Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Content Management (Extended ECM)
API, SDK, REST and Web Services
LAPI & Siteminder
Linda_Stowell_(stonebridgeadmin_-_(deleted))
I am going to build a Java-based LAPI application that must be able to communicate with a Directory Services enabled Livelink instance. The client is using Siteminder for Web Authentication.I have read recent discussions regarding this topic and know that Livelink Explorer (a LAPI application) can work in a Siteminder environment via an INI setting. Opentext Support has indicated that LAPI/Siteminder functionality is not supported, but sees no reason why it would not work if we are sending the authentication request through the web server. Does anyone have experience doing this? If so, are there any issues?Thanks.
Find more posts tagged with
Comments
Adam_Myatt
Linda,Did you solve this issue? I'm building a Java-based LAPI app that needs to authenticate to a Siteminder/Directory Services enabled Livelink instance and would appreciate any help you could provide. Thanks.
eLink User
Message from Nair, Krishnankutty N. via eLinkPlease elaborate on your setup.The website that is siteminder protectedIs it enabled for 'anonymous' access and 'Basic Authentication'.I run asiteminder protectedLivelink web server like that.Have you put REMOTE_USER header variablein siteminder so thatLivelink can cash in on those things.Is your livelink 9.5.Older versiondirectory servicesWere not capable cashing in on the REMOTE_USER.To run LAPI with asiteminder protection you may have to enable a key in your opentext.inifile,it is in the DirSvcs documentation,I forget that.If you have adminaccess to livelink could you see if REMOTE_USER is found when youexecute this command/livelink(.exe)?func=admin.testargsLastly I do not have a piece of lapi code that works against thissiteminder livelink,but I have succeded in connecting thru lapi to ourintranet SSO livelink(not thru the cookie method but thru the configmethod,did take some time for me to figure that out ).Also if you needsomething really fast done about this raise a ticket with OpenText andhave them assign it to Geoff Obard or Tim ****,they are probably thedirectory gurus.Once again if you succeed I would like to know as well.Theoretically this is how your tunneled lapi should workLapi calls anonymous on port 80 of livelink server(our org uses a domainaccount for anonymous as ours is load balanced,hence the IUSR machineaccount is not used) Siteminder asks for credentials and verifies user Siteminder sets REMOTE_USER variable and passes that Basic Auth(cleartext Base64) to livelink CGI Livelink cracks cookie and logs person in and allocates session... -----Original Message-----From: eLink Discussion: Livelink Directory Services Discussion[mailto:directoryservices@elinkkc.opentext.com] Sent: Wednesday, April 19, 2006 7:31 AMTo: eLink RecipientSubject: RE - LAPI & SiteminderRE - LAPI & SiteminderPosted by Myatt, Adam on 04/19/2006 08:26 AMLinda,Did you solve this issue? I'm building a Java-based LAPI app that needsto authenticate to a Siteminder/Directory Services enabled Livelinkinstance and would appreciate any help you could provide. Thanks.[To reply to this thread, use your normal E-mail reply function.]============================================================Topic: LAPI & Siteminder
https://knowledge.opentext.com/knowledge/livelink.exe/open/4411588Discussion
: Livelink Directory Services Discussion
https://knowledge.opentext.com/knowledge/livelink.exe/open/3062146Livelink
Server:
https://knowledge.opentext.com/knowledge/livelink.exeTo
Unsubscribe from this Discussion, send an e-mail tounsubscribe.directoryservices@elinkkc.opentext.com.
Adam_Myatt
Thanks for responding. We run LL 9.5,SP1.I'm looking at this from an app developer standpoint, not a LL admin user standpoint. Our LL instance is set with Basic Auth for IIS with Siteminder in front. In opentext.ini we have :[ExplorerAuthentication]RequireSSOAuthentication=TRUESSOCookieName=SMSESSIONSSOCookieDomain=.OURDOMAIN.comI've got a Java LAPI program running on a J2EE web server. This J2EE app is also 'protected' by siteminder so when the user requests the URL for the app they get redirected to the Siteminder login page, they enter their credentials, and then are redirected back to the app URL. I can then retrieve the params I need from the HTTP header. In that app I would like to connect to our LL server, but the LL server, as mentioned, is SSO configured with Siteminder and I can't figure out for the life of me how to connect to it and pass along the correct headers and data USING the LAPI LLSession object only. The LLSession object does have a constructor that accepts a cookie, but I can't figure out if this allows the SMESSION variable that I can pull from the web app's http header or if it is only some LL-only cookie.
eLink User
Message from Nair, Krishnankutty N. via eLinkThe key should appear here for only LAPI .the section you have posted isfor livelink explorer [Security]Run the URL I sent you to see what livelink receivesHTTP_COOKIE SMIDENTITY=texuYh2qe5yLYtMEoNJgxUBflIM2lXHIomHCFZcC1mAIj3dCuVfKw9ysqt3c2YLH03cfjaHV2hP+VIduZQYuMUDb5TKuGZ7wZ36PDu0L2pfzEYPcU2BehuPe9fvPigkNUU6qOnMvoCkeArikpVdlRNG92mWshRxSRlFySupEdFUdrcXjUSome columns later ----the above one is a huge pieceREMOTE_USER nairkn I believe what you want can be parsed form the HTTP_COOKIE.When we wentto 9.5SP1 I worked with our siteminder team and had them put REMOTE_USERto make it authenticate to our livelink.Our old livelink with directorywas using a vended (PVA) module that would use HTTP_SM_USER to make theauthentication piece with livelink work. -----Original Message-----From: eLink Discussion: Livelink Directory Services Discussion[mailto:directoryservices@elinkkc.opentext.com] Sent: Wednesday, April 19, 2006 8:11 AMTo: eLink RecipientSubject: RE RE RE - LAPI & SiteminderRE RE RE - LAPI & SiteminderPosted by Myatt, Adam on 04/19/2006 09:08 AMThanks for responding. We run LL 9.5,SP1.I'm looking at this from an app developer standpoint, not a LL adminuser standpoint. Our LL instance is set with Basic Auth for IIS with Siteminder in front.In opentext.ini we have :[ExplorerAuthentication]RequireSSOAuthentication=TRUESSOCookieName=SMSESSIONSSOCookieDomain=.OURDOMAIN.comI've got a Java LAPI program running on a J2EE web server. This J2EE appis also 'protected' by siteminder so when the user requests the URL forthe app they get redirected to the Siteminder login page, they entertheir credentials, and then are redirected back to the app URL. I canthen retrieve the params I need from the HTTP header. In that app Iwould like to connect to our LL server, but the LL server, as mentioned,is SSO configured with Siteminder and I can't figure out for the life ofme how to connect to it and pass along the correct headers and dataUSING the LAPI LLSession object only. The LLSession object does have aconstructor that accepts a cookie, but I can't figure out if this allowsthe SMESSION variable that I can pull from the web app's http header orif it is only some LL-only cookie.[To reply to this thread, use your normal E-mail reply function.]============================================================Topic: LAPI & Siteminder
https://knowledge.opentext.com/knowledge/livelink.exe/open/4411588Discussion
: Livelink Directory Services Discussion
https://knowledge.opentext.com/knowledge/livelink.exe/open/3062146Livelink
Server:
https://knowledge.opentext.com/knowledge/livelink.exeTo
Unsubscribe from this Discussion, send an e-mail tounsubscribe.directoryservices@elinkkc.opentext.com.
Adam_Myatt
Yes, there is an http header 'cookie' that internally contains a bunch of variables like SMSESSION, JSESSIONID, etc. Also the http header REMOTE_USER is available, but how do I pass that through LAPI to authenticate to the Livelink server. Which of the parameters need to get passed down to LL and in what format?In java : config.add( "HTTPS", LLValue.LL_FALSE ); config.add( "VerifyServer", LLValue.LL_FALSE ); config.add( "LivelinkCGI", "/livelink/livelink.exe" ); config.add("DomainName",".mydomain.com"); config.add( "HTTPUserName", "myusername" ); config.add( "HTTPPassword", "mypassword" ); config.add("EnableNTLM", LLValue.LL_FALSE);session = new LLSession("nsk1docmgrtest.research.ge.com",80,cookie,config);where cookie is just an empty string for now. As mentioned before I'm not sure exactly what to pass to the cookie argument in the LLSession constructor and what format it needs to be in.
eLink User
Message from Nair, Krishnankutty N. via eLinkMaybe you need to retreive the cookie first check the documentationThe cookie will have the requisite info parse the Llcookie and seeIf it works.My $0.02file:///C:/OPENTEXT/builder/documentation/lapi/ini_cookie.html A LAPI application must obtain and pass the Livelink session cookie,named LLCookie, to the LL_SessionAllocFromCookieEx function (C++/VB) orLLSession (Java/.NET) constructor. The value of the cookie is createdand encrypted by Livelink. An example of an LLCookie value isYz5ffJ%2FPr1XpDlklVMNn%2Fw%3D%3D. -----Original Message-----From: eLink Discussion: Livelink Directory Services Discussion[mailto:directoryservices@elinkkc.opentext.com] Sent: Wednesday, April 19, 2006 9:12 AMTo: eLink RecipientSubject: RE RE RE RE RE - LAPI & SiteminderRE RE RE RE RE - LAPI & SiteminderPosted by Myatt, Adam on 04/19/2006 10:08 AMYes, there is an http header 'cookie' that internally contains a bunchof variables like SMSESSION, JSESSIONID, etc. Also the http headerREMOTE_USER is available, but how do I pass that through LAPI toauthenticate to the Livelink server. Which of the parameters need to getpassed down to LL and in what format?In java : config.add( "HTTPS", LLValue.LL_FALSE ); config.add( "VerifyServer", LLValue.LL_FALSE); config.add( "LivelinkCGI","/livelink/livelink.exe" ); config.add("DomainName",".mydomain.com"); config.add( "HTTPUserName", "myusername" ); config.add( "HTTPPassword", "mypassword" ); config.add("EnableNTLM", LLValue.LL_FALSE);session = newLLSession("nsk1docmgrtest.research.ge.com",80,cookie,config);where cookie is just an empty string for now. As mentioned before I'mnot sure exactly what to pass to the cookie argument in the LLSessionconstructor and what format it needs to be in. [To reply to this thread, use your normal E-mail reply function.]============================================================Topic: LAPI & Siteminder
https://knowledge.opentext.com/knowledge/livelink.exe/open/4411588Discussion
: Livelink Directory Services Discussion
https://knowledge.opentext.com/knowledge/livelink.exe/open/3062146Livelink
Server:
https://knowledge.opentext.com/knowledge/livelink.exeTo
Unsubscribe from this Discussion, send an e-mail tounsubscribe.directoryservices@elinkkc.opentext.com.
Linda_Stowell_(stonebridgeadmin_-_(deleted))
The original posting was made by Jeff Winton who is no longer with Stonebridge. I have inherited his account but unfortunately, I am not able to contribute to these discussions/comments. Sorry for any confusion or inconveniences this may have caused. L. Stowell
Krishnankutty_Nair
Hi Adam,Well did you see light at the end of the tunnel.If so will you be kind so as to post it here too...
Adam_Myatt
Finally got it to work. The confusion lies in the terminology around the Livelink Cookie that can be passed to the LLSession constructor. This is only a Livelink cookie, and has nothing to do with a browser session ID or the Siteminder cookie.If the HTTP header protocol that LAPI uses they do not pass an HTTP header named "cookie: " which is required for Siteminder to correctly know that you have already performed an SSO authentication.Scenario. You have a Java-based web app running in a J2EE server (say Tomcat or Weblogic). You request a page in a browser, the Siteminder "watching" the site intercepts the requests, sees you have not authenticated, and displays the SSO login page. You log in and authenticate, and Siteminder redirects you back to your web app. In that web app to auth to Livelink via HTTP/HTTPS where your Livelink instances is also "watched" by Siteminder you need to do the following. RRetrieve the Siteminder Session cookie (typically called SMSESSION) from the cookies using JSP like : String SMSESSION = "";Cookie[] cookies = request.getCookies();for(int i=0; i<cookies.length; i++){ String strCookieName = cookies[i].getName(); if("SMSESSION".equals(strCookieName.toUpperCase())) { SMSESSION = cookies[i].getValue(); }}Then pass that value to LAPI, but here's the PROBLEM . There is no way to do so with LAPI as is. You need to modify the Source of LLConnect.sendInitialHeader() method to append the text "Cookie: SMSESSION=VALUE" where `value¿ should be a parameter you pass in that is the actual value of the SMSESSION cookie retrieved through your web application and passed down through LAPI (modifyLLSession.getConfigValues to accept an additional value inside the LLValue object that is passed in. Then add an IF clause to retrieve that value and set an internal class member to that value. Append that class member to the "Cookie: SMSESSION=" text above in place of the VALUE marker. This is the ONLY way I have been able to get LAPI to work via HTTP/HTTPS where Livelink is behind Siteminder.
Rainer_Carstens_(rainer.carstens@t-systems.com_(De
Wouldn't it be easier to set up a proxy that handles the SMCOOKIE instead of patching the LAPI-Libs? What about libraries for C/C++? May be I can decompile Java-bytecode, but what is with platform-native libs?