<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Password synchronization to Windows using LDAP? in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184102#M93264</link>
    <description>The documentation for the OpenVMS LDAP SYS$ACM Authentication Agent suggests that password synchronization between OpenVMS and Windows is possible. All of the configuration information in the dicumentation is for synchronizing with a server running Advanced Server. We would like to synchronize passwords from our OpenVMS Alpha 8.3 servers to the Windows domain. Is this is a realistic possibility now using the software and tools available? And is anyone actually doing it successfully in production?</description>
    <pubDate>Mon, 21 Apr 2008 19:58:08 GMT</pubDate>
    <dc:creator>Jim Geier_1</dc:creator>
    <dc:date>2008-04-21T19:58:08Z</dc:date>
    <item>
      <title>Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184102#M93264</link>
      <description>The documentation for the OpenVMS LDAP SYS$ACM Authentication Agent suggests that password synchronization between OpenVMS and Windows is possible. All of the configuration information in the dicumentation is for synchronizing with a server running Advanced Server. We would like to synchronize passwords from our OpenVMS Alpha 8.3 servers to the Windows domain. Is this is a realistic possibility now using the software and tools available? And is anyone actually doing it successfully in production?</description>
      <pubDate>Mon, 21 Apr 2008 19:58:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184102#M93264</guid>
      <dc:creator>Jim Geier_1</dc:creator>
      <dc:date>2008-04-21T19:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184103#M93265</link>
      <description>Hi Jim,&lt;BR /&gt;&lt;BR /&gt;Yes, it is possible.  You need to acmeldap v0200 kit.  Basically, you:&lt;BR /&gt;&lt;BR /&gt;1. Download and install the dec-axpvms-vms83a_acmeldap-v0200--4 pcsi kit&lt;BR /&gt; &lt;BR /&gt;2. Restore sys$update:acme_dev_kits.bck&lt;BR /&gt; &lt;BR /&gt;3.  Install DEC-AXPVMS-V83_ACMELDAP_STD-V0103--4.PCSI;1 and DEC-AXPVMS-V83_ACMELOGIN-V0101--4.PCSI;1&lt;BR /&gt; &lt;BR /&gt;4.  Load the Persona Extension with $ mc sysman SYS_LOADABLE ADD LDAPACME LDAPACME$EXT&lt;BR /&gt; &lt;BR /&gt;5.  Reboot&lt;BR /&gt; &lt;BR /&gt;6.  Configure the ini file (attached) &lt;BR /&gt; &lt;BR /&gt;7.  Run @sys$startup:acme$start&lt;BR /&gt; &lt;BR /&gt;8.  Confirm LDAP-STD agent is loaded - $ show server acme&lt;BR /&gt; &lt;BR /&gt;9.  Set ExtAuth flag on SYSUAF account&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 22 Apr 2008 11:11:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184103#M93265</guid>
      <dc:creator>Paul Nunez</dc:creator>
      <dc:date>2008-04-22T11:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184104#M93266</link>
      <description>Jim&lt;BR /&gt;&lt;BR /&gt;Have a look at the thread &lt;A href="http://forums12.itrc.hp.com/service/forums/questionanswer.do?admit=109447627+1206017464895+28353475&amp;amp;threadId=1197550" target="_blank"&gt;http://forums12.itrc.hp.com/service/forums/questionanswer.do?admit=109447627+1206017464895+28353475&amp;amp;threadId=1197550&lt;/A&gt;&lt;BR /&gt;for some retrictions. Especially read the entry by M. T. Hollinger (4. entry)&lt;BR /&gt;&lt;BR /&gt;Edwin</description>
      <pubDate>Tue, 22 Apr 2008 11:18:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184104#M93266</guid>
      <dc:creator>Edwin Gersbach_2</dc:creator>
      <dc:date>2008-04-22T11:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184105#M93267</link>
      <description>Configuring LDAP External Authentication:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://64.223.189.234/node/619" target="_blank"&gt;http://64.223.189.234/node/619&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Apr 2008 14:44:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184105#M93267</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2008-04-22T14:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184106#M93268</link>
      <description>Thanks for the information. On a standalone AlphaServer running OpenVMS 8.3 and patched up to Update V8, I installed the following three kits:&lt;BR /&gt;VMS83A_ACMELDAP V2&lt;BR /&gt;V83_ACMELOGIN V1.1&lt;BR /&gt;V83_ACMELDAP_STD V1.1&lt;BR /&gt;&lt;BR /&gt;I followed the release notes. I am having a problem with the &lt;BR /&gt;SYSMAN SYS_LOADABLE ADD LDAPACME LDAPACME$EXT &lt;BR /&gt;step. I see in the file SYS$UPDATE:VMS$SYSTEM_IMAGES.IDX a line indicating "SWsystem image LDAPACME$EXT load failed", and after rebooting, I see in VMS$SYSTEM_IMAGES.DATA (in the directory sys$loadable_images) a message "%SYSINIT, system image LDAPACME$EXT load failed."&lt;BR /&gt;&lt;BR /&gt;Any ideas as to how I can get the image to load and get this working? Might something in the VMS 8.3 Update V8 be incompatible with the LDAP images?</description>
      <pubDate>Thu, 08 Jan 2009 18:36:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184106#M93268</guid>
      <dc:creator>Jim Geier_1</dc:creator>
      <dc:date>2009-01-08T18:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184107#M93269</link>
      <description>The error messages may be something of a red herring. The problem with my LDAP-ACME implementation was a problem with the LOGINOUT.EXE image. When I did the PRODUCT INSTALL V83_ACMELOGIN, a message saying that LOGINOUT.EXE would not be replaced because the version already on the system was newer than the image in the kit. This is true, but the version on the system does not have the LDAP-ACME code in it. So after realizing that this was a problem, I extracted LOGINOUT.EXE from the kit, put it in SYS$COMMON:[SYSEXE], did the INSTALL REPLACE and now I have LDAP password synchronization working.&lt;BR /&gt;&lt;BR /&gt;HP OpenVMS Support knows about this problem -- it was first found on OpenVMS on Integrity. The engineering groups are working on a solution.</description>
      <pubDate>Thu, 29 Jan 2009 19:49:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184107#M93269</guid>
      <dc:creator>Jim Geier_1</dc:creator>
      <dc:date>2009-01-29T19:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184108#M93270</link>
      <description>I am addressing a similiar problem in that&lt;BR /&gt;we woule like to explore having our Alpha&lt;BR /&gt;talk to Active Directory and this would appear to be usable here as well.  I have a standalone system upgraded to VMS V8.3 with all of the current patches applied so I have the ACME_LDAP V0200 update.  Question is ... where do I find(the other two):&lt;BR /&gt;&lt;BR /&gt;VMS83A_ACMELDAP V2  ----- have it&lt;BR /&gt;V83_ACMELOGIN V1.1 ------ need it&lt;BR /&gt;V83_ACMELDAP_STD V1.1 --- need it&lt;BR /&gt;&lt;BR /&gt;I have a V8.3 distribution kit.&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;BR /&gt;</description>
      <pubDate>Fri, 30 Jan 2009 16:14:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184108#M93270</guid>
      <dc:creator>Bob Olewine</dc:creator>
      <dc:date>2009-01-30T16:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184109#M93271</link>
      <description>Unpack sys$update:acme_dev_kits.bck&lt;BR /&gt;&lt;BR /&gt;using backup and they are in there</description>
      <pubDate>Fri, 30 Jan 2009 16:34:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184109#M93271</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2009-01-30T16:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184110#M93272</link>
      <description>Thank you!  &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 30 Jan 2009 16:40:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184110#M93272</guid>
      <dc:creator>Bob Olewine</dc:creator>
      <dc:date>2009-01-30T16:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184111#M93273</link>
      <description>I had the LDAP password synchronization working, but not using SSL. Our security require that this use SSL communication. I changed the port number in the initialization file to the port number given by our Windows Server admin . Cycled the OpenVMS system, and now password synchronization is not working.&lt;BR /&gt;&lt;BR /&gt;(1) What is really involved in enabling SSL communication between the OpenVMS system snad the LDAP server? &lt;BR /&gt;&lt;BR /&gt;(2) It is difficult to see what is happening when the password synchronization is working. SHOW SERVICE/FULL ACME gives limited information. What is the best way to debug this problem?&lt;BR /&gt;&lt;BR /&gt;(3) When one makes a change in the configuration file (LDAPACME$CONFIG-STD.INI) what is required to stop and restart the service so that the changes are activated? Can one simply restart the ACME service (SET SERVER/RESTART ACME)?</description>
      <pubDate>Thu, 05 Feb 2009 19:38:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184111#M93273</guid>
      <dc:creator>Jim Geier_1</dc:creator>
      <dc:date>2009-02-05T19:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184112#M93274</link>
      <description>Best way?&lt;BR /&gt;&lt;BR /&gt;If you've followed the release notes and have selected the port and have selected the authentication and it doesn't work (and you have HP support), then ring up HP support.&lt;BR /&gt;&lt;BR /&gt;Restarting the ACME pieces should be enough here, but (if things get sufficiently tangled) I'd expect to reboot. &lt;BR /&gt;&lt;BR /&gt;There is a SET SERVER /TRACE that might be of interest.</description>
      <pubDate>Thu, 05 Feb 2009 20:47:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184112#M93274</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-02-05T20:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Password synchronization to Windows using LDAP?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184113#M93275</link>
      <description>I did get the LDAP-ACME password synchronization working using SSL. The problem was a typographical error in the initialization file. Once corrected, the ACME server was restarted (SET SERVER ACME/RESTART) and it worked right away.&lt;BR /&gt;&lt;BR /&gt;Then I moved the implementation to our 2-system test cluster. And it did not work. So I went through the documentation again and again and found a command I missed -- one MUST run the DCL script sys$update:vms$system_images.com after loading the persona extension and before rebooting.&lt;BR /&gt;&lt;BR /&gt;Generally, the people who answer the HP OpenVMS support calls know nothing or very little about the LDAP-ACME extension. The most challenging problem I encountered was one I found and solved myself -- the problem of LOGINOUT.EXE not getting installed by the V83_ACMELOGIN patch kit because other VMS 8.3 patch kits had left a version with a higher generation. The support folks then researched and told me that this is known by OpenVMS engineering and is to be solved by them "soon". Generally, the LDAP-ACME extension is not well-known, and not well supported. This is too bad, because we see it as a good solution to the continual complaint by our users/customers that there are too many passwords to remember. Synchronizing password from OpenVMS to Active Directory goes a long way towards solving that complaint and giving us happier users/customers.&lt;BR /&gt;&lt;BR /&gt;A short version of the steps, borrowed from the reply by Paul Nunez, and slightly expanded: &lt;BR /&gt;&lt;BR /&gt;1.  Download and install the dec-axpvms-vms83a_acmeldap-v0200--4 pcsi kit&lt;BR /&gt;2.  Restore sys$update:acme_dev_kits.bck&lt;BR /&gt;3.  Install the two kits from the backup saveset:&lt;BR /&gt;    DEC-AXPVMS-V83_ACMELDAP_STD-V0103--4.PCSI;1 and&lt;BR /&gt;    DEC-AXPVMS-V83_ACMELOGIN-V0101--4.PCSI;1&lt;BR /&gt;4.  Load the Persona Extension with&lt;BR /&gt;    $ mcr sysman SYS_LOADABLE ADD LDAPACME LDAPACME$EXT&lt;BR /&gt;    then&lt;BR /&gt;    $ @sys$update:vms$system_images.com&lt;BR /&gt;5.  Reboot&lt;BR /&gt;6.  Configure the initialization file, sys$startup:ldapacme$config-std.ini&lt;BR /&gt;7.  Uncomment the line in SYS$MANAGER:ACME$START.COM:&lt;BR /&gt;    $ @SYS$STARTUP:LDAPACME$STARTUP-STD.COM&lt;BR /&gt;8.  Add SET SERVER ACME/RESTART to SYSTARTUP_VMS.COM, which in turn runs            sys$startup:acme$start.com&lt;BR /&gt;9.  Confirm LDAP-STD agent is loaded using $ show server acme&lt;BR /&gt;    Should see two ACME agents, #1 name "VMS" and #2 name "LDAP-STD"&lt;BR /&gt;10. Set ExtAuth flag on SYSUAF account</description>
      <pubDate>Mon, 09 Feb 2009 05:39:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/password-synchronization-to-windows-using-ldap/m-p/4184113#M93275</guid>
      <dc:creator>Jim Geier_1</dc:creator>
      <dc:date>2009-02-09T05:39:11Z</dc:date>
    </item>
  </channel>
</rss>

