If there is a problem with SSO, the first thing to do is check the xmppd.log server log file and the client log files for errors. Increasing the logging level may be helpful. New logging levels will only take effect after server restart.
Ensure that Instant Messaging services have been assigned to the organization and its parent organization in the Access Manager console (amconsole). See Adding Instant Messaging and Presence Services to a Sub-organization in Access Manager for Single Sign-On and Policy Management Support for information.
If you are unable to log into Instant Messaging directly, look in xmppd.log for an error similar to either of the following:
DEBUG xmppd [com.sun.im.service.util.Worker3] Service \\ URL not found:session.com.iplanet.sso.SSOException: Service URL not found:
INFO xmppd [com.sun.im.service.util.Worker 3] [Identity] \\ Failed to create SSO token for USERNAME
INFO xmppd [org.netbeans.lib.collab.util.Worker 1] [LDAP] \\ pops does not have required objectclass for storing to ldap
If any of these errors exist, use the following steps to solve the problem:
Create a user through
add authentication, configuration, Instant Messaging, and presence services to
Attempt to log in with the user you created.
Check to ensure that the amldapuser's password
is correctly filled in through
Check whether the domain, for example, o=siroe.com, has the Authentication Configuration Service Instance.
Check if the Authentication Configuration Service Instance has the Authentication Module set to LDAP or Membership. The value should show a state of REQUIRED/SUFFICIENT.
Instant Messaging only supports login with username and password. If you are using Auth-Chain, you need to disable it to use Instant Messaging.
In the LDAP or Authentication Module, enter the amldapuser password for CORE.
Select the newly created ldapService Authentication Configuration Service Instance under the Organization Authentication Configuration drop-down menu and the Administrator Authentication Configuration drop-down menu in the Core Authentication Module Configuration.
Log in again.