Showing posts with label websphere. Show all posts
Showing posts with label websphere. Show all posts

Wednesday, 2 December 2020

Modify Maximo URL's Context Root | Maximo

 Some times we need to change the default context root (/maximo) to something else, for example "/maximoprod"

http://localhost/maximo     ------->>>>        http://localhost/maximoprod

1. login to Websphere (https://maximo76.el.com:9043/ibm/console/) with wasadmin user

2. Applications > Enterprise Applications > MAXIMO > Context Root For Web Modules.

and modify the context root to "maximoprod" instead of "maximo" , as in my example. 


Restart Application server or Ripple start your cluster to login with new URL : 

http://maximo76.el.com/maximoprod


you are done :)

Tuesday, 19 May 2020

Enabling SAML SP-Initiated web single sign-on (SSO) | IBM Maximo

This task assumes that you have enabled your system to use the SAML web SSO feature. If you have not done this yet, see Enabling your system to use the SAML websingle sign-on (SSO) feature.

This task provides an example class and the steps to configure SP-initiated SSO.

Develop a SAML authentication request provider that implements the com.ibm.wsspi.security.web.saml.AuthnRequestProvider interface.

The com.ibm.wsspi.security.web.saml.AuthnRequestProvider class is found in the was_public.jar file in the (was_home)/dev directory.

The com.ibm.ws.wssecurity.saml.common.util.UTC class used in this sample can be found in the (was_home)/plugins directory.

The method getAuthnRequest(HttpServletRequest req, String errorMsg, String acsUrl, ArrayList<String> ssoUrls) must return a map that includes four entries with the following keys:

AuthnRequestProvider.SSO_URL

The SAML identity provider's Single-Sign-On URL.

AuthnRequestProvider.RELAY_STATE

The relayState as defined by the SAML Web Browser single-sign-on profile.

AuthnRequestProvider.REQUEST_ID

The value for this key must match the ID attribute's value in the AuthnRequest message.

AuthnRequestProvider.AUTHN_REQUEST

A Base64 encoded AuthnRequest message as defined in the spec. Your code is responsible for generating the AuthnRequest message.

You have to change your code as per your SSO URL you generated from Meta data.


import java.util.ArrayList;
                import java.util.HashMap;
                import javax.servlet.http.HttpServletRequest;
                import com.ibm.websphere.security.NotImplementedException;
                import com.ibm.ws.wssecurity.saml.common.util.UTC;
                import com.ibm.wsspi.security.web.saml.AuthnRequestProvider;
                .........

                public HashMap <String, String> getAuthnRequest(HttpServletRequest req, String errorMsg,
               String acsUrl, ArrayList<String> ssoUrls)
            throws NotImplementedException {
      
            //create map with following keys
            HashMap <String, String> map = new HashMap <String, String>();
          
            String ssoUrl = "https://example.com/saml20/Login";
            map.put(AuthnRequestProvider.SSO_URL, ssoUrl);

            String relayState = generateRandom();
            map.put(AuthnRequestProvider.RELAY_STATE, relayState);

            String requestId = generateRandom();
            map.put(AuthnRequestProvider.REQUEST_ID, requestId);
           
            //create AuthnRequest                       
            String authnMessage = "<?xml version=\"1.0\" encoding=\"UTF-8\"?>"
                   +"<samlp:AuthnRequest xmlns:samlp=\"urn:oasis:names:tc:SAML:2.0:protocol\" "
                   +"ID=\""+requestID+"\" Version=\"2.0\" "
                   + "IssueInstant=\"" +UTC.format(new java.util.Date())+ "\" ForceAuthn=\"false\" IsPassive=\"false\""
                   + "ProtocolBinding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST\" "
                   + "AssertionConsumerServiceURL=\"" +acs+"\" "
                   + "Destination=\"" +destination +"\"> "
                   + "<saml:Issuer xmlns:saml=\"urn:oasis:names:tc:SAML:2.0:assertion\">"
                   + issuer
                   +"</saml:Issuer> <samlp:NameIDPolicy"
                   +"Format=\"urn:oasis:names:tc:SAML:2.0:nameid-format:transient\""
                   +"SPNameQualifier=\"mysp\""
                   +"AllowCreate=\"true\" /> <samlp:RequestedAuthnContext Comparison=\"exact\"> "
                   +"<saml:AuthnContextClassRef xmlns:saml=\"urn:oasis:names:tc:SAML:2.0:assertion\">"
                     +"urn:oasis:names:tc:SAML:2.0:ac:classes:</samlp:RequestedAuthnContext> </samlp:AuthnRequest>";

            map.put(AuthnRequestProvider.AUTHN_REQUEST, authnMessage);
                return map;
            }
             private String generateRandom() {
             //implement code that generates a random alpha numeric String that is unique
             //each time it is invoked and cannot be easily predicted (like a counter)
             }


Put a jar file that contains your custom class in the (WAS_HOME)/lib/ext directory.

Configure the SAML web SSO to use your AuthnRequest message.

Log on to the WebSphere Application Server administrative console.
 
Click Security > Global security.
 
Expand Web and SIP security and click Trust association.
 
Click Interceptors.
 
Click com.ibm.ws.security.web.saml.ACSTrustAssociationInterceptor
 
For Custom properties,
click new, then complete the following custom property information,
where id is what you assigned to the SSO Service Provider (SP) for which you want this property to apply:

Name: sso_<id>.sp.login.error.page
Value: The class name of your custom AuthnRequestProvider implementation.


For More Info please visit : IBM Knowledge center 

SAML web single sign-on








Wednesday, 6 May 2020

Restart Maximo JVMS,Nodes and DMGR (Nodes,DMGR,Syncnode)

Goto WAS ,Login from Wasadmin user, Stop all the JVMS (Maximo_u01,02,03,04, Cron01,Cron02,Rep01,Rep02,Mif01,Mif02)

Go to System administartion stop all Nodes.

------------------Stop Nodes--------------------------------------


Now access server and run following commands from both servers.

server01  , server02

path:server01

/app/IBM/WebSphere/AppServer/profiles/AppSrv01/bin/

./stopNode.sh -username wasadmin -password <password>

path:server02

/app/IBM/WebSphere/AppServer/profiles/AppSrv01/bin/

./stopNode.sh -username wasadmin -password <password>



------------------Stop DMGR------------------------------------------

Goto wasadmin DMGR Path

path:server01

/app/IBM/WebSphere/AppServer/profiles/Dmgr01/bin/

./stopManager.sh -username wasadmin -password <password>


------------------Start DMGR-----------------------------------------

Goto wasadmin DMGR Path

path:mdrcqeamsapp01.qterminals.local

/app/IBM/WebSphere/AppServer/profiles/Dmgr01/bin/

./startManager.sh -username wasadmin -password <password>




-----------------Sync Nodes---------------------------------------------
path:server01

/app/IBM/WebSphere/AppServer/profiles/AppSrv01/bin/

./syncNode.sh <DMGR HOSTNAME> 8879 -username wasadmin -password <password>


path:server02

/app/IBM/WebSphere/AppServer/profiles/AppSrv01/bin/

./syncNode.sh <DMGR HOSTNAME> 8879 -username wasadmin -password <password>

-----------------Start Nodes--------------------------------------------
path:server01

/app/IBM/WebSphere/AppServer/profiles/AppSrv01/bin/

./startNode.sh -username wasadmin -password <password>   (Password is needed to start Nodes)

path:server02

/app/IBM/WebSphere/AppServer/profiles/AppSrv01/bin/

./stopNode.sh -username wasadmin -password <password> (Password is needed to start Nodes)


-----------------Start All JVMS--------------------------------------- 
Once Nodes syncing is done, Go to JVMS and start all the JVMS.



 

Jacl script to Deploy Maximo application Manually using virtual Host.


Applications having build size more then 1 GB need to be deployed from wsadmin using JACL or Python script.
Below example is how to deploy Maximo Application using Jacl commands in DMGR.

Once Application build is done 
In my case I have four applications all with separate functionality.
maximo_ui , maximo_mif, maximo_rep, maximo_cron

after EAR built you will have ear file in default folder.
/app/IBM/SMP/maximo/deployment/default/
First Copy ear file (maximo_ui.ear).
Navigate to the WAS bin folder.
/app/IBM/WebSphere/AppServer/bin/
Paste maximo_ui.ear file within bin folder.

from terminal window (putty,mobaxterm,VNC)

Navigate to the
/app/IBM/WebSphere/AppServer/bin/

Run ./wsadmin.sh -username wasadmin -password wasadmin
DMGR will be login automatically.

wsadmin>

Now if application are already installed /deployed in WAS then you have to uninstall them.
Below are the commands to do it.

wsadmin>$AdminApp uninstall MAXIMO_UI
once uninstall done.
wsadmin>$AdminConfig save.

for REDEPLOY OR INSTALLING again.

wsadmin>$AdminApp install maximo_ui.ear { -usedefaultbindings -defaultbinding.virtual.host maximoui_host }


Make sure Virtual host is defined in Environment of WAS.

$AdminApp install maximo_mif.ear { -usedefaultbindings -defaultbinding.virtual.host maximomif_host }

$AdminApp install maximo_cron.ear { -usedefaultbindings -defaultbinding.virtual.host maximocron_host }

$AdminApp install maximo_rep.ear { -usedefaultbindings -defaultbinding.virtual.host maximorep_host }

Dont forget to issue save command at the end of installation finish.
wsadmin>$AdminConfig save.

 wsadmin>quit. 

Once done goto WAS.
Login from wasadmin.
Navigate to the deployed application (MAXIMO_UI) in Enterprise Applications.
Open Application and click on manage modules. to merge  application on cluster.
Also click on Virtual host to assign all the virtual hosts as well.

once Finish,Restart Nodes and DMGR.
Start JVMS.

For more Info visit below IBM tech Note:
https://www.ibm.com/support/pages/manually-completing-product-deployment