Are multiple ISVA security domains supported on the lightweight containers? I have a case open with L2 where any request on v10.0.3.0 or v10.0.3.1 using the lightweight containers fails with a 403 forbidden, even when I login as sec_master to the webseal. The webseal will authenticate the user, but it will not authorize any request. When I switch the container image to the full verify-access image, without changing any other parameters on the container, just the image, the webseal works and will authorize users and pass traffic without issue.
L2 thinks it could be because we are using security domains other than the default ISVA security domain. We have multiple administrative security subdomains setup under the default domain, and of course the webseal instance is joined to the security domain the appropriate users exist within to authenticate and authorize. This has worked fine for over a couple years on containers. However, now that I built a lab on these lightweight containers, this doesn't seem to work.
I want to make sure the multiple domains are in fact still supported on the lightweight containers, otherwise we have some additional scrambling to do on our end prior to the v10.0.4.0 release in June.
Thanks for your input!
------------------------------
Matt Jenkins
------------------------------