3
Create Administration User Use To administrate and monitor the ICM from a browser, you need an administration user. You can create this user with the program icmon. To do so, proceed as follows. You can do the same in the Web dispatcher with the program wdispmon. This is however usually not necessary, since when the dispatcher is started with Bootstrap Option an administration user is automatically created. Procedure 1. As user <sid>adm go to the directory where the executables are kept and call up icmon -a pf=<instance profile> . The following appears: Maintain authentication file ============================ File name (icmauth.txt): . 2. If you are happy with the default file name, press the enter key, otherwise enter a different file name or path. 3. In the next menu choose a (add user to set). 4. Enter the user name, then the password twice, the group name, the subject of the X.509 certificate (wildcards allowed, and it can be left empty). User Name: icmadm Enter Password: ***** Re-enter Password: ***** Group name: admin Subject Value of Client Cert: CN=template,* new entry locally created

Create Administration User for ICM

Embed Size (px)

DESCRIPTION

Create Administration User for ICM

Citation preview

Create Administration UserUseTo administrate and monitor the ICM from a browser, you need an administration user.You can create this user with the programicmon.To do so, proceed as follows.

You can do the same in the Web dispatcher with the programwdispmon.This is however usually not necessary, since when the dispatcher is started withBootstrap Optionan administration user is automatically created.Procedure1.As useradmgo to the directory where the executables are kept and call upicmonapf=.The following appears:Maintain authentication file============================File name (icmauth.txt):.2.If you are happy with the default file name, press the enter key, otherwise enter a different file name or path.3.In the next menu choosea(add user to set).4.Enter the user name, then the password twice, the group name, the subject of the X.509 certificate (wildcards allowed, and it can be left empty).

User Name:icmadmEnter Password:*****Re-enter Password:*****Group name:adminSubject Value of Client Cert:CN=template,*new entry locally created

The user created is in groupadmin, the user is therefore an administration user without administration authorization.In particular this user can create further users in the Web admin interface.

If you select another group name other thanadmin, create a monitoring user that can monitor, but not administrate, the ICM/Web Dispatcher.If you want a user to be able to log on only with the X.509 client certificate, you can enter an x as the password (with queries), which makes the following entry (in the example) in file:icmadm:x:admin:CN=muster,*5.Chooses(save changes of set to file), to copy your changes from the local buffer to the authorization file.6.Chooseq, to quit the program.

You can display the users in the menu by choosing(list users of set), though you will only see the users in the local buffer.To view the users copied to the file, look in the file or call upicmonaagain.ResultYou have created a user with which you can use theWeb Administration Interface.