IBM E027SLL-H Troubleshooting Guide - Page 135

Cannot connect to the portal server

Page 135 highlights

Table 12. Cannot log in to the Tivoli Enterprise Portal Server (continued) Problem Corrective action and solution If the Tivoli Enterprise Portal Server connection to LDAP is lost. When the portal server is configured to authenticate against the LDAP server (with optionally enabled Single Sign-On capability), if you lose the portal server to LDAP connection, this will cause any log in attempt to fail with error code KFWITM393E: "User ID or password is invalid". This authentication failure will be reported for any user, including the default administrative user "sysadmin", and not only for users defined in the LDAP repository. Re-establish the connection to LDAP. As soon as the portal server to LDAP connection is re-established, you can log in to the Tivoli Enterprise Portal. If there is still a problem connecting with LDAP, de-configure LDAP authentication. If the LDAP connection is broken and the normal procedure to switch off LDAP-based authentication does not work, the following steps need to be performed: 1. For AIX and Linux systems, stop the portal server with the ./itmcmd agent stop cq command invoked from the installation directory. 2. Run the ./disableLDAPRepository.sh script from candle_home/arch/iw/ scripts, where arch is the system architecture, for example "li6263" or "aix533." 3. Reconfigure the portal server and disable LDAP authentication using the ./itmcmd config -A cq command invoked from the installation directory. 4. Start the portal server with the ./itmcmd agent start cq command invoked from installation directory. The portal server authentication through the monitoring server is now enabled. 5. If the monitoring server was also configured to use LDAP and the reason for this procedure being applied is LDAP being out of service, ensure you also change the monitoring server configuration to not authenticate through LDAP, following steps from the monitoring server configuration help. 1. For Windows systems, stop the portal server service using the Manage Tivoli Enterprise Monitoring Services application. \ 2. Run the disableLDAPRepository.bat script from candle_home\CNPSJ\ scripts. 3. Reconfigure the portal server using the Manage Tivoli Enterprise Monitoring Services application and disable the "Validate User with LDAP" option. 4. Start the portal server service using the Manage Tivoli Enterprise Monitoring Services application. The portal server authentication through the monitoring server is now enabled. 5. If the monitoring server was also configured to use LDAP and the reason for this procedure being applied is LDAP being out of service, ensure you also change the monitoring server configuration to not authenticate through LDAP, following the steps from the monitoring server configuration help. Cannot connect to the portal server Review the problems and resolutions when you have trouble with the connection to the Tivoli Enterprise Portal Server. Chapter 6. Connectivity troubleshooting 117

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310

Table 12. Cannot log in to the Tivoli Enterprise Portal Server (continued)
Problem
Corrective action and solution
If the Tivoli Enterprise Portal Server
connection to LDAP is lost.
When the portal server is configured to authenticate against the LDAP
server (with optionally enabled Single Sign-On capability), if you lose the
portal server to LDAP connection, this will cause any log in attempt to fail
with error code KFWITM393E: "User ID or password is invalid". This
authentication failure will be reported for any user, including the default
administrative user "sysadmin", and not only for users defined in the LDAP
repository.
Re-establish the connection to LDAP. As soon as the portal server to LDAP
connection is re-established, you can log in to the Tivoli Enterprise Portal.
If there is still a problem connecting with LDAP, de-configure LDAP
authentication.
If the LDAP connection is broken and the normal procedure to switch off
LDAP-based authentication does not work, the following steps need to be
performed:
1.
For AIX and Linux systems, stop the portal server with the
./itmcmd
agent stop cq
command invoked from the installation directory.
2.
Run the ./disableLDAPRepository.sh script from candle_home/arch/iw/
scripts, where arch is the system architecture, for example "li6263" or
"aix533."
3.
Reconfigure the portal server and disable LDAP authentication using the
./itmcmd config -A cq
command invoked from the installation
directory.
4.
Start the portal server with the
./itmcmd agent start cq
command
invoked from installation directory. The portal server authentication
through the monitoring server is now enabled.
5.
If the monitoring server was also configured to use LDAP and the
reason for this procedure being applied is LDAP being out of service,
ensure you also change the monitoring server configuration to not
authenticate through LDAP, following steps from the monitoring server
configuration help.
1.
For Windows systems, stop the portal server service using the Manage
Tivoli Enterprise Monitoring Services application. \
2.
Run the
disableLDAPRepository.bat
script from
candle_home\CNPSJ\
scripts
.
3.
Reconfigure the portal server using the Manage Tivoli Enterprise
Monitoring Services application and disable the "Validate User with
LDAP" option.
4.
Start the portal server service using the Manage Tivoli Enterprise
Monitoring Services application. The portal server authentication
through the monitoring server is now enabled.
5.
If the monitoring server was also configured to use LDAP and the
reason for this procedure being applied is LDAP being out of service,
ensure you also change the monitoring server configuration to not
authenticate through LDAP, following the steps from the monitoring
server configuration help.
Cannot connect to the portal server
Review the problems and resolutions when you have trouble with the connection
to the Tivoli Enterprise Portal Server.
Chapter 6. Connectivity troubleshooting
117