cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Showing results for 
Search instead for 
Did you mean: 

Community Tip - Did you get called away in the middle of writing a post? Don't worry you can find your unfinished post later in the Drafts section of your profile page. X

Directory server is mandatory to install in WC installation.?

PM_11017169
4-Participant

Directory server is mandatory to install in WC installation.?

I am new with windchill set up and just trying to figure it out few queries/confusions. If I get any expert opinion will be great relief /help.

 

Monolithic Installation-

 

1.Is directory server mandatory to install for any version of WC installation?

2.If answer to above question is yes then What are the LDAP settings ( I not able to get clarity form document)? I mean should be keep the same populated values or change it? 

3.If answer to question 1 is NO then what can be used?

4.We have our company LDAP server set up , we can use that? if yes can some give quick values or any configuration related info for it? 

5.If i have installed Directory server and want to use the LDA sever of company is it possible to connect? If yes can someone shares any basic steps involved.

6.It would be great if someone gives me approach for installation ..Just for example...

Step1 install DS

step 2 - install x

Step 3-- install y

.

. so on.

 

I would like to know what's the best approach to be followed. 

 

Cluster set up-

1.What's the step wise approach to this?

2.Any steps instructions followed /link to read out?

3. can we use same LDAP server for the cluster setup?

4.What's it he differences in Master nodes installation and slave node installation? 

 

My question might be very basic/ordinary, but it would be always having pleasure to get expert opinions.

1 ACCEPTED SOLUTION

Accepted Solutions

On the monolithic install:

Monolithic Installation-

 

1.Is directory server mandatory to install for any version of WC installation?

  • Not generally after 12.0.2 (I can't remember the specific CPS build). 

2.If answer to above question is yes then What are the LDAP settings ( I not able to get clarity form document)? I mean should be keep the same populated values or change it? 

  • N/A

3.If answer to question 1 is NO then what can be used?

  • Any LDAP v3 Data store
  • Note: LDAP isn't just used for authentication, there is also a back end infoengine connection to look up AD group membership, get additional attributes about users etc. So even if you do some sort of SAML authentication, LDAP will still be required.

4.We have our company LDAP server set up , we can use that? if yes can some give quick values or any configuration related info for it? 

  • No special settings, however if your LDAP is using LDAPs you will need the certificate for the domain controllers / ldap servers in the java keystore on Windchill before starting the installer
  • If your LDAP doesn't allow anonymous binding, you will need the full CN of an admin user that will be the site admin. I would recommend this be a generic account like a service account and not a user account (admin user can be changed later with some xconfmanager commands).
    • ex: cn=MyAdminUser,ou=myorg,dc=mycompany,dc=com
  • Additionally you could define a group or OU to use to filter members

5.If i have installed Directory server and want to use the LDA sever of company is it possible to connect? If yes can someone shares any basic steps involved.

6.It would be great if someone gives me approach for installation ..Just for example...

Step1 install DS

step 2 - install x

Step 3-- install y

 

  • If you are using a local DS such as a legacy unsupported Windchill DS or Open DJ, it needs to be installed and configured first
  • then install Windchill

View solution in original post

3 REPLIES 3

On the monolithic install:

Monolithic Installation-

 

1.Is directory server mandatory to install for any version of WC installation?

  • Not generally after 12.0.2 (I can't remember the specific CPS build). 

2.If answer to above question is yes then What are the LDAP settings ( I not able to get clarity form document)? I mean should be keep the same populated values or change it? 

  • N/A

3.If answer to question 1 is NO then what can be used?

  • Any LDAP v3 Data store
  • Note: LDAP isn't just used for authentication, there is also a back end infoengine connection to look up AD group membership, get additional attributes about users etc. So even if you do some sort of SAML authentication, LDAP will still be required.

4.We have our company LDAP server set up , we can use that? if yes can some give quick values or any configuration related info for it? 

  • No special settings, however if your LDAP is using LDAPs you will need the certificate for the domain controllers / ldap servers in the java keystore on Windchill before starting the installer
  • If your LDAP doesn't allow anonymous binding, you will need the full CN of an admin user that will be the site admin. I would recommend this be a generic account like a service account and not a user account (admin user can be changed later with some xconfmanager commands).
    • ex: cn=MyAdminUser,ou=myorg,dc=mycompany,dc=com
  • Additionally you could define a group or OU to use to filter members

5.If i have installed Directory server and want to use the LDA sever of company is it possible to connect? If yes can someone shares any basic steps involved.

6.It would be great if someone gives me approach for installation ..Just for example...

Step1 install DS

step 2 - install x

Step 3-- install y

 

  • If you are using a local DS such as a legacy unsupported Windchill DS or Open DJ, it needs to be installed and configured first
  • then install Windchill
PM_11017169
4-Participant
(To:jbailey)

Thanks J bailey for guidance, I will follow the suggestion.

Hello @PM_11017169

 

It looks like you have a response on your topic. If it helped you solve your question please mark the reply as the Accepted Solution. 

Of course, if you have more to share on your issue, please let the Community know so other community members can continue to help you.

Thanks,
Community Moderation Team.

Top Tags