Symantec Access Management

Workaround to register an admin UI with multiple policy servers 

Dec 20, 2017 09:44 AM

Overview

Each adminUI must have a one-to-one mapping with a policy servers DNS entry. 
These DNS entries are saved in trusted hosts at the policy store.

Registration process

Using XPSregClient open policy server 1 for registration:
XPSRegClient siteminder:passphrase –adminui-setup
Register AdminUI with policy server 1 from the adminUI login window.
Note down the DNS entry used to register the adminUI (This entry cannot be used again)
Stop the JBOSS server on the admin UI
./jboss-cli.sh --connect --command=:shutdown
On the AdminUI server cd to:
[admin ui home]/standalone/data/derby/siteminder
Remove the objectstore folder
Start the adminui again
Using XPSregClient open policy server 2 for registration
XPSRegClient siteminder:passphrase –adminui-setup
Register AdminUI with policy server 2
Note down the DNS entry used to register the adminUI (This entry cannot be used again)
The AdminUI is now registered with both policy servers
Repeat this process for each additional ADMINUI - Remember you cannot use re-use a DNS entry already used for another AdminUI in the policy store.

Statistics
0 Favorited
8 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.