If you are unable to create a new account, please email support@bspsoftware.com

 

News:

MetaManager - Administrative Tools for IBM Cognos
Pricing starting at $2,100
Download Now    Learn More

Main Menu

LDAP and NT Namespaces ..

Started by NaviGator, 28 Apr 2009 04:50:33 AM

Previous topic - Next topic

NaviGator

Hello guys,

I have managed to configure the LDAP with Cognos to be used as our authentication provider. I can access the environment using the users defined in the LDAP. My problem is that all these users have the same rights. When I open the Administration page and go to the Security tab. I found that The LDAP entry already exists but just as an entry name not as a link so I can't open it and check the users or groups defined in the LDAP.

Before the LDAP I used the local NT as my authentication provider. I can open this entry and check the users and give the required permissions to each user but I can't do the same with LDAP. Even when I open the Cognos Namespace and then try to assign the users to the predefined roles, I can access only the NT users but not the LDAP.  ???

Do you know what is the problem? Do I have anything missing in the LDAP configuration ?

Thanks ,,
Never Stop Learning ..

sasdev

Try this: After logging into congnos connection, click the login option again and try logging into the additional LDAP namespace. You can be logged into dual namespaces at the same time. As long as you are part of the domain that hosts the Active Directory you should have Read rights to it so long as you are connected to it. In order to give people different access you can either ask the network admins to create a new group within AD and have them add certain people to it, or you can create a Cognos group and add users to it. If you have the newworking staff do it then they will maintain the users when turnover occurs, otherwise you will need to maintain the groups if added to a newly created cognos group. Hope this helps.

NaviGator

Thank you Traci, but I really don't understand why do I need to login again using the LDAP ?

As I mentioned in my post, when I open the Administration page and then go to the security tab. I can find the Cognos namespace that contains the predefined roles and the Local NT namespace as links. when you click on the Local NT for example you can find all the groups and users defined on the Local NT. This is the not the case for the LDAP namespace. The LDAP doesn't appear as a link so you can not open it and browse the users and groups like the Local NT namespace.

I would like to do this ? Any ideas ?

Thanks again ..
Never Stop Learning ..

sasdev

I had a similar issue as well when authenticating against two namespaces. When you first sign into cognos does it give you an option of which namespace to sign on to? If so, if you are signing on using  Local NT, then after sign-on go to the cognos administration and then click security. You should see all of your namespaces. Then, in the upper right of the cognos browser you should see something that says 'Log In' again...or something to that effect. This is allowing you to log into an additional namespace without having to sign-out first. Then you should be able to view the LDAP namespace users\groups within Cognos. This was my own experience however, maybe yours is different.

sasdev

As I said previously, you need to sign on to the LDAP via Cognos connection in order to view it's contents.