Symantec Access Management

 View Only
  • 1.  Unable to create Policy store for siteminder

    Posted Dec 03, 2019 03:26 AM

    Hi ,

     

    I am trying to install siteminder.

     

    Version : 12.52

    Windows server : 2008

    Java version : 1.7.0_45 32 bit

     

    • I was able to install policy server. It is up and running.
    • I am trying to create policy store from wizard C:\Program Files (x86)\CA\siteminder\install_config_info\ ca-ps-config.exe

    Test LDAP Connection is working fine.

     

    But I am getting below error under ca-ps-details.log while executing smldapsetup lmod command.

     

    COMMAND: "C:\Program Files (x86)\CA\siteminder\bin\smldapsetup" ldgen -fsmldap.ldif

    RETURN: 0

    STDOUT: --------------- Verifying LDAP settings ---------------

    STDERR:

    ***

    ***

    COMMAND: "C:\Program Files (x86)\CA\siteminder\bin\smldapsetup" ldmod -fsmldap.ldif

    RETURN: 64

    STDOUT: --------------- Verifying LDAP settings ---------------

     

     

     

    LDAPError: 64. LDAP error 64. Naming violation

    Unable to create policy store branch under root DN

    STDERR:

    ***

    ***

    COMMAND: "C:\Users\sysadmin\AppData\Local\Temp\2\454328.tmp\smreg"  -su ******

    RETURN: -1

    STDOUT: The super user could not be saved in the policy store.

    Failed to create the super user account.

    STDERR:

     

    Please help.

     

    Thanks,

    Ketaki

     



  • 2.  RE: Unable to create Policy store for siteminder
    Best Answer

    Broadcom Employee
    Posted Dec 03, 2019 04:29 PM
    Ketaki,  Every Policy Server installer comes with a 'smreg.exe' file. This file needs to be copied over to the <siteminder_home>\bin folder before running the "smreg –su password" command.  First, please make sure the smreg.exe in your environment is from the corresponding Policy Server installation zip.

    Also, 
    FYI, if you're not aware, R12.52 PS is EOS, but we can still answer here.

    One suggestion: Try "smreg -tu <password>" and you'll get more detail in the smtrace, which is sometimes helpful in troubleshooting.
    Thanks.


  • 3.  RE: Unable to create Policy store for siteminder

    Posted Dec 03, 2019 11:41 PM

    Hi Vijay,

     

    I have copied smreg.exe to <siteminder_home>\bin folder and then ran smreg -su <password>.

     

    It is giving below error :

     

     

    My question is while creating policy store I am getting below error :

    C:\Program Files (x86)\CA\siteminder\bin>smldapsetup ldmod -fsmldap.ldif

    --------------- Verifying LDAP settings --------------- 

    LDAPError: 64. LDAP error 64. Naming violation

    Unable to create policy store branch under root DN

     

    Is it something to do with permissions for the AD user with which I am trying to create policy store. The AD user that I am using is already part of Administrators group. Do I need to give some extra privileges or change any configurations to this AD user?

     

     

    Thanks,

    Ketaki