Connector’s configuration settings.
When both steps are complete, an Installation Summary pane is displayed.
- Click the Details button if you want to review the installation log.
Installation logs are written to the %TEMP% directory, which is C:\TEMP on most Windows NT systems.
- Click Finished to exit the installation program.
After installing the Windows NT Connector, you can install other Connectors and/or Directory Server Plugins that you configured when you configured resources (Chapter 4):
- Install additional Windows NT Connectors: Restart the installation program (see Running the Installation Program) and then repeat Step 1 through Step 6.
- Install an Directory Server Connector: Go to Installing the Directory Server Connector.
- Install an Active Directory Connector: Go to Installing an Active Directory Connector.
- Install the Directory Server Plugin: Go to Installing Directory Server Plugins.
Installing Directory Server PluginsThis section explains how to install the Identity Synchronization for Windows Directory Server Plugin.
- Complete the steps described in Running the Installation Program.
Figure 5-11 Selecting the Directory Server Plugin
- When the Connector Configuration panel is displayed, enable the Directory Server Plugin (dc=example,dc=com) button and click Next.
- Another Directory Server Plugin Installation pane is displayed (Figure 5-12).
Figure 5-12 Specifying the Directory Server URL and Credentials
- Select the appropriate Host Type from the drop-down list.
- Enter the URL where your Directory Server exists, if it is not a preferred or secondary host.
- Enter the Directory Server administrator’s name and password, and then click Next.
The Ready to Install pane is displayed to provide information about the Plugin’s installation location and how much disk space is required for the installation.
- When you are ready, click the Install Now button.
The Plugin installation is accomplished in two steps:
- When both steps are complete, the following prompt is displayed. After reading the information, click OK to close the dialog box.
Figure 5-13 Restart Directory Server Prompt
- Click the Details button if you want to review the installation log.
- On Solaris: Installation logs are written to /var/sadm/install/logs/
- On Windows: Installation logs are written to the %TEMP% directory, which is a subdirectory of the Local Settings folder located under
C:\Documents and Settings\Administrator
- Click Finished to exit the installation program.
The “To Do list” panel is displayed (similiar to Figure 5-10) to indicate which steps remain in the installation/configuration process.
After installing the Directory Server Plugin, you can install other Connectors and/or Directory Server Plugins that you configured when you configured resources (Chapter 4):
- Install additional Directory Server Plugins: Restart the installation program (see Running the Installation Program) and then repeat Step 2 through Step 9.
- Because Identity Synchronization for Windows requires you to install the Plugin on every Directory Server in your deployment, you can continue running the Plugin installation program an unlimited number of times.
- Install an Directory Server Connector: Go to Installing the Directory Server Connector.
- Install an Active Directory Connector: Go to Installing an Active Directory Connector.
- Install a Windows NT Connector: Go to Installing the Windows NT Connector.
- If you have no other connectors or plugins to install, restart Directory Server.