IBM License Metric Tool (ILMT)

IBM License Metric Tool (ILMT)

Connect with Db2, Informix, Netezza, open source, and other data experts to gain value from your data, share insights, and solve problems.

 View Only
  • 1.  Azure AD SSO integration with ILMT

    Posted Fri October 13, 2023 11:08 AM

    Has anyone tried integrating ILMT with AZURE AD SSO? We are thinking to implement the same in our environment . We had tried to implement SSO in our test environment but the URL didnt work. Could someone please guide me through?



    ------------------------------
    Sarthak saluja
    ------------------------------


  • 2.  RE: Azure AD SSO integration with ILMT

    Posted Fri October 13, 2023 12:51 PM

    Hello Sarthak,

    As of now integrating ILMT with AZURE is at the wish list (IDEA / RFE).

    However some customers have successfully implement SAML (using WebSphere) with Azure AD as IdP.
    So, I'd say that it's doable but requires some additional setup...

    As a starting point there are three things to verify :

    1) Which URL is it ?
    Does the 'Login page URL' on SSO page has the value copied from Azure console "Azure > Properties > access URL

    2) Has the spMetadata.xml been imported to Azure AD ?
    procedure is described in following :
    https://www.ibm.com/docs/en/license-metric-tool?topic=token-step-2-configuring-identity-provider-single-sign#configuring_claim_rule3)

    3) You have to make sure that Azure IdP provider is configured to allow for HTTP-POST binding in order to interoperate with ILMT.
    (By default, Azure AD only enables HTTP redirect binding and not HTTP POST binding, HTTP redirect binding is not supported by ILMT/WebSphere)



    ------------------------------
    Thank you,
    Oktawian

    Oktawian Powązka, L3 Support
    IBM License Metric Tool
    ------------------------------



  • 3.  RE: Azure AD SSO integration with ILMT

    Posted Tue October 17, 2023 03:19 AM

    Hi,

    Thanks for the reply. Is there any document to support the claim regarding ILMT not supporting http redirect binding and only supports http post binding?

    Regards,

    Sarthak Saluja



    ------------------------------
    Sarthak saluja
    ------------------------------



  • 4.  RE: Azure AD SSO integration with ILMT

    Posted Tue October 17, 2023 04:13 AM

    Hello,

    Not really...
    It's not included in our documentation.

    As a matter of fact SSO setup is no controlled by ILMT but by underlying Liberty profile (WebSphere).
    Here are some troubleshooting steps for SSO setup (containing that aforementioned claim):
    https://www.ibm.com/support/pages/troubleshoot-saml-web-sso-websphere-traditional



    ------------------------------
    Thank you,
    Oktawian

    Oktawian Powązka, L3 Support
    IBM License Metric Tool
    ------------------------------



  • 5.  RE: Azure AD SSO integration with ILMT

    Posted Mon October 30, 2023 02:51 AM

    All of the prerequisites are checked but still the login page is only loading, nothing is coming up even after waiting 30 minutes.



    ------------------------------
    Sarthak saluja
    ------------------------------



  • 6.  RE: Azure AD SSO integration with ILMT

    Posted Mon October 30, 2023 07:10 AM

    Hello,

    Screenshot is not enough to deduce anything...

    Please enable SAML SSO traces by extending 'traceSpecification' of the 'logging' stanza found in ILMT's server.xml file : 
    ... maxFileSize="10" maxFiles="20" messageFileName="tema.log" traceFormat="BASIC" traceSpecification="*=info:com.ibm.ws.security.web.*=all:com.ibm.ws.security.saml.*=all:com.ibm.websphere.wssecurity.*=all:com.ibm.ws.wssecurity.*=all"/>

    Restart ILMT...check the login, collect the trace.log/tema.log files.

    Nevertheless, this forum is not a right medium to exchange log files (mainly due to security concerns), thus, I'd prefer that you open a dedicated ticket to ILMT support.



    ------------------------------
    Thank you,
    Oktawian

    Oktawian Powązka, L3 Support
    IBM License Metric Tool
    ------------------------------