BPMSecurity WSTE
BPMSecurity WSTE
Agenda
Introduction - background of BPM security LDAP configuration.
Security Providers
User and Group Tables
Entity type mapping
BPM user Cache
Configuration files
Common Problems and solutions
Mustgather
References
Questions
Introduction
BPM integrates with user repositories which enables utilizing the existing
organizational structure to facilitate its human workflow processing.
The human centric workflow is designed to route the tasks based on the
design of a Business Process (BPD). An LDAP integration facilitates using
the existing organizational tree to be used for such routing.
security providers
User Repository
a. LDAP based repository. External to WAS
10
11
12
Unable to login to any BPM console including WAS Admin console when repository is down
http://pic.dhe.ibm.com/infocenter/wasinfo/v7r0/index.jsp?topic=%2Fcom.ibm.websphere.wim.doc%2F
UnableToAuthenticateWhenRepositoryIsDown.html
Switching Login attribute may result new users generated on LSW_USR_XREF table.
Process Admin does not show groups from LDAP after configuration.
Process Admin synchronizes all visible group by sending a query * for group. If LDAP is configured
not accepting wild card character. LDAP timeout.
Active Directory may have a default value for a maximum search result. Change MaxPageSize
according to attaching technote:
http://www-01.ibm.com/support/docview.wss?uid=swg21439593
13
JS API tw.System.org.FindUserByName() throws NPE when user has not log on to BPM.
http://www-01.ibm.com/support/docview.wss?uid=swg1JR42912
LDAP group name longer than 255 char will result a sql error.
WAS ldapsearch utility
http://www-01.ibm.com/support/docview.wss?uid=swg21113384
14
BPM mustgather
Trace Strings.
*=info:com.ibm.ws.security.*=all:com.ibm.websphere.security.*=all:com.ibm.websphere.wim.*=all:co
m.ibm.wsspi.wim.*=all:com.ibm.ws.wim.*=all:WLE.wle_security=finest
Config tree
The profile config directory that stores the profile configuration in XML files
In an ND environment , config directories from both DMGR and Federated Nodes.
15
References
http://pic.dhe.ibm.com/infocenter/dmndhelp/v8r0mx/topic/com.ibm.wbpm.ad
min.doc/topics/deploying_introduction.html
http://www-01.ibm.com/support/docview.wss?uid=swg21439593
http://www-01.ibm.com/support/docview.wss?uid=swg21113384
http://www-01.ibm.com/support/docview.wss?uid=swg21619620
16
Summary
17
Learn about upcoming WebSphere Support Technical Exchange webcasts, and access
previously recorded presentations at:
http://www.ibm.com/software/websphere/support/supp_tech.html
Access key product show-me demos and tutorials by visiting IBM Education Assistant:
http://www.ibm.com/software/info/education/assistant
View a webcast replay with step-by-step instructions for using the Service Request (SR)
tool for submitting problems electronically:
http://www.ibm.com/software/websphere/support/d2w.html
18
3. Be connected!
Connect with us on Facebook
Connect with us on Twitter
19
20