<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACMELDAP with Active Directory in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983522#M94754</link>
    <description>Hi Thomas,&lt;BR /&gt;&lt;BR /&gt;I thought support for AD would entail more than having to compile your own schema, and that on a W$ system.&lt;BR /&gt;&lt;BR /&gt;If it helps I have attached the source schema files that come with the OpenVMS Enterprise Directory (albeit the ones delivered with the EAK). The latest one would be in one of the Enterprise Save Sets and is called ACCOUNT.SC. Hopefully you can adapt it and compile it on your W$ system. &lt;BR /&gt;&lt;BR /&gt;John</description>
    <pubDate>Fri, 20 Apr 2007 08:40:55 GMT</pubDate>
    <dc:creator>JohnDite</dc:creator>
    <dc:date>2007-04-20T08:40:55Z</dc:date>
    <item>
      <title>ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983502#M94734</link>
      <description>Since we are urged by our auditors to introduce a strict password policy in our company, we established an W2003 Active Directory Server which handles the authorization requests for most our customer logins. A lot of our users still use interactive logins on a range of OpenVMS systems, which are not synchronized with Active Directory and require different passwords. We aim to authenticate non-core users on these systems external via ACME and LDAP.&lt;BR /&gt;To check this out we installed a DS10 alpha with OpenVMS V8.3, Update V2, TCP/IP V5.6, added VMS83A_ACMELDAP-V0200 and V83_ACMELDAP_STD, and tried to establish an ACME LDAP server.&lt;BR /&gt;We created a sys$manager:ldapacme.ini, had a logical ldapacme$init pointing to it and use these commands:&lt;BR /&gt;$ def/syst/exec ldapacme$init sys$manager:ldapacme.ini&lt;BR /&gt;$ def/syst/exec ldapacme$no_tls true&lt;BR /&gt;$ set noon&lt;BR /&gt;$ set server acme /exit&lt;BR /&gt;$ dele/nolog/noconf sys$manager:acme$server.log;*&lt;BR /&gt;$ set server acme /start&lt;BR /&gt;$ set server acme /trace=10&lt;BR /&gt;$ set server acme /conf=(name=VMS)&lt;BR /&gt;$ set server acme /conf=(name=LDAP,fac=LDAPACME,cred=VMS)&lt;BR /&gt;$ set server acme /enable=name=vms&lt;BR /&gt;$ set server acme /enable=name=ldap&lt;BR /&gt;$ type sys$manager:acme$server.log;*&lt;BR /&gt;We were only partially sucessful, since we only got this:&lt;BR /&gt;ACME Agent id: 2  State: Initialized&lt;BR /&gt;   Name: "LDAP"&lt;BR /&gt;   Image: "DISK$SYSFEP:[VMS$COMMON.SYSLIB]LDAPACME$LDAP_ACMESHR.EXE;1"&lt;BR /&gt;   Identification: "LDAPACME Agent V1.0-BL2"&lt;BR /&gt;   Information: "ldap_agent initialized, waiting to be enabled"&lt;BR /&gt;   Domain of Interpretation: Yes&lt;BR /&gt;   Execution Order:      0&lt;BR /&gt;The log file contains lines like&lt;BR /&gt;%ACME-I-TRACE, trace event from "ACME_ReadControlMBX: Enable received" on 18-AP?&lt;BR /&gt;-ACME-I-THREAD, thread: id = 1, type = CONTROL&lt;BR /&gt;%ACME-I-TRACE, trace event from "ACME_EnableServer: ERROR" on 18-APR-2007 07:18?&lt;BR /&gt;-ACME-I-THREAD, thread: id = 1, type = CONTROL&lt;BR /&gt;-ACME-I-EXITSTATUS, exiting with status = %X074ABEB2&lt;BR /&gt;&lt;BR /&gt;Has somebody an idea what's possibly wrong?</description>
      <pubDate>Wed, 18 Apr 2007 00:36:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983502#M94734</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-18T00:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983503#M94735</link>
      <description>Thomas,&lt;BR /&gt;  According to the status:&lt;BR /&gt;&lt;BR /&gt;$ exit  %X074ABEB2&lt;BR /&gt;%ACME-E-INCOMPATSTATE, server state is incompatible with requested operation&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Note that the /TRACE value is a bitmask. Value 10 will trace "general" and "ast" operations only. You may wish to enable more things. To enable everything use /TRACE=2047 (to make things clearer when dealing with bitmasks, it might be better to use hex /TRACE=%X7FF) &lt;BR /&gt;</description>
      <pubDate>Wed, 18 Apr 2007 02:01:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983503#M94735</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2007-04-18T02:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983504#M94736</link>
      <description>Thanks for that hint, but I am still not wiser! I included the new log file generated with /TRACE=%x7FF - perhaps there is someon who can see what's wrong.</description>
      <pubDate>Wed, 18 Apr 2007 02:40:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983504#M94736</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-18T02:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983505#M94737</link>
      <description>Thomas,&lt;BR /&gt;  You have a different status:&lt;BR /&gt;&lt;BR /&gt;-ACME-I-GETCLIENTF, client message acquisition failure, status = %X074AD83A&lt;BR /&gt;&lt;BR /&gt;$ exit %X074AD83A&lt;BR /&gt;%ACME-E-NOMSGFND, no acceptable message found&lt;BR /&gt;&lt;BR /&gt;Anything in the log files from the directory server?</description>
      <pubDate>Wed, 18 Apr 2007 03:31:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983505#M94737</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2007-04-18T03:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983506#M94738</link>
      <description>I've got a TCPTRACE running which shows absolutely nothing. The server seems not to be ready to try to connect yet.</description>
      <pubDate>Wed, 18 Apr 2007 03:47:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983506#M94738</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-18T03:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983507#M94739</link>
      <description>I assume you are planning the LDAP server available on OpenVMS. If not, how are you planning to define the required schema on the  external LDAP server?&lt;BR /&gt;&lt;BR /&gt;Have you started/configured the OpenVMS LDAP/Directory Server?&lt;BR /&gt;&lt;BR /&gt;If you check for the DXD$DSA_SERVER process then that will tell you that an attempt was made to start the Directory server.&lt;BR /&gt;&lt;BR /&gt;If you have DECnet+ installed the following NCL command will show you the status:&lt;BR /&gt;&lt;BR /&gt;$MC NCL SHOW DSA ALL STATUS&lt;BR /&gt;&lt;BR /&gt;Then see if the LDAP Port has been set:&lt;BR /&gt;&lt;BR /&gt;$MC NCL SHOW DSA LDAP PORT&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 18 Apr 2007 05:57:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983507#M94739</guid>
      <dc:creator>john Dite</dc:creator>
      <dc:date>2007-04-18T05:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983508#M94740</link>
      <description>The external Server is an existing MS Windows 2003 Server. The current problem is how to start the ACME LDAP server, connecting and questioning the external LDAP server will be the next one...</description>
      <pubDate>Wed, 18 Apr 2007 06:00:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983508#M94740</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-18T06:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983509#M94741</link>
      <description>Thomas&lt;BR /&gt;&lt;BR /&gt;can you show us the contents of your sys$manager:ldapacme.ini file.</description>
      <pubDate>Wed, 18 Apr 2007 08:25:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983509#M94741</guid>
      <dc:creator>john Dite</dc:creator>
      <dc:date>2007-04-18T08:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983510#M94742</link>
      <description>Thomas,&lt;BR /&gt;&lt;BR /&gt;the existing ACME LDAP Server is based on the OpenVMS Enterprise Directory V5.5+ (?). You will have to install this kit and then depending whether you have DECnet installed or not use either a JAVA or the NCL utility to initally set up the directory.  &lt;BR /&gt;&lt;BR /&gt;I'm sure this is all described in the accompanying documentation.&lt;BR /&gt;&lt;BR /&gt;As I have said before, if you're planning to use an external LDAP server you'll have to find a way to integrate the ACME schema files on the remote LDAP server.</description>
      <pubDate>Wed, 18 Apr 2007 08:43:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983510#M94742</guid>
      <dc:creator>john Dite</dc:creator>
      <dc:date>2007-04-18T08:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983511#M94743</link>
      <description>You might want to consider Process Software's VAM product.  &lt;A href="http://www.process.com/VMSauth/index.html" target="_blank"&gt;http://www.process.com/VMSauth/index.html&lt;/A&gt;&lt;BR /&gt;It has the necessary glue between loginout and Active Directory.</description>
      <pubDate>Wed, 18 Apr 2007 09:52:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983511#M94743</guid>
      <dc:creator>Richard Whalen</dc:creator>
      <dc:date>2007-04-18T09:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983512#M94744</link>
      <description>sorry Thomas, I can't help, but I did want to question the assertion from John Dite that you need to use an OpenVMS LDAP server.&lt;BR /&gt;&lt;BR /&gt;That was certainly what I understood to be true, but in the recently released VMS83A_ACMELDAP-V0200 kit (which Thomas has installed), it says....&lt;BR /&gt;&lt;BR /&gt; 5.1  New functionality addressed in this kit&lt;BR /&gt;&lt;BR /&gt;          5.1.1  Add Active Directory Support&lt;BR /&gt;&lt;BR /&gt;               5.1.1.1  Functionality Description:&lt;BR /&gt;&lt;BR /&gt;               This ACMELDAP kit adds Active Directory support to the&lt;BR /&gt;               LDAP ACME agent so users can&lt;BR /&gt;&lt;BR /&gt;               1.  Login to VMS using their Active Directory usernanme&lt;BR /&gt;                   and password&lt;BR /&gt;&lt;BR /&gt;               2.  Change their Active Directory password from VMS&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;So I read from this that you could now get external authentication working against AD.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;chris</description>
      <pubDate>Wed, 18 Apr 2007 23:43:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983512#M94744</guid>
      <dc:creator>Chris Barratt</dc:creator>
      <dc:date>2007-04-18T23:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983513#M94745</link>
      <description>First, thanks to all who engaged themselves in this case!&lt;BR /&gt;I appended the contents of my LDAPACME.INI file. The bind_dn value is based on what AD says about my account: "pclan.iplan.dklb.de/DKLB-BUSINESS-UNITS&lt;BR /&gt;/DKLB-SYS/DKLB-SYSMGMT/PAULI"&lt;BR /&gt;But as far as I know ACMELDAP does not even try to connect to the AD server, since I have TCPTRACE running. The only things I see there are the broadcasts of the AD server itself.</description>
      <pubDate>Thu, 19 Apr 2007 00:17:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983513#M94745</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-19T00:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983514#M94746</link>
      <description>Hi Thomas,&lt;BR /&gt;&lt;BR /&gt;I stand to be corrected as far as the Active Directory support is concerned. I tested ACME this withe the EAK version so my experiences are based on using the OpenVMS Enterprise Directory. &lt;BR /&gt;&lt;BR /&gt;Now I don't know whether you want to initially go down that route to see whether ACME works with the 'local' LDAP server before trying to connect it to AD.&lt;BR /&gt;&lt;BR /&gt;We can assume that dkexcv1.iplan.dklb.de resolves to an IP Address?&lt;BR /&gt;&lt;BR /&gt;John</description>
      <pubDate>Thu, 19 Apr 2007 03:39:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983514#M94746</guid>
      <dc:creator>JohnDite</dc:creator>
      <dc:date>2007-04-19T03:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983515#M94747</link>
      <description>John,&lt;BR /&gt;&lt;BR /&gt;no, we don't want to establish a VMS LDAP server, we've got the MS one running and want to use it.&lt;BR /&gt;The dkexcv1 name does translate, I checked it with a ping (TCPIP PING dkexcv1).</description>
      <pubDate>Thu, 19 Apr 2007 03:54:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983515#M94747</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-19T03:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983516#M94748</link>
      <description>Thomas,&lt;BR /&gt;&lt;BR /&gt;I don't have an V8.3 System but don't you have a LDAPACME$STARTUP.COM startup file, that is possibly in your SYSTARTUP_VMS.COM file?&lt;BR /&gt;&lt;BR /&gt;If I start the ACME Server using the commands as you have listed then I get the same error.&lt;BR /&gt;&lt;BR /&gt;You did:&lt;BR /&gt;$ set server acme /enable=name=vms&lt;BR /&gt;$ set server acme /enable=name=ldap&lt;BR /&gt;&lt;BR /&gt;However if I follow the documentation "hp OpenVMS LDAP SYS$ACM Authentication Agent Guide 2003" and use&lt;BR /&gt;$ set server acme/enable=name=(ldap,vms)&lt;BR /&gt;&lt;BR /&gt;then I get it to start (see attachment)&lt;BR /&gt;&lt;BR /&gt;John</description>
      <pubDate>Thu, 19 Apr 2007 09:39:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983516#M94748</guid>
      <dc:creator>JohnDite</dc:creator>
      <dc:date>2007-04-19T09:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983517#M94749</link>
      <description>John,&lt;BR /&gt;&lt;BR /&gt;incredible - that did the trick! Now I got both servers up and active!&lt;BR /&gt;&lt;BR /&gt;Thanks the lot!</description>
      <pubDate>Fri, 20 Apr 2007 00:40:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983517#M94749</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-20T00:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983518#M94750</link>
      <description>Thomas,&lt;BR /&gt;&lt;BR /&gt;glad to hear that the ACME server is now running. I would be interested to hear of your results when using the AD for OpenVMS user authentication.&lt;BR /&gt;&lt;BR /&gt;For all followers of the AD may I point you to an interesting article:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cs.kent.ac.uk/pubs/2000/2115/content.pdf" target="_blank"&gt;http://www.cs.kent.ac.uk/pubs/2000/2115/content.pdf&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;John</description>
      <pubDate>Fri, 20 Apr 2007 02:39:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983518#M94750</guid>
      <dc:creator>JohnDite</dc:creator>
      <dc:date>2007-04-20T02:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983519#M94751</link>
      <description>John,&lt;BR /&gt;&lt;BR /&gt;thanks for all the help. Next thing is to modify the AD schema to satisfy ACME requests.&lt;BR /&gt;I will keep the thread open to provide informations about our progress.</description>
      <pubDate>Fri, 20 Apr 2007 03:25:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983519#M94751</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-20T03:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983520#M94752</link>
      <description>Hi Thomas,&lt;BR /&gt;&lt;BR /&gt;if ACME claims to have added &lt;BR /&gt;"Active Directory Support" does the documentation tell you explicitly that you have  to adapt the AD schema or is there some other flag that indicates to the ACME LDAP Agent that you are doing a lookup on an AD? &lt;BR /&gt;&lt;BR /&gt;John</description>
      <pubDate>Fri, 20 Apr 2007 06:26:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983520#M94752</guid>
      <dc:creator>JohnDite</dc:creator>
      <dc:date>2007-04-20T06:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: ACMELDAP with Active Directory</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983521#M94753</link>
      <description>Hi John,&lt;BR /&gt;&lt;BR /&gt;sadly there is no such flag! We are now facing the task to facilitate changes to our AD scheme so it will work with ACME. The documentation we managed to extract from all possible sources is not too instructive, so we will have to set up a test AD server to find everything out.&lt;BR /&gt;This will take it's time, but we think it's worth it!</description>
      <pubDate>Fri, 20 Apr 2007 06:30:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/acmeldap-with-active-directory/m-p/3983521#M94753</guid>
      <dc:creator>Thomas Pauli</dc:creator>
      <dc:date>2007-04-20T06:30:33Z</dc:date>
    </item>
  </channel>
</rss>

