IT Process Automation

  • 1.  Logging into ITPAM as an LDAP user through EEM

    Broadcom Employee
    Posted Mar 07, 2012 11:30 AM
    CA Process Automation Tech Tip by Andy Thompson, Sr. Support Engineer, March 7, 2012

    The following tech doc has been posted to walk through enabling LDAP authentication to ITPAM via EEM.
    https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=TEC565739


  • 2.  Re: Logging into ITPAM as an LDAP user through EEM

    Posted Mar 29, 2018 01:41 PM

    Are we able to do pass-through authentication with LDAP?  Want to put users into one AD group to use PAM and also not have to have users log into PAM and not have to add users to the PAM Application in EEM.

     

    Is that possible?



  • 3.  Re: Logging into ITPAM as an LDAP user through EEM

    Broadcom Employee
    Posted Mar 29, 2018 02:35 PM

    This is very possible Paul, you can setup a Dynamic group to allow everyone basic PAM access, or a specific group.

    Please see:

    Dynamic Group Policy to enable PamUsers level permissions for everyone in Active Directory



  • 4.  Re: Logging into ITPAM as an LDAP user through EEM

    Posted Mar 29, 2018 02:42 PM

    The reason I asked was because the documentation calls for NTLM pass through and doesn't talk about LDAP.  So I can set up EEM authentication with LDAP and set the "ntlm.enabled=true" in the OASISCONFIG.Properties on the PAM server and this will make it so the user doesn't have to log-in again.



  • 5.  Re: Logging into ITPAM as an LDAP user through EEM

    Broadcom Employee
    Posted Mar 29, 2018 02:45 PM

    Sorry if I misunderstood your question. Unfortunately NTLM is Microsoft specific and will only work with Microsoft Active Directory.  

    Process Automation can authenticate users against with other LDAP servers, but cannot do pass through authentication.



  • 6.  Re: Logging into ITPAM as an LDAP user through EEM

    Posted Mar 29, 2018 02:50 PM

    I have used LDAP in the past to connect to AD.  Just to confirm, so if there is one AD Domain we can set it up as NTLM authentication which will allow for the Dynamic AD Group to be assigned to PAM Users and then do the PAM server configuration to allow pass through.



  • 7.  Re: Logging into ITPAM as an LDAP user through EEM

    Broadcom Employee
    Posted Mar 29, 2018 04:12 PM

    Simply - yes.

    In order to utilize NTLM/Pass through authentication for CA Process Automation, EEM must be setup and connected to an external AD server.

    Connect EEM to your AD domain, follow the procedure outlined in the knowledge article provided by Michael, and as long as your users are logged in with their network credentials to their workstations, pass through authentication will work after having enabled NTLM in the oasisconfig.properties file for Process Automation.