<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>NOVELL FORUMS - Access Manager 3</title>
		<link>http://forums.novell.com/</link>
		<description />
		<language>en</language>
		<lastBuildDate>Sun, 22 Nov 2009 08:32:37 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.novell.com/images/ca_serenity/misc/rss.jpg</url>
			<title>NOVELL FORUMS - Access Manager 3</title>
			<link>http://forums.novell.com/</link>
		</image>
		<item>
			<title>multihoming - mixing dns and path based?</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393491-multihoming-mixing-dns-path-based.html</link>
			<pubDate>Fri, 20 Nov 2009 21:10:52 GMT</pubDate>
			<description><![CDATA[I'm on my last iChain to NAM upgrade. 
 
The ichain setup had 3 accelerators on it. 
 
One was regular domain based multihoming (with a few items...]]></description>
			<content:encoded><![CDATA[<div>I'm on my last iChain to NAM upgrade.<br />
<br />
The ichain setup had 3 accelerators on it.<br />
<br />
One was regular domain based multihoming (with a few items having Secure Exchange in them).<br />
<br />
One was a &quot;parent&quot; accelerator with 3-5 path-based children<br />
<br />
One was an http (not https) accelerator.<br />
<br />
<br />
With NAM, I know I will need at least two IP for my proxies.<br />
<br />
One proxy will be for HTTP (non SSL as we had that discussion in this forum that you couldn't have one IP do both http and https).<br />
<br />
the other proxy would be for the other stuff.<br />
<br />
However, I'm not sure if I can mix proxies.<br />
<br />
The reason I had to separate them out in iChain was that I couldn't do this (have the parent contain both domain and path based)<br />
<br />
So my path based ones can only do SSL.<br />
<br />
I THINK I can do this in NAM, but not sure.</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>kjhurni</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393491-multihoming-mixing-dns-path-based.html</guid>
		</item>
		<item>
			<title>Diff branding/pages for diff. resources</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393481-diff-branding-pages-diff-resources.html</link>
			<pubDate>Fri, 20 Nov 2009 18:56:01 GMT</pubDate>
			<description>Hopefully someone can help me decide which method is the best/easiest to use: 
 
I have two IDP clusters and two LAG clusters. 
 
One set for...</description>
			<content:encoded><![CDATA[<div>Hopefully someone can help me decide which method is the best/easiest to use:<br />
<br />
I have two IDP clusters and two LAG clusters.<br />
<br />
One set for internal, one set for &quot;outside&quot; users.<br />
<br />
The &quot;outside&quot; one needs to have different branding (so that means changes to the nidp.jsp file) for two diff. proxies.<br />
<br />
One proxy gets &quot;branding1&quot; and one proxy gets &quot;branding2&quot;.  the proxy with branding2 will have many proxies on it (like one parent, many children if I were to use iChain terms).<br />
<br />
The docs on page 42 seem to indicate that if I created a custom page from the nidp.jsp file (which I'm assuming I would have to do since that's where the branding is at), that I MUST use the &quot;adding logic to the main.jsp file&quot; section.<br />
<br />
Both &quot;login pages&quot; would also have their own respective and different login.jsp file as well.<br />
<br />
But that's it.<br />
<br />
Just want to make sure that if I need to customize the branding (again that's in the nidp.jsp) that I MUST do the &quot;long/nasty&quot; portion of the login page, vs. just creating two methods and specifying the pages there.</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>kjhurni</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393481-diff-branding-pages-diff-resources.html</guid>
		</item>
		<item>
			<title>128-bit encryption for IDP - server.xml file</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393415-128-bit-encryption-idp-server-xml-file.html</link>
			<pubDate>Fri, 20 Nov 2009 16:33:19 GMT</pubDate>
			<description>The docs say to add the following line: 
 
bunch of ciphers= blah here 
 
The question is that where do you add this? 
 
Can it be anywhere in the...</description>
			<content:encoded><![CDATA[<div>The docs say to add the following line:<br />
<br />
bunch of ciphers= blah here<br />
<br />
The question is that where do you add this?<br />
<br />
Can it be anywhere in the server.xml file?<br />
<br />
At the end, the beginning, where?<br />
<br />
Right now, mine's right below the:<br />
&lt;!-- Define the Tomcat Standalone Service --&gt;<br />
<br />
line</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>kjhurni</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393415-128-bit-encryption-idp-server-xml-file.html</guid>
		</item>
		<item>
			<title>Invalid Signature on SAML artifact Request</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393413-invalid-signature-saml-artifact-request.html</link>
			<pubDate>Fri, 20 Nov 2009 16:18:32 GMT</pubDate>
			<description>Hi, 
 
I have configured my NAM 3.1.1 to protect a web server using SSL. When I try to access it I get to the login page and enter my credential....</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I have configured my NAM 3.1.1 to protect a web server using SSL. When I try to access it I get to the login page and enter my credential. According to the logs the authentication succeed on the IDS but then I get the following error :<br />
<br />
&lt;amLogEntry&gt; 2009-11-20T15:45:57Z INFO NIDS IDFF: AM#500106006: AMDEVICEID#79EE784B25D1CD3E:  Validation failure on message from <a href="https://collab-test.mymazars.com:443/nesp/idff/metadata" target="_blank">https://collab-test.mymazars.com:443/nesp/idff/metadata</a> : Digital signature is required &lt;/amLogEntry&gt;<br />
<br />
I don't get it, I've solver all the 100101043 and 100101044 errors so I thought I had the certificates right but it doesn't work. Can anyone help ?<br />
Thanks &amp; regards<br />
Pascal</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>skalpa13</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393413-invalid-signature-saml-artifact-request.html</guid>
		</item>
		<item>
			<title>Does NAM protect the web servers from vulnerabilities?</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393405-does-nam-protect-web-servers-vulnerabilities.html</link>
			<pubDate>Fri, 20 Nov 2009 15:45:21 GMT</pubDate>
			<description><![CDATA[Hello, everyone! 
 
I keep describing NAM to my customers as Ťa firewall for your web serversť. But I'm curious to know if NAM protects the web...]]></description>
			<content:encoded><![CDATA[<div>Hello, everyone!<br />
<br />
I keep describing NAM to my customers as Ťa firewall for your web serversť. But I'm curious to know if NAM protects the web servers from vulnerabilities, such as users trying to send commands to the server to try and hack it. I mean, if the Access Gateway simply hands off all commands back to the web server, wouldn't the command eventually run on the web server anyways?<br />
<br />
I'd appreciate your input on this!<br />
<br />
Thanks!<br />
<br />
Jacques</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>jsauve</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393405-does-nam-protect-web-servers-vulnerabilities.html</guid>
		</item>
		<item>
			<title>Identity Server Audit SourceIP</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393352-identity-server-audit-sourceip.html</link>
			<pubDate>Fri, 20 Nov 2009 04:13:36 GMT</pubDate>
			<description><![CDATA[Hi Guys, I noticed that auditing for Identity Server only capture server's IP in Source IP field, is there any way for me to record the client IP,...]]></description>
			<content:encoded><![CDATA[<div>Hi Guys, I noticed that auditing for Identity Server only capture server's IP in Source IP field, is there any way for me to record the client IP, says like client browser authenticate to IDS.<br />
<br />
Thanks.</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>kkyen</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393352-identity-server-audit-sourceip.html</guid>
		</item>
		<item>
			<title>Incoming HTTP Request Active for too long</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393304-incoming-http-request-active-too-long.html</link>
			<pubDate>Thu, 19 Nov 2009 17:17:12 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I am running AM 3.1.1.236. In the Identity server Health, I see the icon Yellow and it has the message "There are 2 incoming HTTP requests...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I am running AM 3.1.1.236. In the Identity server Health, I see the icon Yellow and it has the message &quot;There are 2 incoming HTTP requests that have been active for between 74997 and 75034 seconds.&quot;<br />
<br />
How do I get rid of this?<br />
<br />
-Naresh</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>nareshbk</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393304-incoming-http-request-active-too-long.html</guid>
		</item>
		<item>
			<title>openSAML</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393303-opensaml.html</link>
			<pubDate>Thu, 19 Nov 2009 17:04:11 GMT</pubDate>
			<description>My client is going to be using NAM to federate to a hosted forums vendor that uses openSAML. Since they provide guest access, they were asking if NAM...</description>
			<content:encoded><![CDATA[<div>My client is going to be using NAM to federate to a hosted forums vendor that uses openSAML. Since they provide guest access, they were asking if NAM supports the following:<br />
<br />
forceAuthentication = false<br />
isPassive = true<br />
<br />
Not really certain if this is an openSAMLism or I just can't find similar parameters in NAM or if this simply isn't supported.<br />
<br />
Thanx<br />
Rob</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>rrawson</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393303-opensaml.html</guid>
		</item>
		<item>
			<title>Multi-directory authentcationh</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393293-multi-directory-authentcationh.html</link>
			<pubDate>Thu, 19 Nov 2009 15:53:06 GMT</pubDate>
			<description>I have a client who is implementing NAM right now. We have a use case question. 
 
The large majority of users will be in an edirectory instance...</description>
			<content:encoded><![CDATA[<div>I have a client who is implementing NAM right now. We have a use case question.<br />
<br />
The large majority of users will be in an edirectory instance which has been populated by data from a database and one of two authentication directories. The data in the directory will be used for identity injection, the password will come from their current authentication directory. No problem here, straightforward.<br />
<br />
These first two directories are customers and partners. For employees, they will not permit IDM to be installed in the directory (it's controlled by a parent). So I suggested we could authenticate to their employee AD via Kerberos and get them some nice added benefit there. So far so good.<br />
<br />
The question is that they have information from the database sitting in the eDir instance, how would i configure authentication and identity injection so that I authenticate to one directory using the Kerberos authentication (or directly using that domain's creds if they are on a standalone workstation) and then look up all the data to do ID injection from the other eDir instance?</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>rrawson</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393293-multi-directory-authentcationh.html</guid>
		</item>
		<item>
			<title>user self registration - built in functionality ?</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393193-user-self-registration-built-functionality.html</link>
			<pubDate>Wed, 18 Nov 2009 20:55:15 GMT</pubDate>
			<description>Hello, 
 
it seems I cannot find enough information in the NAM documentation to answer my question.  
 
I want to put a self registration portal into...</description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
it seems I cannot find enough information in the NAM documentation to answer my question. <br />
<br />
I want to put a self registration portal into the internet where customers can register itself requesting access to a specific resource like a web page that is protected via the access manager. Once the customer has registered another internal person needs to approve the request and then access will be granted.<br />
<br />
So my question is if the access manager has such a self registration function or if I need to use a different application like the IDM user application for that.<br />
<br />
Thanks for any information,<br />
Rainer</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>brunold</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393193-user-self-registration-built-functionality.html</guid>
		</item>
		<item>
			<title>IDP Issue from the Outside</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393084-idp-issue-outside.html</link>
			<pubDate>Wed, 18 Nov 2009 02:36:10 GMT</pubDate>
			<description>Hello, everyone! 
 
Just setup an AM3.1 config at work: 1 LAG and 1 Identity Server. I am using authentication on 2 web sites; from the inside,...</description>
			<content:encoded><![CDATA[<div>Hello, everyone!<br />
<br />
Just setup an AM3.1 config at work: 1 LAG and 1 Identity Server. I am using authentication on 2 web sites; from the inside, everything works great on all workstations, including my Mac. When I try to hit one of these web sites, I get redirected to the Identity Server for authentication, and once done, on to the web server. Beautiful.<br />
<br />
From the outside, I have created 2 public IPs, with the same DNS names as internally. I have opened up ports 8080 and 8443 to the Identity Server. When I try to hit one of the web servers, I can see in my browser that I get redirected to the Identity Server. However, I never get the login page and eventually get a timeout.<br />
<br />
I had one of my colleagues try it from his Windows workstation and it works fine! WHY? My Mac with Firefox works great on the internal network, why not from the outside?<br />
<br />
Any suggestions would be greatly appreciated!<br />
<br />
Thanks!<br />
<br />
Jacques</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>jsauve</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393084-idp-issue-outside.html</guid>
		</item>
		<item>
			<title>The cluster object was not found in the configuration store.</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393062-cluster-object-not-found-configuration-store.html</link>
			<pubDate>Tue, 17 Nov 2009 21:32:00 GMT</pubDate>
			<description>Hi,  
 
I am trying to add an edirectory replica to my LDAP configuration for an identity provider in access manager.  When I try to import the...</description>
			<content:encoded><![CDATA[<div>Hi, <br />
<br />
I am trying to add an edirectory replica to my LDAP configuration for an identity provider in access manager.  When I try to import the trusted root, I get this error:<br />
<br />
The cluster object was not found in the configuration store.<br />
<br />
Any idea what this meals?  The error is from the calalina.out file on the admin server.<br />
<br />
Thanks, <br />
<br />
Jeff</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>jeynon</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393062-cluster-object-not-found-configuration-store.html</guid>
		</item>
		<item>
			<title>create web certificate for Oracle wallet</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393059-create-web-certificate-oracle-wallet.html</link>
			<pubDate>Tue, 17 Nov 2009 21:06:22 GMT</pubDate>
			<description>Hello. 
 
Does novell or can AM3 create a certificate that we could use to install to Oracle wallet? Our application cannot use the shared...</description>
			<content:encoded><![CDATA[<div>Hello.<br />
<br />
Does novell or can AM3 create a certificate that we could use to install to Oracle wallet? Our application cannot use the shared certificate and every year we have to buy the certs and install it on the server.<br />
<br />
If novell has a product that allows us to create our certificate and install it on our server via Oracle wallet, that could solve our issues.<br />
<br />
thanks</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>bctechnology</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393059-create-web-certificate-oracle-wallet.html</guid>
		</item>
		<item>
			<title>SSLVPN: Failed to start client on Opensuse</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393054-sslvpn-failed-start-client-opensuse.html</link>
			<pubDate>Tue, 17 Nov 2009 20:00:17 GMT</pubDate>
			<description>Hi, 
 
We had tot install SP4_IR4 for Access Manager 3.0 (on advice of Novell to solve a problem with roles in SSLVPN). 
Now I have a problem with...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
We had tot install SP4_IR4 for Access Manager 3.0 (on advice of Novell to solve a problem with roles in SSLVPN).<br />
Now I have a problem with SSLVPN on Opensuse.<br />
After the installation SSLVPN did not work anymore on Opensuse 11.1<br />
Error &quot;AM#1019:Failed to start client - Please logout&quot;<br />
I upgraded to Opensuse 11.2, same error.<br />
<br />
Anyone an idea how to solve this (I know that Opensuse is not supported, but it worked all the time before we installed the patch)?<br />
<br />
/usr/sbin/novl-sslvpn-service is started (novl-sslvpn-service-3.0.4-10.i586).<br />
<br />
VPN-client-log:<br />
SSL VPN Applet Logs :<br />
Tue Nov 17 20:38:32 CET 2009  SSL VPN Applet: Installed SSL VPN trust manager<br />
Tue Nov 17 20:38:33 CET 2009  SSL VPN Applet: Novell SSL VPN ConnectApplet version 3.0.4.4<br />
Tue Nov 17 20:38:33 CET 2009  SSL VPN Applet: OS Language : Nederlands (Nederland)<br />
Tue Nov 17 20:38:33 CET 2009  SSL VPN Applet: Checking Client Integrity. Please wait ...<br />
Tue Nov 17 20:38:34 CET 2009  SSL VPN Applet: Starting SSL VPN Client in Enterprise mode...<br />
Tue Nov 17 20:38:34 CET 2009  SSL VPN Applet: Unable to run specified command<br />
<br />
Messages in /var/log/messages<br />
Nov 17 20:57:35 snake NOVELL_SSLVPN_SERVICE: :Successfull command GETVERSION<br />
Nov 17 20:57:35 snake NOVELL_SSLVPN_SERVICE: SIGNATUER varification error <br />
Nov 17 20:57:35 snake NOVELL_SSLVPN_SERVICE: :Bad Binary<br />
<br />
<br />
Regards, Jeroen</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>jklaauw</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393054-sslvpn-failed-start-client-opensuse.html</guid>
		</item>
		<item>
			<title>SSO to ANGEL learning management system</title>
			<link>http://forums.novell.com/novell-product-support-forums/access-manager-3/393049-sso-angel-learning-management-system.html</link>
			<pubDate>Tue, 17 Nov 2009 19:21:41 GMT</pubDate>
			<description>Im looking for SSO options to ANGEL learning management system. 
ANGEL Learning -- Learning Management Suite for K-12 and Higher Education...</description>
			<content:encoded><![CDATA[<div>Im looking for SSO options to ANGEL learning management system.<br />
<a href="http://www.angellearning.com" target="_blank">ANGEL Learning -- Learning Management Suite for K-12 and Higher Education</a></div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/access-manager-3/">Access Manager 3</category>
			<dc:creator>jdwilbur</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/access-manager-3/393049-sso-angel-learning-management-system.html</guid>
		</item>
	</channel>
</rss>
