If you were unsuccessful in creating an account request workflow, you can troubleshoot the problem on the computer where Tivoli Identity Manager Express Server is installed, and also on the computer where the managed resource is installed.
For example, the following problems might occur:
- If you created an approval activity with an incorrect value for the approver, the account request might go to an unintended recipient.
- If the managed resource or the intermediate servers are not running at the time you request the account, the account request might fail.
- Request transmission requires a brief interval of time in which a request for an account goes to and returns from the Tivoli Identity Manager Express Server, the intermediate Tivoli Directory Integrator Server, and the managed resource, where an account is created. If you check for a new account too soon after your request, the account creation process might not be complete.
After taking steps to correct the problem, repeat the process to request an account. For example, restart the managed resource, and repeat your request for a test account.
To troubleshoot on the managed resource, log on to the managed resource, using the administrator user ID and password.
To troubleshoot on the Tivoli Identity Manager Express Server, logon with your administrator user ID, and complete these steps:
- View your request by taking these steps:
- In the navigation tree, click View Requests > View All My Requests.
- In the View All My Requests window, in the Requests table, examine the Status field for the status of an Account add request that has a timestamp and service instance that matches your earlier request.
If the account request failed, complete these steps:
- In the Requests table, click the request name in the Request type field.
- In the General window, a Result details or a Reason for failure field might contain a message such as CTGIMD810E The adapter returned an error status for an add request.
- Examine the Requested changes page for possible values that do not match the intended approver type.
- Locate additional information on why the adapter returned an error message. For example, there might be information in the TIVOLI_COMMON_DIRECTORY/trace.log file. There might also be information in the msg.log file.
Additionally, you might examine the ITDI_HOME/solDir/ibmdi.log file. You can also set the log4jrootCategory property in the ITDI_HOME/solDir/log4j.properties file to obtain additional information.
- Correct the error and submit the account request again.
- If this is a UNIX-based adapter and you chose to use a shadow file when you created the service, ensure that shadow utility is running on the operating system. To determine whether the utility is storing encrypted passwords, type the following at an operating system prompt:
cat /etc/shadow
You should see encrypted entries in the file.
- Test server connectivity by taking these steps:
- If you did not accept the default, which is blank, for the Tivoli Directory Integrator Server location, ensure that you entered the correct address of the Tivoli Directory Integrator Server and also for the managed resource. Test the connection. Correct the values in the address fields if you receive an error such as this message:
The following error occurred. Error: CTGRI0001E
The application could not establish a connection to
mybox.mylablab.city.company.com.
To locate this field, complete these steps:
- In the navigation tree, click Manage Services.
- In the Select a Service window, in the Services table, select the service.
- On the Service Information page, in the Tivoli® Directory Integrator location field, specify the correct address.
- Ensure that the necessary servers are running:
- Tivoli Directory Server
On Windows systems, click Start > Programs > Control Panel > Administrative Tools > Services. In the list of services, determine if the Tivoli Directory Server entry has a status of started. If not, start the service.
- WebSphere Application Server
Start the WebSphere Application Server administrative console. On a browser, enter this Web address:
http://hostname:9060/admin
The value of hostname is the fully qualified host name or the IP address of the computer on which the WebSphere Application Server is running. The value 9060 is the default port number for the WebSphere administrative HTTP transport.
Comments (0)
Post a Comment