Novell Access Manager 3.1 SP4 Quick start guide

Category
Software
Type
Quick start guide
www.novell.com/documentation
Quick Start
Access Manager 3.1 SP5
January 2013
Legal Notices
Novell,Inc.,makesnorepresentationsorwarrantieswithrespecttothecontentsoruseofthisdocumentation,andspecifically
disclaimsanyexpressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.,
reservestherighttorevisethispublicationandtomakechangestoitscontent,at
anytime,withoutobligationtonotifyany
personorentityofsuchrevisionsorchanges.
Further,Novell,Inc.,makesnorepresentationsorwarrantieswithrespecttoanysoftware,andspecificallydisclaimsany
expressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.,reservestheright
to
makechangestoanyandallpartsofNovellsoftware,atanytime,withoutanyobligationtonotifyanypersonorentityof
suchchanges.
AnyproductsortechnicalinformationprovidedunderthisAgreementmaybesubjecttoU.S.exportcontrolsandthetrade
lawsofothercountries.Youagreeto
complywithallexportcontrolregulationsandtoobtainanyrequiredlicensesor
classificationtoexport,reexportorimportdeliverables.YouagreenottoexportorreexporttoentitiesonthecurrentU.S.
exportexclusionlistsortoanyembargoedorterroristcountriesasspecifiedintheU.S.
exportlaws.Youagreetonotuse
deliverablesforprohibitednuclear,missile,orchemicalbiologicalweaponryenduses.SeetheNovellInternationalTrade
ServicesWebpage(http://www.novell.com/info/exports/)formoreinformationonexportingNovellsoftware.Novellassumes
noresponsibilityforyourfailuretoobtainanynecessaryexportapprovals.
Copyright©2013Novell,
Inc.Allrightsreserved.Nopartofthispublicationmaybereproduced,photocopied,storedona
retrievalsystem,ortransmittedwithouttheexpresswrittenconsentofthepublisher.
Novell, Inc.
1800 South Novell Place
Provo, UT 84606
U.S.A.
www.novell.com
OnlineDocumentation:ToaccessthelatestonlinedocumentationforthisandotherNovellproducts,seetheNovell
DocumentationWebpage(http://www.novell.com/documentation).
Novell Trademarks
ForNovelltrademarks,seetheNovellTrademarkandServiceMarklist(http://www.novell.com/company/legal/trademarks/
tmlist.html).
Third-Party Materials
Allthirdpartytrademarksarethepropertyoftheirrespectiveowners.
Contents 3
Contents
About This Guide 5
1 Installing Access Manager Components 7
1.1 System Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.2 Administration Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.2.1 Linux Administration Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.2.2 Windows Administration Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.3 Identity Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.3.1 Linux Identity Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
1.3.2 Windows Identity Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
1.4 Access Gateway Appliance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
1.5 Access Gateway Service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
1.6 SSL VPN Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
1.7 Verifying the Installation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
2 Configuring Access Manager Components 13
2.1 New Identity Server Cluster Configuration. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13
2.2 First Reverse Proxy Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
2.3 Configuring the Protected Resource for Authentication. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
2.4 Basic Configuration for SSL VPN. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
2.4.1 Configuring Authentication for ESP-Enabled SSL VPN. . . . . . . . . . . . . . . . . . . . . . . . . . . .18
2.4.2 Accelerating the Traditional SSL VPN Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
3 Configuring SSL 21
3.1 Configuring a New Identity Server Cluster with SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .21
3.2 Configuring a New Access Gateway for SSL. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .24
4 Configuring Access Manager Components In A Multi-Tenant Network 27
4.1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .27
4.2 System Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .27
4.3 Network Setup Flow Chart . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
4.4 Network Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .28
4.4.1 Service Provider Network Setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .28
4.4.2 Customer Network Setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
5 Installing Access Manager Components in NAT Environments 31
5.1 Deployment Scenarios. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31
5.1.1 Administration Console in Private Network Behind NAT Configuration and Access Gateway
in Public Network. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
5.1.2 Both the Administration Console and Access Gateway IP Address Behind NAT Configuration
In Conflicting Scenario. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
5.1.3 The Administration Console is Behind NAT Configuration and the Access Gateway IP
Address Through VPN Tunnel In Non-Conflicting Scenario . . . . . . . . . . . . . . . . . . . . . . . .34
5.2 Installing the Administration Console. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
5.3 Configuring Global Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .35
4 Contents
5.4 Installing Sentinel Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .36
5.5 Configuring Audit Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36
5.6 Installing Identity Servers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
5.7 Configuring User Stores. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .38
5.8 Installing Access Gateway. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .38
5.9 Configuring Access Gateway. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .38
6 Troubleshooting the Access Manager Components in NAT Environemnt 39
6.1 Access Gateway is Not Importing into Administration Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
6.2 After Importing the Access Gateway Service, the Embedded Service Provider Does not Start . . . .39
6.3 Access Gateway Takes More Than Five Minutes to Complete Service Provider Refresh Command and
Access Gateway Events Are Not Seen in Sentinel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
6.4 The Access Gateway Service Fails to Start on the Embedded Service Provider . . . . . . . . . . . . . . .40
6.5 After installing the Identity Server, Communication to Access Gateway Fails, Due to port 8443 Listens
on Loop Back Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .41
About This Guide 5
About This Guide
ThisguideisdesignedtohelpyougetabasicAccessManagersysteminstalledandconfigured.It
containsthefollowing:
Chapter 1,“InstallingAccessManagerComponents,”onpage 7
Chapter 2,“ConfiguringAccessManagerComponents,”onpage 13
Chapter 3,“ConfiguringSSL,”onpage 21
Chapter 4,“ConfiguringAccessManagerComponentsInAMultiTenantNetwork,”onpage 27
Chapter 5,“InstallingAccessManagerComponentsinNATEnvironments,”onpage 31
Chapter 6,“TroubleshootingtheAccessManagerComponentsinNATEnvironemnt,”on
page 39
Audience
ThisguideisintendedforAccessManageradministratorswhoarenewtotheproduct.
ItisassumedthatyouhavetheknowledgeofevolvingInternetprotocols,suchas:
ExtensibleMarkupLanguage(XML)
SimpleObjectAccessProtocol(SOAP)
SecurityAssertionMarkupLanguage(SAML)
PublicKeyInfrastructure(PKI)digitalsignatureconceptsandInternet
security
SecureSocketLayer/TransportLayerSecurity(SSL/TLS)
HypertextTransferProtocol(HTTPandHTTPS)
UniformResourceIdentifiers(URIs)
DomainNameSystem(DNS)
WebServicesDescriptionLanguage(WSDL)
Feedback
Wewanttohearyourcommentsandsuggestionsaboutthismanualandtheotherdocumentation
includedwiththisproduct.PleaseusetheUserCommentsfeatureatthebottomofeachpageofthe
onlinedocumentation,orgotowww.novell.com/documentation/feedback.htmlandenteryour
commentsthere.
Documentation Updates
ForthemostrecentversionoftheAccessManagerQuickStartGuide,visittheNovellAccessManager
DocumentationWebsite(http://www.novell.com/documentation/novellaccessmanager31).
Additional Documentation
NetIQAccessManager3.1SP5InstallationGuide
6 Novell Access Manager 3.1 SP5 Quick Start
NetIQAccessManager3.1SP5SetupGuide
NetIQAccessManager3.1SP5AdministrationConsoleGuide
NetIQAccessManager3.1SP5PolicyGuide
NetIQAccessManager3.1SP5IdentityServerGuide
NetIQAccessManager3.1SP5AccessGatewayGuide
NovellAccessManager3.1SP4SSLVPNServerGuide
NetIQAccessManager
3.1SP5J2EEAgentGuide
1
Installing Access Manager Components 7
1
Installing Access Manager Components
AbasicAccessManagerinstallationhasthreeAccessManagercomponents(anAdministration
Console,anIdentityServer,andanAccessGateway),anLDAPserver,andWebserverswith
applicationsanddata.Figure11illustratesasetupwherethesecomponentsareinstalledonseparate
machines.
Figure 1-1 BasicInstallation
TheAdministrationConsolemustbeinstalledfirst.Theothercomponentscanthenbeinstalledin
anyorder.TheSSLVPNservercanbeinstall edsothatitcommunicateswiththeIdentity Serveror
withtheAccessGatewayforauthenticationcredentials.
Section 1.1,“SystemRequirements,”onpage 8
Section 1.2,AdministrationConsole,”onpage 8
Section 1.3,“Identity
Server,”onpage 8
Section 1.4,AccessGatewayAppliance,”onpage 9
Section 1.5,AccessGatewayService,onpage 10
Section 1.6,“SSLVPNServer,”onpage 10
Section 1.7,“VerifyingtheInstallation,”onpage 11
Administration Console
LDAP Server
Identity Server
SSL VPN Server
Web Servers
Access Gateway
8 Novell Access Manager 3.1 SP5 Quick Start
1.1 System Requirements
Reviewthefollowingsectionstoensurethatyourmachinesorvirtualimagesmeettheinstallation
prerequisites:
AdministrationConsoleRequirementsintheNetIQAccessManager3.1SP5InstallationGuide
IdentityServerRequirementsintheNetIQAccessManager3.1SP5InstallationGuide
AccessGatewayRequirementsintheNetIQAccessManager
3.1SP5InstallationGuide
SSLVPNRequirementsintheNetIQAccessManager3.1SP5InstallationGuide
1.2 Administration Console
1.2.1 Linux Administration Console
1 Downloadthe
tar.gz
file,extractit,anduse
install.sh
tostarttheinstallation.
Forsoftwaredownloadinstructions,seethe“NovellAccessManagerReadme”(http://
www.novell.com/documentation/novellaccessm anager31/accessmanager_readme/data/
accessmanager_readme.html).
2 AttheInstallationmenu,select1,thenfollowtheprompts.
3 AnswerYestotheprimaryinstallation prompt.
1.2.2 Windows Administration Console
1 DownloadtheWindowsfileand executeit.
Forsoftwaredownloadinstructions,seethe“NovellAccessManagerReadme”(http://
www.novell.com/documentation/novellaccessm anager31/accessmanager_readme/data/
accessmanager_readme.html).
2 SelecttoinstalltheNovellAccessManagerAdministrationcomponent.
3 AnswerYestotheprimaryinstallation prompt.
1.3 Identity Server
TheIdentityServercanbeinstalledonitsownmachineorwiththeAdministrationConsole.
What you need to know
The username and password you want to use for the Access Manager
administrator.
This is your first installation of an Administration Console, so answer Yes
for a primary installation, when prompted.
You can create a failover environment by installing more than one
Administration Console. For more information, see “Clustering and Fault
Tolerance” in the NetIQ Access Manager 3.1 SP5 Setup Guide.
For more information See “Installing the Access Manager Administration Console” in the NetIQ
Access Manager 3.1 SP5 Installation Guide.
Installing Access Manager Components 9
1.3.1 Linux Identity Server
1 Downloadthe
tar.gz
file,extractit,anduse
install.sh
tostarttheinstallation.
Forsoftwaredownloadinstructions,seethe“NovellAccessManagerReadme”(http://
www.novell.com/documentation/novellaccessm anager31/accessmanager_readme/data/
accessmanager_readme.html).
2 AttheInstallationmenu,select2,thenfollowtheprompts.
1.3.2 Windows Identity Server
1 DownloadtheWindowsfileand executeit.
Forsoftwaredownloadinstructions,seethe“NovellAccessManagerReadme”(http://
www.novell.com/documentation/novellaccessm anager31/accessmanager_readme/data/
accessmanager_readme.html).
2 SelecttoinstalltheNovellIdentityServercomponent.
1.4 Access Gateway Appliance
1 InserttheCD.
2 Attheinstallation optionspage,selectStandardInstallation.
3 Acceptthelicenseagreement.
4 Selectanappropriatekeyboardandtimezone.
5 ChangethedateandtimetomatchtheIdentityServer.
6 Specifythefollowinginfo rmation:
TheNetworkConfigurationinformation.SpecifytheIPaddressyouhaveselectedforthe
AccessGateway.
What you need to know
Username and password of the Access Manager administrator.
(Conditional) IP address of the Administration Console if it is installed on a
separate machine
For more information See Installing the Novell Identity Server” in the NetIQ Access Manager 3.1 SP5
Installation Guide.
What you need to know
Username and password of the Access Manager administrator.
IP address of the Administration Console.
Static IP address, hostname, and domain name to use for the Linux
Access Gateway.
Network settings: IP address of default gateway and the subnet mask for
your network.
DNS settings: the IP address of one or two DNS servers.
For more information See “Installing the Linux Access Gateway Appliance” in the NetIQ Access
Manager 3.1 SP5 Installation Guide.
10 Novell Access Manager 3.1 SP5 Quick Start
Apasswordforthe
root
user.
ThehostnameanddomainnamefortheAccessGatewayandtheIPaddressofatleastone
DNSserver.
TheIPaddress,username,andpasswordoftheAdministrationConsole.
(Optional)IfyouwanttoinstallSSLVPNalongwithLinuxAccessGateway,selectInstall
andenableSSLVPNService.
7 ClickNextandreviewtheinstallationsettingspage.
8 ClickInstalltocontinuewithinstallation.
Duringinstallation,themachinereboots.Duringthereboot,someerrormessagesaredisplayed.
Letthemscrollbyandwaitfortheloginprompt.
1.5 Access Gateway Service
1 DownloadthefiletotheLinuxorWindowsmachine.
Forsoftwaredownloadinstructions,seethe“NovellAccessManagerReadme”(http://
www.novell.com/documentation/novellaccessm anager31/accessmanager_readme/data/
accessmanager_readme.html).
2 (Linux)Grantexecuterightstotheinstallationprogram.
3 Starttheinstallationprogram:
Linux:Enterthefollowingcommand:
./<filename>
Windows:Doubleclicktheexecutablefile.
4 Acceptthelicenseagreement.
5 SpecifytheAdministrationConsoleinformation.
6 Configurethediskcache.
7 Reviewtheinstallationsummary.
8 Ifeverythinglookscorrect,selecttoinstall.
1.6 SSL VPN Server
What you need to know
Username and password of the Access Manager administrator.
IP address of the Administration Console.
For more information See “Installing the Access Gateway Service” in the NetIQ Access Manager 3.1
SP5 Installation Guide.
What you need to know
Username and password of the Access Manager administrator.
IP address of the Administration Console.
For more information See “Installing the SSL VPN Server” in the NetIQ Access Manager 3.1 SP5
Installation Guide.
Installing Access Manager Components 11
YoucaninstalltheSSLVPNservereitherasatraditionalSSLVPNserver(whichcommunicateswith
theAccessGatewayforauthenticationcredentials)orasanESPenabledserver(whichcomm unicates
withtheIdentityServerforauthenticationcredentials).YoucaninstalltheSSLVPNserverona
separatemachine,withthe
IdentityServer,withtheAdministrationConsole,orwiththeAccess
GatewayAppliance.
ToinstalltheSSLVPNonaseparatemachine,continuewiththissection.
ToinstalltheSSLVPNwiththeIdentityserver,seeSection 1.3,“IdentityServer,”onpage 8.
ToinstalltheSSLVPNwiththeAdministrationConsole,
seeSection 1.2,A dministration
Console,”onpage 8.
ToinstalltheSSLVPNwiththeAccessGatewayAppliance,seeSection 1.4,AccessGateway
Appliance,”onpage 9
ToinstallSSLVPNonaseparatemachine:
1 Downloadthe
tar.gz
file,extractit,anduse
install.sh
tostarttheinstallation.
Forsoftwaredownloadinstructions,seethe“NovellAccessManagerReadme”(http://
www.novell.com/documentation/novellaccessm anager31/accessmanager_readme/data/
accessmanager_readme.html).
2 Dooneofthefollowing:
Type4toinstallthetraditionalSSLVPN.
Type3toinstalltheESPEnabledSSLVPN.
3 PressEnter,thenfol lowthe prompts.
1.7 Verifying the Installation
Toverifytheinstallationofthecomponents:
1 Openabrowserandenablebrowserpopups.
2 LogintotheAdministrationConsole.TheURListheIPaddressoftheAdministrationConsole
followedby
:8080/nps
fortheportandtheapplication.Forexample:
http://10.10.15.10:8080/nps
Ifyougetanerrormessage,restartTomcatontheAdministrationConsole:
Linux:Enterthefollowingcommand:
/etc/init.d/novell-tomcat5 restart
Windows:Enterthefollowingcommands:
net stop Tomcat5
net start Tomcat5
Ifyoustillreceiveanerror,seeUnabletoLogIntotheAdministrationConsoleinthe NetIQ
AccessManager3.1SP5AdministrationConsoleGuide.
3 ClickAccessManager>Overview.
Eachiconshouldcontainthenumberone,ifyourcomponentsuccessfullyimportedintothe
AdministrationConsole.
Ifacomponenthasnotimported,clickthelinktothedevice.Ifarepairimportoptionis
available, clickthislink.Ifitisnotavailable,seeTroubleshooting
InstallationandUpgradein
theNetIQAccessManager3.1SP5InstallationGuide.
12 Novell Access Manager 3.1 SP5 Quick Start
4 Beforecontinuingwithconfiguration,verifythefollowing:
Usethe
ping
commandtoverifythattheDNSnamesfortheIdentityServerandtheAccess
Gatewayareresolvable.
Makesuretimeissynchronizedamongyourcomponents.
2
Configuring Access Manager Components 13
2
Configuring Access Manager
Components
AbasicconfigurationhasthreeAccessManagercomponents(anAdministrationConsole,anIdentity
Server,andanAccessGateway),anLDAPserver,andWebserverswithapplicationsanddata.Figure
21illustratesaconfigurationwherethesecomponentsareinstalledonseparatemachines.
Figure 2-1 ModulesRequiredforaBasicConfiguration
ThissectionexplainshowtoconfigureyoursystemsothatusersinyourLDAPservercanloginand
accessaprotectedresourceonaWebserverandalsoaccessanSSLVPNapplication.
Section 2.1,“NewIdentityServerClusterConfiguration,”onpage 13
Section 2.2,“FirstReverseProxyConfiguration,”onpage 15
Section 2.3,“Configuring
theProtectedResourceforAuthentication,”onpage 17
Section 2.4,“BasicConfigurationforSSLVPN,”onpage 18
2.1 New Identity Server Cluster Configuration
ThissectionexplainshowtoaddyourIdentityServertoaclusterandhowtoconfiguretheclusterto
communicatewiththeLDAPserveranduseitsauthenticationcredentials.
Administration Console
LDAP Server
Identity Server
SSL VPN Server
Web Servers
Access Gateway
14 Novell Access Manager 3.1 SP5 Quick Start
Table 2-1 IdentityServerConfigurationInformation
1 IntheAdministrationConsole,clickDevices>IdentityServers.
2 ClickNewCluster.
3 Specifyanamesuchas
idpa
,selectyourIdentityServer,thenclickOK.
InTable21,
idpa
istheIdentityServerclusternameyoucreated.
4 ConfiguretheBaseURLoftheIdentityServer,usingtheDNSnameoftheIdentityServer:
http://idpa.test.novell.com:8080/nidp
InTable21,thisistheDNSnameoftheIdentityServerwithaportand
/nipd
.
5 ClickNext,thenconfiguretheorganizationinformation.
Name:
Access Manager
Displayname:
Access Manager 3
URL:
idpa.am.novell.com
InTable21,thesethreefieldsaretheorganizationinformationyoucreatedfortheIdentity
Servercluster.
6 ClickNext,thenconfiguretheuserstore:
Name:
User Store
What you need to know Example Your Value
LDAP server information:
DN of the administrator
cn=admin,o=novell
______________________
Password of the administrator
novell
_______________________
IP address of the LDAP server
10.10.10.16
______________________
DN of the user container
ou=users,o=novell
______________________
DNS name of the Identity Server
i
dpa.test.novell.com
______________________
Names you need to create:
Identity Server cluster name
idpa
______________________
User store name
User Store
_______________________
Replica name
User Store Replica
_______________________
Alias certificate name
UserStoreRoot
_______________________
Organization information for the Identity
Server cluster:
Name
Access Manager
________________________
Display name
Access Manager 3
________________________
URL
idpa.am.novell.com
________________________
For more information, see “Creating a Basic Identity Server Configuration” in the NetIQ Access Manager 3.1
SP5 Setup Guide.
Configuring Access Manager Components 15
InTable21,
User Store
isthesamplenamefortheuserstore.
Adminname:
cn=admin,o=novell
InTable21,thisisthesampleDNoftheadministratorfortheLDAPserver.
Adminpassword:
novell
Confirmpassword:
novell
InTable21,thesefieldsarethesamplepasswordfortheadministratoroftheLDAPserver.
DirectoryType:Selectatypefromthedropdownmenu.
7 IntheServerreplicassection,clickNew,thenfillinthefollowingfields:
Name:
User Store Replica
InTable21,
User Store Replica
isthesamplenameforthereplica
IPAddress:
10.10.10.16
InTable21,thisisthesampleIPaddressoftheLDAPserver.
UsesecureLDAPconnections:Selectthisoption.
Autoimporttrustedroot:Clickthislink,followtheprompts,andspecify
UserStoreRoot
for
thealias.
InTable21,
UserStoreRoot
isthesamplealiascertificatename.
8 ClickOK,thenmakesuretheValidationStatusofthereplicadisplaysagreencheckmark.Ifthe
checkmarkisred,youhaveaconfigurationerror:
Checkthedistinguishednameoftheadminuser,thepassword,andtheIPaddressofthe
replica.
Checkfornetworkcommunicationproblemsbetween
theIdentityServerandtheLDAP
server.
9 IntheSearchContextssection,clickNew,thenspecifythefollowing:
Searchcontext:
ou=users,o=novell
InTable21,thisisthesampleDNoftheusercontainer.
Scope:
Subtree
10 ClickOK>Finish,thenrestartTomcatasprompted.
11 WaitforthehealthstatusoftheIdentityServertoturngreen,thenverifytheconfiguration:
11a EntertheBaseURLoftheIdentityServerinabrowser.
http://idpa.test.novell.com:8080/nidp
11b LoginusingthecredentialsofauserintheLDAPserver.
Theuserportalappears.
IftheURLreturnsanerrorratherthandisplayingaloginpage,verifythefollowing:
ThebrowsermachinecanresolvetheDNSnameoftheIdentityServer.
Thebrowsermachinecanaccesstothe
port.
2.2 First Reverse Proxy Configuration
ThissectionexplainshowtocreateareverseproxytoprotectthenameandIPaddressofyourWeb
serverfrombeingexposedtousers.Section 2.3,“ConfiguringtheProtectedResourcefor
Authentication,”onpage 17buildsonthisconfigurationandexplainshowtorequireauthentication
togainaccesstotheWebserver.
16 Novell Access Manager 3.1 SP5 Quick Start
Table 2-2 AccessGat ewayConfigurationInformation
1 IntheAdministrationConsole,clickDevices>AccessGateways.
2 ClickEdit,thenclickReverseProxy/Authentication.
3 Configureareverseproxy:
IntheAuthenticationSettingssection,select
idpa
fromthedropdownlist.
InTable22,thisisthesamplenameoftheIdentityServercluster.
IntheReverseProxysection,clickNew,specify
DigitalAirlines
,thenclickOK.
InTable22,
DigitalAirlines
isthesamplereverseproxyname.
4 Toconfigureaproxyservice,clickNewintheProxyServicesection,thenfillinthefollowing
fields:
ProxyServiceName:
DA
InTable22,
DA
isthesampleproxyservicename.
PublishedDNSName:
lag.test.novell.com
InTable22,thisisthesampleDNSnameoftheAccessGateway.
WebServerIPAddress:
10.10.16.16
InTable22,thisisthesampleIPaddressoftheWebserver.
HostHeader:SelecttheWebServerHostNamefromthedropdownlist.
WebServerHostName:
digital.test.novell.com
InTable22,thisisthesampleDNSnameoftheWebserver.
5 ClickOK,thenconfigureaprotectedresource.
ClicktheProtectedResourcetab.
IntheProtectedResourcesection,clickNew,thenspecify
everything
.
InTable22,
everything
isthesampleprotectedresourcename.
IntheURLPathsection,examinethepath.Itshouldbesetto/*tomatcheverythingonthe
Webserver.
6 ClickOKtosavetheconfiguration.
What You Need To Know Example Your Value
Name of the Identity Server cluster
idpa
_______________________
DNS name of the Access Gateway
lag.test.novell.com
_______________________
Web server information
IP address
10.10.16.16
_______________________
DNS name
digital.test.novell.com
_______________________
Names you need to create
Reverse proxy name
DigitalAirlines
_______________________
Proxy service name
DA
_______________________
Protected resource name
everything
_______________________
For more information, see “Configuring the Access Gateway” in the NetIQ Access Manager 3.1 SP5 Setup
Guide.
Configuring Access Manager Components 17
7 ClicktheAccessGatewaystask,thenclickUp date.
Waitforthehealthstatustoturngreen.Ifitdoesn’tturngreen,clicktheHealthicontodiscover
thecause.
IftheAccessGatewaycannotconnecttotheWebserver,verifytheIPaddressoftheWeb
server.
Usethe
ping
commandtoverifythattheAccessGatewaycancommunicatewiththeWeb
serverandtheIdentityServer.
VerifythattheAccessGatewaycanresolvetheDNSnameoftheIdentityServer.
Forotherproblems,seeMonitoringtheHealthofanAccessGatewayintheNetIQAccess
Manager3.1
SP5AccessGatewayGuide.
8 ClicktheIdentityServerstask,thenclickUpdate.
9 TotestthattheAccessGatewayisprotectingtheWebserver,openabrowserandenterthe
followingURL:
http://lag.test.novell.com:80/
ThefirstpageoftheWebserverisdisplayed.Ifyougetanerror,verifythefollowing:
CheckthetimesontheAccessGatewayandtheIdentityServer.Theirtimesneedtobe
synchronized.
VerifythatthebrowsermachinecanresolvetheDNSnameoftheAccessGateway.
2.3 Configuring the Protected Resource for Authentication
ThissectionexplainshowtoconfiguretheAccessGatewaysothatusersarepromptedtologinwhen
accessingtheprotectedresource.
1 Toreturntotheprotectedresource,clickDevices>AccessGateways>Edit>DigitalAirlines>DA>
ProtectedResources>everything.
2 FortheContractoption,selectName/PasswordFormfromthedropdownlist.
Ifthelistisempty,youhavenotselectedanIdentityServerclusterconfigurationfortheAccess
Gateway.SeeStep 3onpage 16.
3 ClickOKtosavetheconfiguration.
4 ClicktheAccessGatewaystask,thenclickUp date.
5 Totestthataccessingtheresourcenowrequiresauthentication,openabrowser,thenenterthe
URLtoyourprotectedresource:
http://lag.test.novell.com:80/
Whenyouarepromptedforlogincredentials,useanameandapasswordfromauseronthe
LDAPserver.
Ifyoureceiveanerror,verifythefollowing:
TheIdentityServercanresolvetheDNSnameoftheAccessGateway.
TheAccessGatewaycanresolvetheDNSnameoftheIdentity
Server.
TimeissynchronizedbetweentheIdentityServerandtheAccessGateway.
Forotherproblems,seeGeneralAuthenticationTroubleshootingTipsintheNetIQAccess
Manager3.1SP5IdentityServerGuide.
18 Novell Access Manager 3.1 SP5 Quick Start
2.4 Basic Configuration for SSL VPN
ThissectionexplainshowtocreateabasicconfigurationfortheSSLVPNserver.
IfyouhaveinstalledtheESPenabledSSLVPN,continuewithSection 2.4.1,“Configuring
AuthenticationforESPEnabledSSLVPN,”onpage 18.
IfyouhaveinstalledthetraditionalSSLVPN,continuewithSection 2.4.2,Acceleratingthe
TraditionalSSL
VPNServer,”onpage 19.
2.4.1 Configuring Authentication for ESP-Enabled SSL VPN
ThissectionexplainshowtoestablishatrustrelationshipbetweentheIdentityServerandthe
EmbeddedServiceProvideroftheSSLVPNserver.
Table 2-3 ESPEnabledSSLVPNConfigurationInformation
1 IntheAdministrationConsole,clickDevices>SSLVPNs>Edit.
2 SelectAuthenticationConfigurationfromthe GatewayConfigurati onsection.
3 Fillinthefollowingfields:
IdentityServerCluster:
idpa
InTable23,thisisthesamplenameoftheIdentityServercluster.
AuthenticationContract:SelectAnyContract.
EmbeddedServiceProviderBaseURL:
https:sslvpn.test:8443/sslvpn
InTable23,thisistheDNSnamefortheSSLVPNserver.ItassumesyouwanttouseHTTPS.If
youwanttouseHTTP,select
http
andmakesuretheportis8080.
RedirectRequestsfromNonSecurePorttoSecurePort:Selectthisoptionifyouareusing
HTTPS.
SSLVPNCertificate:Clicktheiconandselectthecertificatethathasasubjectnamethat
matchestheDNSnameoftheSSLVPNserver.
EmbeddedService
ProviderCertificate:Clicktheiconandselectthecertificatethathas a
subjectnamethatmatchestheDNSnameoftheSSLVPNserver.
4 RestarttheTomcatserverwhenprompted.
5 ClickOK,thenclickUpdateontheConfigurationpage.
6 ClickUpdateontheIdentityServerConfigurationpage.
What You Need To Know Example Your Value
Name of the Identity Server cluster
idpa
_______________________
DNS name of the SSL VPN machine
sslvpn.test.novell.com
_______________________
A certificate where the subject name
matches the DNS name of the SSL VPN
machine
For information on how to create such a certificate, see “Creating
a Locally Signed Certificate” in the NetIQ Access Manager 3.1
SP5 Administration Console Guide.
For more information, see “Configuring Authentication for the ESP-Enabled Novell SSL VPN” in the NetIQ
Access Manager 3.1 SP5 Setup Guide.
Configuring Access Manager Components 19
2.4.2 Accelerating the Traditional SSL VPN Server
ThissectionexplainshowtoacceleratethetraditionalSSLVPNserverinapathbasedmultihoming
configuration.
1 IntheAdministrationConsole,clickDevices>AccessGateways,thenclickEdit>[NameofReverse
Proxy].
2 IntheProxyServiceList,clickNew,thenprovidethefollowingvalues:
ProxyServiceName:Specifysslvpn.
MultiHomingType:SelectPathBased.
Path:Specify/sslvpn.
WebServerIPAddress:SpecifytheIPaddressofSSLVPNserver.
HostHeader:IfyourSSLVPNserverhasaDNSname,select
WebServerHostName.Otherwise,
selectForwardReceivedHostName.
WebServerHostName:SpecifytheDNSnameoftheSSLVPNserverifyouselectedWebServer
HostNamefortheHostHeaderoption.
3 ClickOK.
4 IntheProxyServiceList,clicksslvpn>WebServers.
5 ChangetheConnectPortfrom80to8080,thenclickOK.
6 IntheProxyServiceList,selectthesslvpn.
7 InthePathList,selectthesslvpnpath,thenclickEnableSSLVPN.
8 Fillinthefollowingfields:
PolicyContainer:SelectMaster_Container.
Policy:SelectCreateSSLVPNDefaultPolicy.InthePolicyListwindow,clickApplyChanges,then
clickClose.
Name:SelectCreateSSLVPNDefaultProtectedResource.
9 ClickOKtwice,thenupdatetheAccessGatewayandtheSSLVPNserver.
20 Novell Access Manager 3.1 SP5 Quick Start
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40
  • Page 41 41
  • Page 42 42

Novell Access Manager 3.1 SP4 Quick start guide

Category
Software
Type
Quick start guide

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI