WebSphere Application Server & Liberty

WebSphere Application Server & Liberty

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Lost Primary Administrative User Name

    Posted Wed August 10, 2011 11:04 AM












     


    Hi

    I didn't create an administrative account during the initial installation. Then I used admin/ login and configured the security with LDAP, and added a couple of LDAP/AD ids into the administrative role. After re-started WAS7, I can't login with "admin/" anymore.

    1. How can I create a new primary admistrative id?
    2. Is there anything I can't do with these LDAP id in administrative role? I mean do I have to have that primary admistrative id

    Thanks
    Jirong



  • 2.  Lost Primary Administrative User Name

    Posted Wed August 10, 2011 04:15 PM

    If i understand it correctly..



    • Initially you did not set up a administrative user ... so security is not enabled?

    • Then, you configured LDAP as user repository and set it as current.


     



    1. Login with the Primary administrative user account you supplied while configuring LDAP. [you must entered this while configuring LDAP as user repository] . This is the primary administrative user ID now.

    2. You can add a new user and then give him administrator role and adminsecuritymanager role [with this he can do user management] and iscadmin role [for user management when using federated repositories]



  • 3.  Lost Primary Administrative User Name

    Posted Wed August 10, 2011 04:48 PM

    Your understanding is perfectly right, however


     


    1. From this post, jazz.net/forums/viewtopic.php?t=18796&hi..., I used "admin" in this Primary Administrative user name while configuring LDAP. This is not in AD/LDAP so now I can't login with "admin" (I was using my own id and later got confused).


    2. I don't understand this. How can I add more users? I see no menu can click in Users and Groups --> Manage User (not enough privilege with my current login?)


    I added my id into the administrative role while configuring LDAP. But now when I login with my id, I can't see the "Aministrative Role" menu beside the "Enable administrative security" anymore. So I can't add more users into this role, and I am afraid if I can' t do all the admin work.


     


    I am not an expereince WAS admin, just my RTC using it.


     


    Thanks


    Jirong



  • 4.  Lost Primary Administrative User Name

    Posted Wed August 10, 2011 09:12 PM

    primary administrative user specified while configuring LDAP is not available in LDAP.


    The users who doesn't have security admin role assigned cannot manage users [add/remove/assign role]


     


    You may follow these steps



    • Disable the security by editing security.xml

    • Then restart the servers

    • Configure the LDAP again with correct configuration and with a user available in LDAP.


     


    Steps to disable and enable passowrd, when administrator not able to login :


    josephamrithraj.wordpress.com/2011/03/01...


     



  • 5.  Lost Primary Administrative User Name

    Posted Thu August 11, 2011 12:44 PM

    I want to follow your process to get back the primary admin user. However, I've already deployed some applications and inside the application, created some Security roles to group mapping.


    If I disable the security, will I:


     


    1. lose all LDAP info in the Global Security --> Standalone LDAP registry? This is ok, I can redo.


    2. lose the Security roles to group mapping inside each application, more important, will it demage the application?


    Thanks for your time to help.


    Jirong



  • 6.  Lost Primary Administrative User Name

    Posted Thu August 11, 2011 02:01 PM

    1. Yes


    2. You need to re-do the role mappings



  • 7.  Lost Primary Administrative User Name

    Posted Thu August 11, 2011 04:38 PM

    OK, i am done, works perfect.


    The good news is all the old LDAP info and setting are still there, application role mapping are also there.


    Thanks a lot for helping.


    Jirong



  • 8.  Lost Primary Administrative User Name

    Posted Thu August 11, 2011 04:46 PM

    Good to hear that the issue was RESOLVED.


    I though role mapping [not applications but administrative roles] will disappear.