Tab navigation
- Overview
- Objectives- selected tab,
- Test preparation
Section 1:Planning
- Given access to the customer, their hardware, applications, and policies, collect and analyze the customer requirements so that a solution document is created.
With emphasis on performing the following tasks:- Arrange a kick-off meeting with stakeholders.
- Interview the appropriate personnel.
- Review the security infrastructure of the customer.
- Identify and understand customer's Single Sign-On (SSO) requirements.
- Determine key objectives for enterprise SSO project.
- Collect the list of applications to be included in project.
- Analyze the customer's environment.
- Determine the secrets for passwords.
- Identify the auditing requirements.
- Create a solution document.
- Given the topology of the client network (number of PCs, subnets, etc), the number of users and the network link capacity, measure the network performance and analyze IBM Security Access Manager for Enterprise Single Sign-On V8.2 (ISAM ESSO)'s impact on the environment so that an estimate of the maximum network bandwidth consumed is available.
With emphasis on performing the following tasks:- Identify the most active period of time when users tend to log into ISAM ESSO.
- Identify replication bandwidth requirement for clustered databases distributed geographically if needed.
- Estimate the number of users involved.
- Estimate the size of their wallets by taking into account the number of accounts stored, number of profiles, etc.
- Estimate the average number of automatic fill of credentials that are done over the same period.
- Identify the synchronization interval.
- By using this information, generate an estimate of the maximum network bandwidth consumed.
- Given the customer's environment, explain the solution architecture so that a solution document with minimum hardware and software requirements for the solution is created.
With emphasis on performing the following tasks:- Arrange a meeting with customers.
- Explain the use of LDAP or AD.
- Explain the type of information stored and managed by the database.
- Explain the functionality of the IMS Server.
- Explain the purpose of the TIM AD adapter.
- Explain the Tivoli Common Reporting tool.
- Explain the purpose of Load Balancer.
- Explain several administration tools that an administrator can use for different purposes (AccessAdmin, AccessAssistant, AccessStudio).
- Explain where the AccessAgent has to be installed and the purpose.
- Explain the single sign-on and automation workflows which are accomplished through AccessStudio.
- Explain the minimum hardware and software requirements for each component including supported clients.
- Explain the Virtual Appliance solution.
- Explain any consideration regarding network requirements for supported clients and supported servers.
- Explain types of desktop applications supported.
- Explain supported Web browsers.
- Explain supported thin clients
- Explain how ESSO can be used with other Tivoli products for provisioning purposes.
- Create a document with minimum hardware and software requirements for the solution.
- Given access to the customer applications, collect and analyze the customer application requirements so that application profile checklist/document is created.
With emphasis on performing the following tasks:- Arrange a kick-off meeting with stakeholders.
- Get a representative desktop and application list.
- Review the customer applications in scope.
- Identify and understand customer's specific application requirements.
- Determine which applications are Web, Windows, mainframe, Java, others.
- Determine which applications password change workflow is required.
- Determine password policies for each application.
- Determine if any applications share authentication services.
- Identify any potentially "challenging" applications. #Identify mechanisms and personnel for password resets/expiry.
- Obtain or create credentials on the applications for testing purposes.
- Create an application profile checklist/document.
- Given access to the customer's test servers, applications, and test credentials, and ISAM ESSO installers, collate the data so that the components of the staging environment are determined and documented.
With emphasis on performing the following tasks:- Identify test server, test workstations, AccessAgent, AccessStudio, and ISAM ESSO software.
- Identify test applications that should be installed on the test workstations.
- Identify test user accounts.
- Verify which accounts to use for ISAM ESSO administrator account.
- Verify which accounts to use for ISAM ESSO lookup account.
- Verify which accounts to use for ISAM ESSO user accounts.
- Verify which accounts to use for ISAM ESSO databases account
- Verify which accounts to use for application profile creation/testing.
- Determine hostname/URL to be used for staging IMS Server.
- Identify the database to be used and obtain valid database credentials.
- Identify the directory server to be used and obtain valid credentials.
- Create a staging environment document.
- Given access to the customer's SSO project manager, their hardware, network administrator, and an estimate of the maximum network bandwidth consumed, determine High Availability (HA) and load balancing environment requirements so that a HA design document is created.
With emphasis on performing the following tasks:- Arrange a meeting with SSO project manager, Enterprise n/w Administrator and Infrastructure personnel.
- Collect information on existing network bandwidth and usage statistics and load infrastructure existing in the customer environment.
- Collect information needed to estimate hardware sizing for HA.
- Collect peak hour traffic estimates for One Time Password login and AA logins/secondDetermine peak installation and user sign-up rates
- Collect IMS database utilization and clustering requirements
- Collect load balancing architecture requirements
- Size hardware requirements for HA.
- Architect HA solution for ISAM ESSO components.
- Create a HA design document.
- Given access to the AA installer, the domain controller, client machine and a network share accessible to all clients, create an AA Installation Group Policy Object (GPO) and deploy it to the client machines.
With emphasis on performing the following tasks:- Review the Active Directory infrastructure.
- Modify the Setup help .ini file.
- Modify the installer package according to the customer requirements.
- Create a new GPO or identify an existing GPO to setup for AA Installation.
- Configure changes to the GPO.
- Verify connectivity between clients and IMS Server (80 and 443).
- Install the agent and add the client machine into the scope of this GPO.
- Verify the agent was installed.
- Restart the client machine.
- Given the business requirement document, determine a windows session management strategy so that a deployment recommendation for session management in the customer environment is created.
With emphasis on performing the following tasks:- Review the security infrastructure of the customer.
- Identify and understand customer's session management requirements.
- Determine system hardware so appropriate policies can be implemented.
- Determine key objectives for shared/roaming and personal workstation.
- Collect the usage of fast user switching in the environment.
- Collect the usage of kiosk environment.
- Collect the second factor authentication information.
- Create the windows session management strategy document.
- Given the authentication mechanisms, IMS deployment, second factor options and access to customer's authentication requirement, determine a strong authentication strategy so that a strong authentication strategy is documented.
With emphasis on performing the following tasks:- Analyze customer's authentication requirements.
- Identify required authentication setup.
- Identify the second factor(s) to use, if applicable
- Identify and Validate appropriate reader for second factor authentication, if applicable.
- Identify the readers that are available, compatible and supported with the ISAM ESSO environment being deployed.
- Validate the readers that are identified as compatible and supported with the ISAM ESSO environment being deployed.
- Document the list of readers to be considered for deployment.
- Document the strong authentication strategy.
- Given customer requirements, determine need and identify resources for any integration with ISAM ESSO API so as to define an integration strategy (if needed).
With emphasis on performing the following tasks:- Determine whether any customer requirements need integration with ISAM ESSO API.
- Identify the ISAM ESSO API that can meet the requirement (e.g. ISAM ESSO Provisioning API).
- Define and document the strategy and provide implementer (possibly self) information/documentation needed to implement the integration.
- Given requirements for upgrade, analyze the existing ISAM ESSO environment so that an appropriate upgrade strategy is created.
With emphasis on performing the following tasks:- Identify existing infrastructure that will be affected by the upgrade.
- Identify key stakeholders in upgrade.
- Identify what, if any, new features will be implemented with the upgrade
- Identify ISAM ESSO downtime during upgrade.
- Determine upgrade steps.
- Create update strategy document containing above information with a notification plan.
Section 2:Installation
- Given the IBM Security Access Manager for Enterprise Single Sign-On V8.2 (ISAM ESSO) server architecture requirements, set up the middleware components so that the IMS Server is installed successfully.
With emphasis on performing the following tasks:- Verify the operating system prerequisite and free disk space have been met.
- Install WebSphere Application Server according to documented server architecture.
- Install IBM HTTP Server and plug-ins.
- Configure IHS as a front end to WebSphere Application Server.
- Test communication of connections between HIS and WebSphere Application Server.
- Document configuration.
- Given the ISAM ESSO server installer, set up the server component so that the IMS Server is installed successfully.
With emphasis on performing the following tasks:- Verify the IMS prerequisites.
- Run the installer of the server.
- Configure the enterprise directory and database instance details during the installation.
- Verify that IMS application components have been mapped to servers.
- Verify the IMS Server is installed on the system.
- Document installation parameters in the Planning Worksheet.
- Given the ISAM ESSO IMS application has been installed, upgrade ISAM ESSO so that the IMS Server has been upgraded successfully.
With emphasis on performing the following tasks:- Upgrade from a existing ISAM ESSO server WAS Standalone server.
- Upgrade the IMS Server setting.
- Restart the WebSphere Application Server.
- Update the ISAM ESSO IMS module mapping.
- Restart the WebSphere Application Server.
- Verify if the upgrade is successful.
- Upgrade from a existing ISAM ESSO server WAS network deployment.
- Start the WebSphere Application Server Deployment Manager.
- Install the IMS Server on the deployment manager.
- Stop the nodes.
- Upgrade the IMS Server setting.
- Restart the WebSphere Deployment Manager.
- Update the ISAM ESSO IMS module mapping.
- Overide session management for ISAM ESSO IMS.
- Sync the nodes.
- Restart the cluster.
- Upgrade to a new server.
- Prepare all middleware for the new ISAM ESSO IMS Server version 8.2.
- Prepare and install the new IMS Server with the installer for an upgrade.
- Install and deploy the IMS Server to WebSphere® Application Server with the IMS Server installer.
- Stop the node agent and server on the new server installation
- Export the current configuration and import into new server.
- Run the IMS Configuration Wizard to upgrade the IMS Server settings.
- Configuring the IMS Server to use directory servers.
- Configure the SSL Certificates after an updates on the IBM HTTP Server.
- Verify if the upgrade is successful.
- Upgrade from a existing ISAM ESSO server WAS Standalone server.
- Given the new AccessAgent and AccessStudio installer, a test workstation, customer requirement ,and an existing IMS Server, set up the client workstations or endpoints so that the new AccessAgent and AccessStudio are installed successfully.
With emphasis on performing the following tasks:
- Upgrade AccessAgent.
- Prepare custom scripts that the installer runs before and after upgrading the AccessAgent.
- Upgrade the AccessAgent directly or with prepackaged installer on designed client computers.
- Upgrade the AccessStudio.
- Uninstall the existing AccessStudio 8.x.
- Install the AccessStudio on designated client computers.
- Verify a successful upgrade is completed on each server and client component to ensure that the upgrade is complete and it works.
- Upgrade AccessAgent.
- Given configured and available database, directory server, and virtual server environment, deploy a virtual appliance containing configured software prerequisites with the IMS Server in a single virtual image so that the Virtual Appliance running successfully.
With emphasis on performing the following tasks:- Extract and deploy the virtual appliance on VMware ESXi.
- Activate and configure the virtual appliance.
- Provision the IMS Server administrator.
- Verify the IMS Server configuration.
- Replicate the virtual appliance deployment and configuration, for High Availability (optional).
- Given a test workstation, customer requirement, an existing IMS Server and client communication via IMS Server hostname, install ISAM ESSO AccessAgent on the workstation with the required configurations so that the AccessAgent is installed successfully on test workstation.
With emphasis on performing the following tasks:- Verify the operating system prerequisite and free disk space on test workstation.
- Ensure that the workstation will get the correct machine policy template as defined by the requirements.
- Ensure that an AccessAgent installer package is available and has been customized for the deployment.
- Ensure that second factor hardware is configured and connected, if needed.
- Install the AccessAgent software
- On the workstation run AccessAgent installer package.
- Restart workstation.
- Verify connectivity with the IMS Server.
- Document procedure used to do install.
- Given a test workstation, customer requirement, user with administrative role, and an existing IMS Server, install ISAM ESSO AccessAgent on the workstation with the required configurations.
With emphasis on performing the following tasks:- Verify the operating system prerequisite and free disk space.
- Verify AccessAgent connectivity to IMS Server.
- Install the Access Studio software.
- On the workstation run Access Studio installer package.
- Restart workstation.
- Verify Access Studio is installed on the system.
- Verify connectivity with the IMS Server.
- Document procedure used to do install.
- Given an installed ISAM ESSO system and the Tivoli Common Reporting (TCR) installer, set up TCR so that the Administrator View Reports for ISAM ESSO activities is available.
With emphasis on performing the following tasks:- Install the TCR.
- Install reporting tool with proper database parameter.
- View reports.
- Document installation parameters in the Planning Worksheet.
Section 3:Configuration
- Given an enterprise directory, implement the directory integration between IBM Security Access Manager for Enterprise Single Sign-On V8.2 (ISAM ESSO) and the enterprise directory structure.
With emphasis on performing the following tasks:- Obtain relevant access to manipulate the Enterprise Directory Structure by IMS Server.
- Identify Enterprise Directory Servers to be used.
- Verify connectivity from IMS Server.
- Verify credentials are functional.
- Configure the enterprise directory by using Enterprise Directory Configuration Utility.
- Choose the type of directory to be connected with.
- Supply Authentication settings.
- Supply Attribute settings.
- For Active Direcotry deployments, enable "AD password sync" where appropriate.-If SSL not being used, Install and configure AD Agent on Domain Controller.-If SSL in use configure settings as appropriate.
- Test the enterprise directory.
- Document procedure and settings used.
- Given the prerequisites for databases, prepare the database so that the database is ready for IMS Server installation.
With emphasis on performing the following tasks:
- Identify customer database requirements.
- Prepare the database for the IMS Server installation.
- Verify the network connection between the IMS Server and the database server if those are in different workstation or servers.
- Obtain relevant access to create the DB instance to be used by IMS Server.
- Determine the path of the database (where it is installed).
- Synchronize the system clocks if IMS database and IMS Server would be running on different machines.
- Given a running IMS Server, run the IMS Configuration Utility so that the IMS Server is configured.
With emphasis on performing the following tasks:- Open the IMS Configuration Utility.
- Set up new or upgrade a existing IMS Server.
- Enter data source information.
- Create IMS DB Schema if new.
- Choose DB type.
- Configure DB connection info.
- Provide root Certification Authority (CA) details.
- Configure IMS services URL.
- Configure enterprise directory.
- Given customer strong authentication requirement and ISAM ESSO second factor supported options, configure strong authentication for second factor so that strong authentication for second factor can be implemented
With emphasis on performing the following tasks:- Identify the second factor(s) to be configured.
- Ensure that second factor hardware is available and connected, if needed
- Ensure that the drivers for second factor hardware are installed on server or client, if needed.
- Install any third party components required for second factor support prior to AccessAgent install.
- Verify hardware and software for second factor(s) are set up properly.
- Configure a strong authentication for second factor setup.
- Test the configuration according to use cases.
- Given the organization security policy, configure the IMS system policy so that IMS system policy is configured successfully.
With emphasis on performing the following tasks:
- Review the default system policy settings.
- Modify the default system policy settings according to customer requirements through AccessAdmin.
- Wait for the system policy to be replicated on to the agent.
- Verify IMS Server policy is configured successfully.
- Document parameters in the Planning Worksheet.
- Given an installed IMS Server, implement machine policies for workstations so that ISAM ESSO now has workstation policies available for assignment.
With emphasis on performing the following tasks:- Identify Workstation types based on customer requirements.
- Configure identified workstation policies.
- Configure identifying attribute for each policy.
- Wait for the system policy to be replicated on to the agent.
- Test policy configuration on test workstation.
- Document parameters in the Planning Worksheet.
- Given the organization security policy, configure the IMS user policy so that IMS user policy is configured successfully.
With emphasis on performing the following tasks:
- Review the default user policy setting.
- Modify the default user policy setting according to the customer requirements through the Access Admin.
- Verify the IMS user policy is configured successfully.
- Test policy configuration on test workstation.
- Document parameters in the Planning Worksheet.
- Given the requirements for ISAM ESSO IMS Server integration with a provisioning system, and installed IBM Java 1.5 or above, implement the provisioning bridge so that the user provisioning workflows are implemented successfully.
With emphasis on performing the following tasks:
- Identify the minimum requirements for both, the provisioning system and IMS Server that can integrate with the IMS.
- Create an IMS Bridge account at IMS for use by the provisioning bridge.
- Configure a key store for the IMS provisioning bridge on the Provisioning Server.
- Configure the IMS provisioning bridge (to point to right key-store and IMS, etc).
- Test the system for successful integration with the provisioning bridge.
- Document parameters in the Planning Worksheet.
- Given the ISAM ESSO solution and installed IBM Java 1.5 or above, implement the provisioning agent so that the provisioning agent is implemented on the customer environment.
With emphasis on performing the following tasks:
- Identify the minimum requirements for both the provisioning system and IMS Server that can integrate with the IMS.
- Create the ISAM ESSO Adapter.
- Create an IMS Bridge account at IMS for use by the provisioning bridge.
- Configure SSL between ITDI and IMS Bridge.
- Configure the IMS provisioning bridge.
- Configure workflow extension/operations.
- Create/Configure ISAM ESSO service instance.
- Test the system for successful integration with the provisioning bridge.
- Given access to the solution document and customer's ISAM ESSO environment on a test workstation, configure workstation usage workflows so that the desired workstation usage workflows are created.
With emphasis on performing the following tasks:
- Configure usage workflows for personal workstation.
- Implement personal workstation lock, unlock, logon and logoff scripts - if needed.
- Configure usage workflows for private desktop.
- Implement shared shared desktop lock, unlock, logon and logoff scripts - if needed.
- Implement shared private desktop lock, unlock, logon and logoff scripts - if needed.
- Configure usage workflows for roaming desktop.
- Implement roaming desktop for Citrix/TS environment.
- Given access to the requirement analysis document and customer's ISAM ESSO environment, define the machine policy templates and assignments so that the desired Machine Policy Template with assignments is created.
With emphasis on performing the following tasks:- Create new Machine Policy Templates based on customer requirements.
- Configure initial system settings for sign up and self-service.
- Configure Authentication policy (based on second factors).
- Configure Wallet policy.
- Configure Signup policy .
- Configure Shared Workstation and Desktop type policies.
- AccessAgent policy for Citrix or Terminal Server.
- Configure RFID logon.
- Configure Hybrid smart card logon.
- Create the rules for assignment.
- Select one of the new Machine Policy Template as the default policy to be used.
- Change the template assignment of existing machines if reassignment is required.
- Create new Machine Policy Templates based on customer requirements.
- Given a functional IMS Server and client requirements for the thin client, deploy the corresponding thin client solution so that a working thin client system (Citrix Server) with published applications enabled.
With emphasis on performing the following tasks:- Analyze customer requirements and determine the type of remote server (Terminal server or Citrix).
- Define and update the Citrix and Terminal Server Machine Policy Template to the Citrix or Terminal Server.
- Develop a virtual channel connector to deploy single sign-on and authentication services on a Citrix Server.
- Install AccessAgent on the remote server and ensure it is configured as a shared single session workstation.
- Set the server's AccessAgent policies.
- Enable port redirection and mapping if using RFID.
- Test the published application for Single Sign-on (or other automation) on Citrix.
- Document parameters in the Planning Worksheet.
- Given access to customer's audit requirement, configure and generate the audit logs so that the Audit log report is created.
With emphasis on performing the following tasks:- Search or define custom audit logs to be generated by the agents, if necessary.
- Configure the audit log events listed on the server interface.
- Define audit log event generation conditions.
- Select the search criteria for audit logs.
- Define the specific duration for which the audit logs are required and generate the report.
- Use published log database schema to generate reports using an external reporting tool, if necessary.
- Print the Audit log report.
- Given access to customer's audit requirement, configure and view the audit logs and customize it to the appropriate Audit report.
With emphasis on performing the following tasks:- Obtain support version of Tivoli Common Reporting utility.
- Define audit report type and custom audit logs to be generated by the server, if necessary.
- Configure the audit report content listed on the server interface.
- Determine and define audit report generating criterion.
- Select the search criteria for audit reports.
- Define the specific duration for which the audit reports are required and generate the report in support format and language.
- Use published log database schema to generate reports using an external reporting tool, if necessary.
- Print the Audit log report.
- Given the customer requirements, customize ISAM ESSO so that the requirements are met and the system can be implemented successfully.
With emphasis on performing the following tasks:- Customize the ISAM ESSO IMS Server.
- Modify the IMS configuration settings to address requirements such as enterprise directories to be integrated (SSL or non-SSL connection), AccessAdmin user interface customizations, housekeeping, etc.
- Install any required TAM or TIM adapters for ISAM ESSO Wallet manager provisioning or AD for SSL connection with the AD enterprise directory, if necessary.
- Ensure the ISAM ESSO IMSConfig and ISAM ESSO IMS WebSphere Enterprise Application service is running. Run through the Setup Assistant on AccessAdmin to configure the default user policy template, machine policy templates and assignments and system policies.
- Review the system policies, machine policy templates (and assignments) and user policy templates (and assignments). Create new ones if needed.
- Review and create the required saved Audit searches.
- Customize the ISAM ESSO AccessAgent Package.
- Review and make changes to the package based on GINA, Logon Banner, IMS Server fully qualified domain name (FQDN), etc. requirements in the INI file.
- Review and make changes to default registry settings in the deployment options registry file.
- Add in any files or scripts to be distributed with the installer in the Config folder.
- Review and make changes to the MSI installer file based on software distribution mechanism.
- Install any third party components required for second factor support prior to AccessAgent install.
- Set up any thin client solution components required for the customer prior to AccessAgent install
- Develop and customize the ISAM ESSO AccessProfiles.
- Review the application screens and SSO workflow requirements for each application and profile them accordingly.
- Test the customizations and obtain the customer's sign off.
- Document parameters in the Planning Worksheet.
- Customize the ISAM ESSO IMS Server.
- Given the requirements for an application's authentication to be augmented using ISAM ESSO One Time Password (OTP) functionality, implement a solution so that the OTP authentication by using third-party token requirements is addressed.
With emphasis on performing the following tasks:- Configure the IMS Server to enable OTP (time-based, OATH-based OTP, OTP by VASCO) for the authentication service to be strengthened.
- Configure OTP settings and install OTP token support on the IMS via WebSphere.
- Configure RADIUS authentication for the application (server) whose authentication service is to be strengthened.
- Configure to enable users sign up (registration) through AccessAdmin.
- Define necessary Authentication policies and configure Authentication modes to support OTP options via AccessAssistant.
- Set the ActiveCode enabled bindings for each token user.
- Set the requisite User and System policy settings.
- For OATH based OTP tokens, set the OATH look-ahead number and token reset window.
- Configure the bypass option for OTP authentication for AccessAssistant and Web Workplace Policies in the system scope.
- Given the requirements for an application's authentication to be augmented using ISAM ESSO Mobile Active Code functionality, implement a solution so that the MAC authentication requirements are addressed.
With emphasis on performing the following tasks:- Enable MAC support by configure MAC settings on the IMS Server.
- Configure the IMS Configuration Utility to define settings for the ActiveCode deployment including Allowed ActiveCode client IPs, the IMS Server address, OTP token reset window, enable the MAC-only registration of users, set to true.
- Configure an existing or SMTP message connector on the IMS Server for the selected MAC delivery channel. (Or develop a new message connector).
- Configure and set up the Authentication service. This is to configure the IMS Server's RADIUS Authentication interface if the application supports RADIUS authentication.
- Configure the Application's Authentication Server to perform RADIUS authentication with the IMS's RADIUS server.
- Configure the Application's Server to direct the client to display the MAC challenge screen on first authentication step success.
- Customize the Application's client user interface to show appropriate messaging on the MAC challenge screen.
- Set the selected user whom will utilize MAC authentication.
- For non-RADIUS authentication supporting applications.
- Customize the application logon interface to include a request for MAC or provide a separate MAC request page.
- Develop a SOAP client with the ability to make authentication calls and MAC request calls to the IMS.
- Configure the AccessAssistant and Web Workplace policies to use MAC.
- Configure necessary system policies.
- Configure the machine, system and user-related policies to employ MAC in AccessAdmin.
- Configure MAC options for selected users.
- Configure a bypass option for MAC authentication.
- Given access to the Solution Document, customer's ISAM ESSO Environment and system policies, define the self-service functionality so that the self-service functionality is defined.
With emphasis on performing the following tasks:- Enable self-service functionality and set the corresponding policies required to authorize.
- Enable self-service password reset.
- Enable self-service second factor registration.
- Enable self-service for authorization code generation.
- Test and deploy the self-service functionality.
- Include the self-service definitions in the user policy templates.
- Enable self-service functionality and set the corresponding policies required to authorize.
- Given a functional IMS Server and the customer requirements, configure user access to AccessAssistant so that AccessAssistant is configured.
With emphasis on performing the following tasks:- Configure AccessAssistant-related policies in user policy templates.
- Configure AccessAssistant-related policies in system policies.
- Test access for users.
- Document parameters in the Planning Worksheet.
- Given access to customer environment and business requirements, set policy priorities so that the policy priority is implemented.
With emphasis on performing the following tasks:- Analyze customer's policy requirements.
- Determine the scope of the policy (such as Machine, User or System policy)..
- If a policy is defined for two scopes, define which takes higher priority.
- Execute the command-line tool to modify the policy priorities.
- Given the customer requirements regarding application screens and workflows (Application Design Document) and an existing AccessProfile, modify an existing AccessProfile so that each application can be profiled successfully to meet the requirements.
With emphasis on performing the following tasks:- Determine the modifications required in order to make the existing AccessProfile work accordingly.
- Determine details like Account Data Template, Authentication service (and groups), to be used in the AccessProfile.
- Complete the Application Design Template based on the options determined.
- Given an IMS Server installation and customer requirements, define additional IMS Server administrators and set up the roles for User, Helpdesk and Administrator so that the users have been assigned roles.
With emphasis on performing the following tasks:- Log on to the AccessAdmin as the administrator.
- Search for users.
- Select a user to change his role.
- Open administrative policies.
- Change the role user and update.
- Assign default HelpDesk users through user policy templates.
- Enable the automatic role assignment for large deployments if it is necessary.
- Run the IMS Configuration Utility. -Specify the attribute name and attribute value for automatic role assignment.-Restart the IMS Server.
- Given end user availability, and functional AccessAgent and IMS components, utilize AccessAgent or AccessAssistant sign-up functionality so that users are successfully signed up with ISAM ESSO.
With emphasis on performing the following tasks:
- Verify user account in directory server.
- Verify default policy.
- Sign up users with:
- The AccessAgent sign up process.
- AccessAssistant.
- External provisioning system.
- Given customer requirements, IMS Server details, Tivoli Federated Identity Manager STS service, install, configure, and troubleshoot Web API's and security trust chain to enable credential management.
With emphasis on performing the following tasks:- Identify customer requirement for credential management.
- Install and configure Web API's.
- Install Tivoli Federated Identity Manager.
- If Tivoli Federated Identity Manager and Web API are installed in different WebSphere Application Servers, enable SSL between the two WebSphere instances.
- Deploy and configure security token service modules.
- Configure Tivoli Federated Identity manager STS modules.
- Testing the security trust chain.
Section 4:Administration
- Given AccessStudio, administrative privileges on the IMS Server, access to applications and notification when applications are modified, the review and update the Accessprofiles so that they are always up to date and working correctly.
With emphasis on performing the following tasks:
- Evaluate applications which are to be updated or changed to validate if the AccessProfile remains functional.
- Test in a staging environment.
- Deploy to production IMS Server once new profile is working correctly.
- Given access to the solution document, the customer's ISAM ESSO environment and disaster recovery site, determine and establish a disaster recovery regime so that an effective failover to Disaster Recovery (DR) environment is achieved in the event of a failure in the production environment
With emphasis on performing the following tasks:- Determine failover and recovery criteria for ISAM ESSO components.
- Determine backup and restore strategy for IMS database.
- Set up DR environment in a separate site or location.
- Test DR environment for failover situations.
- Prepare DR Invocation document.
- Given the IMS Server is up , review trace or audit logs and reports through the IMS , Tivoli Common Reporting (TCR) , and WebSphere so that audit logs and reports can be viewed by the Administrator.
With emphasis on performing the following tasks:- Search the audit logs based on the query.
- Save the query for the audit logs.
- Search the reports on the IMS Server based on user activity.
- Search the reports on the TCR server based on user information, token, user information ,and Helpdesk activity.
- Manage the reports based on the page size.
- Enable trace logs on WebSphere
- Review logs and trace logs on WebSphere.
- Given IMS Server is up and running, maintain the IMS Server so that the IMS Server is maintained.
With emphasis on performing the following tasks:- Configure and manage system policy.
- Configure and manage machine policy.
- Configure and manage user policy.
- Manage the roles of users and Helpdesk.
- Manage Second Factors.
- Provision, revoke, and delete the users.
- Stop and start the services of IMS Server.
Section 5:Performance Tuning/Problem Determination
- Given an existing ISAM ESSO installation, identify and implement measures for improving performance so that the server and client components perform at optimal levels.
With emphasis on performing the following tasks:- Identify and address opportunities for Improving Server performance, for example, configure the LDAP lookup timeout on a directory connector.
- Identify and address opportunities for Improving agent performance, for example, performance may be tuned by removing unnecessary application proflies, lowering the log level, excluding AccessAgent installation folder from certain runtime scans, adjust the synch interval between client and server, adjust communication timeouts etc.
- Identify and address opportunities for improving database performance, for example, log pruning, changing memory allocated to database, create indexes.
- Given an issue with the ISAM ESSO IMS Server functionality, troubleshoot the server utilizing tools provided so that the issue can be identified.
With emphasis on performing the following tasks:- Identify that the problem at hand is an IMS Server issue, and obtain the result-code provided in the IMS error logs (or on the Status page in AccessAdmin).
- Identify the cause of the specific error code in the diagnostics pages.
- If the result-code is related to integration with the enterprise directory, utilize the enterprise directory troubleshooting capability provided by the diagnostics pages.
- Identify the issue.
- Given a ISAM ESSO installation with lost connectivity to the IMS Server, troubleshoot IMS connectivity issues so that the connectivity problem can be identified.
With emphasis on performing the following tasks:- Determine if the client machine is on the network.
- Determine if certificates between the IMS and the agent are set up correctly.
- Determine if an intervening firewall between the client machine and IMS Server.
- Determine if any network configuration issue, such as DNS problems.
- Determine if an intervening application protector between the client machine and IMS Server.
- Determine if some personal firewall or anti-spyware is blocking traffic from winlogon.exe.
- Determine if the registry settings are corrupted or configured incorrectly, if AccessAgent is pointing to the wrong IMS Server.
- Check to see if agent machine can ping Web Server.
- Check to see if the IMS Server is up and running (ping test, visual inspection, etc) .
- Check to ensure the IMS application is running.
- Try to "Set IMS Server Location" from a client workstation.
- Identify the connectivity issue.
- Given ISAM ESSO operation issues with users, computers or servers, recover from common user/computer situations so that the issue is resolved.
With emphasis on performing the following tasks:
- Understand common issues affecting:
- Users, for example, user forgets password, user forgets key.
- Computers, for example, the user tries to log on to AccessAgent and unlock the computer but is unsuccessful.
- Servers, for example, IMS Server has crashed, database has crashed.
- Start the appropriate recovery workflow.
- Resolve the issue.
- Understand common issues affecting:
- Given an AccessProfile that is not working as it should, review the logs and make changes so that the AccessProfile works correctly.
With emphasis on performing the following tasks:
- From AccessStudio and import current AccessProfiles from the IMS Server.
- Use the test function of AccessStudio.
- Launch the application with AccessProfiles that you want to test.
- Perform the relevant actions on the application (i.e. login) to verify if the AccessProfile is executed correctly.
- Stop the test.
- Review the results of the test provided in the Messages pane and make changes to the AccessProfile as required.
- Given an existing ISAM ESSO installation, improve the Access Agent performance on Citrix server with Lightweight mode so that there is optimal server and client performance on Citrix environment.
With emphasis on performing the following tasks:
- Identify and measure the performance overhead introduced by AccessAgent on Terminal/Citrix server, for example: memory consumption, network traffic, application loading time, AccessAgent response time.
- Understand customer requirement and identify whether and which Lightweight mode can be deployed, for example: no lightweight mode, enforced lightweight mode, automatic mode.
- Configure Lightweight mode on Terminal/Citrix server and verify performance improvement.
