<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>www.cubetoon.com - wading through social software technology &#187; Websphere Application Server</title>
	<atom:link href="http://www.cubetoon.com/category/websphere-application-server/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cubetoon.com</link>
	<description>wading through social software technology</description>
	<lastBuildDate>Thu, 02 Feb 2012 20:33:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc/3.0/</creativeCommons:license>		<item>
		<title>Sametime 8.5.x LDAP: Domino vs. Active Directory</title>
		<link>http://www.cubetoon.com/2011/sametime-8-5-x-ldap-domino-vs-active-directory/</link>
		<comments>http://www.cubetoon.com/2011/sametime-8-5-x-ldap-domino-vs-active-directory/#comments</comments>
		<pubDate>Mon, 16 May 2011 08:49:53 +0000</pubDate>
		<dc:creator>cubetoon</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Lotus Sametime]]></category>
		<category><![CDATA[Websphere Application Server]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Lotus Domino]]></category>
		<category><![CDATA[Sametime]]></category>
		<category><![CDATA[SPNEGO]]></category>
		<category><![CDATA[SSO]]></category>
		<category><![CDATA[WAS 7.0]]></category>
		<category><![CDATA[Websphere]]></category>

		<guid isPermaLink="false">http://www.cubetoon.com/?p=397</guid>
		<description><![CDATA[While I was working on the upgrade of our existing Sametime environment to Sametime 8.5.1 (soon 8.5.2) I have run across an interesting question that I considered worth sharing: Will I use Domino LDAP or connect to Active Directory. There are good and not so good reasons for either option: To get the discussion started there seems [...]]]></description>
			<content:encoded><![CDATA[<p>While I was working on the upgrade of our existing Sametime environment to Sametime 8.5.1 (soon 8.5.2) I have run across an interesting question that I considered worth sharing: Will I use Domino LDAP or connect to Active Directory.</p>
<p>There are good and not so good reasons for either option:<span id="more-397"></span></p>
<ul>
<li>To get the discussion started there seems to be the obvious choice to keep on  using the Domino Directory when switching to LDAP. This way users can  work in their familiar directory structure without the need to impose the rather technical structure of (our) AD.</li>
<li>On the other hand it appears to be quite reasonable to also implement <a title="Integrating SPNEGO with IBM Lotus Sametime components using IBM WebSphere Application Server 7.0" href="http://www.ibm.com/developerworks/lotus/documentation/spnegowithsametime/" target="_blank">SPNEGO</a>.  This however requires the use of Active Directory as a LDAP source.</li>
<li>On the flip-side there is the obvious issue of the non-hierarchic structure of the Domino groups. Combine this with the requirement to have a base entry for LDAP defined as <a title="More Lessons From Sametime 8.5 Deployments And One Big Old BUG" href="http://www.turtleweb.com/turtleblog.nsf/dx/18022010215742GDATVS.htm?opendocument" target="_blank">mentioned</a> by Gabriella Davis and you are left with yet another point for consideration. Especially if you are reluctant to make existing groups in the Domino Directory hierarchic &#8211; who is doing that anyhow?</li>
</ul>
<p>I am wondering how other environments have designed their solution. Did you really append an organisation to the name of groups just to make them available in an LDAP tree?<br />
How did you maintain group entries in the vpuserinfo.nsf when moving between directories? Person entries are easily managed utilising the name change task but groups are rarely replicated between directories, hence the benefit of previously added public groups to the contact list is just gone.<br />
Is there any way to use Domino as a LDAP source but still provide SSO in a Windows environment? I am wondering whether there is the possibility to have the  Websphere server connecting to two directories, one for authentication,  the other one for online awareness. Similar to the portal configuration  described <a title="Configuring SSO if Lotus Sametime authenticates with Domino LDAP" href="http://publib.boulder.ibm.com/infocenter/wpzosdoc/v6r1/index.jsp?topic=/com.ibm.wp.zos.doc_v615/collab/cfg_st_sso_domldap.html" target="_blank">here</a>. Or maybe utilising a Domino server for authentication with shared LTPA keys between Websphere and Domino?</p>
<p>I am sorry for everyone who expected any answers to their own questions in here. Do not hesitate though to leave a comment if you are having a suggestion for any of the questions raised in here or below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cubetoon.com/2011/sametime-8-5-x-ldap-domino-vs-active-directory/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DB2 error message on Windows 2008</title>
		<link>http://www.cubetoon.com/2011/db2-error-message-on-windows-2008/</link>
		<comments>http://www.cubetoon.com/2011/db2-error-message-on-windows-2008/#comments</comments>
		<pubDate>Mon, 21 Feb 2011 23:04:54 +0000</pubDate>
		<dc:creator>cubetoon</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[DB2]]></category>
		<category><![CDATA[Lotus Connections]]></category>
		<category><![CDATA[Lotus Sametime]]></category>
		<category><![CDATA[Websphere Application Server]]></category>
		<category><![CDATA[Error]]></category>
		<category><![CDATA[Sametime]]></category>

		<guid isPermaLink="false">http://www.cubetoon.com/?p=384</guid>
		<description><![CDATA[Just a quick note interesting for DB2 installations on Windows 2008 Server or Windows 7 workstations. If you are receiving an error &#8220;SQL5005C System Error&#8221; immediately after the launch of the operating system you have most likely missed to add your current user ID to the DB2Admin group on the local machine.]]></description>
			<content:encoded><![CDATA[<p>Just a quick note interesting for DB2 installations on Windows 2008 Server or Windows 7 workstations.</p>
<p>If you are receiving an error &#8220;SQL5005C System Error&#8221; immediately after the launch of the operating system you have most likely missed to add your current user ID to the DB2Admin group on the local machine.</p>
<div id="attachment_385" class="wp-caption alignnone" style="width: 228px"><a href="http://www.cubetoon.com/wp-content/uploads/2011/02/DB2Admin.jpg"><img class="size-full wp-image-385" title="DB2 UDB Error" src="http://www.cubetoon.com/wp-content/uploads/2011/02/DB2Admin.jpg" alt="SQL5005C System Error" width="218" height="142" /></a><p class="wp-caption-text">SQL5005C System Error</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.cubetoon.com/2011/db2-error-message-on-windows-2008/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Transferring the single server SSL certificate to ND Gateway installation</title>
		<link>http://www.cubetoon.com/2010/transferring-the-single-server-ssl-certificate-to-nd-gateway-installation/</link>
		<comments>http://www.cubetoon.com/2010/transferring-the-single-server-ssl-certificate-to-nd-gateway-installation/#comments</comments>
		<pubDate>Fri, 08 Oct 2010 01:52:23 +0000</pubDate>
		<dc:creator>cubetoon</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Lotus Sametime]]></category>
		<category><![CDATA[Websphere Application Server]]></category>
		<category><![CDATA[Sametime Gateway]]></category>
		<category><![CDATA[WAS]]></category>

		<guid isPermaLink="false">http://www.cubetoon.com/?p=372</guid>
		<description><![CDATA[This post is in response to a question asked on my previous post by Gili Nachum. When re-installing the Sametime Gateway to convert it from a Single Server to a Network Deployment you are obviously faced with the task to re-configure the system, which definitely includes the SSL configuration. There might possibly be a way [...]]]></description>
			<content:encoded><![CDATA[<p>This post is in response to a question asked on my <a href="http://www.cubetoon.com/2010/unable-to-re-install-sametime-gateway/" target="_blank">previous post</a> by <a title="Java Tuning" href="http://javatuning.com/" target="_blank">Gili Nachum</a>.</p>
<p>When re-installing the Sametime Gateway to convert it from a Single Server to a Network Deployment you are obviously faced with the task to re-configure the system, which definitely includes the SSL configuration. There might possibly be a way to transfer most of the configuration using Websphere scripts. In absence of any experience in this area I am going to describe the manual steps here.</p>
<p><strong>Very important</strong>: create a backup of your Websphere directory before removing the old installation of the Gateway. I am assuming here that you have followed <a title="Setting up SSL on a single server" href="http://publib.boulder.ibm.com/infocenter/sametime/v8r5/topic/com.ibm.help.sametime.v851.doc/config/config_gw_ssl_setup.html" target="_blank">IBM&#8217;s instructions</a>for the SSL setup of the single server and didn&#8217;t create a custom keystore. In this case you&#8217;ll find a key.p12 file within the profile config, which is the NodeDefaultKeyStore and a trust.p12 file, reflecting the NodeDefaultTrustStore.</p>
<p>On setting up the new Sametime Gateway server using network deployment you will be <a title="Creating a new keystore" href="http://publib.boulder.ibm.com/infocenter/sametime/v8r5/topic/com.ibm.help.sametime.v851.doc/config/config_gw_ssl_create_keystore.html" target="_blank">creating</a> a new key store. Instead of <a title="Creating a certificate request" href="http://publib.boulder.ibm.com/infocenter/sametime/v8r5/topic/com.ibm.help.sametime.v851.doc/config/config_gw_ssl_request_cert_clus.html" target="_blank">creating a certificate request</a> though you are going to import the existing certificate.</p>
<ol>
<li>Select Personal Certificates under Additional properties and choose Import.</li>
<li>Choose Key store file and type the path to you key.p12 file.</li>
<li>Leave Type set to PKCS12.</li>
<li>Enter the Key file password. The default key store password, if you haven&#8217;t changed it, is WebAS .</li>
<li>Hit the &#8216;Get Key File Aliases&#8217; button and select the alias to import in the drop down below.</li>
<li>Define the alias name for the import and hit okay.</li>
</ol>
<p>Repeat above steps for all trust certificates using the trust.p12 file of the old installation and the CellDefaultTrustStore of the new installation. You can now continue with the SSL configuration for the <a title="Defining the SSL configuration for a cluster" href="http://publib.boulder.ibm.com/infocenter/sametime/v8r5/topic/com.ibm.help.sametime.v851.doc/config/config_gw_ssl_define_ssl_clus.html" target="_blank">cluster</a>, the <a title="Configuring the SIP proxy server to use SSL" href="http://publib.boulder.ibm.com/infocenter/sametime/v8r5/topic/com.ibm.help.sametime.v851.doc/config/config_gw_ssl_sip_proxy_clus.html" target="_blank">SIP</a> and <a title="Configuring the XMPP proxy server to use SSL" href="http://publib.boulder.ibm.com/infocenter/sametime/v8r5/topic/com.ibm.help.sametime.v851.doc/config/config_gw_ssl_xmpp_proxy_clus.html" target="_blank">XMPP</a> proxy.</p>
<p>As a side note to above: it is strongly recommended to change the password for your DefaultKeyStores. Otherwise an attacker might possibly be able to steal and misuse your identity.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cubetoon.com/2010/transferring-the-single-server-ssl-certificate-to-nd-gateway-installation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Automatically launch Websphere node agent and application server</title>
		<link>http://www.cubetoon.com/2010/automatically-launch-websphere-node-agent-and-application-server/</link>
		<comments>http://www.cubetoon.com/2010/automatically-launch-websphere-node-agent-and-application-server/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 20:06:34 +0000</pubDate>
		<dc:creator>cubetoon</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Lotus Connections]]></category>
		<category><![CDATA[Websphere Application Server]]></category>
		<category><![CDATA[WAS 6.1]]></category>

		<guid isPermaLink="false">http://www.cubetoon.com/?p=317</guid>
		<description><![CDATA[WASServiceCMD.exe &#8211; Nice command line tool to register Websphere servers as a Windows service Adam Brown &#8211; Starting up Lotus Connections automatically Thanks for sharing!]]></description>
			<content:encoded><![CDATA[<p><a href="http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg21397335" target="_blank">WASServiceCMD.exe</a> &#8211; Nice command line tool to register Websphere servers as a Windows service</p>
<p><a href="http://www.isw.com.au/domino/isw/brownblog.nsf/d6plinks/ABRN-7WD66P" target="_blank">Adam Brown</a> &#8211; Starting up Lotus Connections automatically</p>
<p>Thanks for sharing!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cubetoon.com/2010/automatically-launch-websphere-node-agent-and-application-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

