Configuration Instructions
- Login to WAS8 administration console. Goto Applications > Application Types > WebSphere enterprise applications
- Select the checkbox next to ifsapp, fndweb and docvue (if available) and click Stop. This will stop the selected applicaions.
- Goto Security > Global security. Under User account repository \ Available realm definitions select Federated repositories and click Configure.
- Under Repositories in the realm click Add Base entry to Realm. Expand Add repostiry and select LDAP repository.
- Set values as shown. Click OK and Save.

- In the current panel you are in, give the Distinglished name of the realm. For example something like “DC=devsys,DC=local”. Click OK and Save.

- Back in Federated repositories panel you will see the configured LDAP repository. Set values as shown. Click OK and Save.

- Back in the Global security panel, make sure Federated repository is selected as the current realm. Then click Set as current to make the setting permanent.
- Then check Enable administrative security and Enable application security. Click Apply and Save.
- Stop the application server. If the server would not stop properly, try to give the username and password for the admin from the command prompt to stop the server.
E.g.: <profile home>\stopServer.bat -username <username> -password <password>
- [Optional]
Enhanced security for server scripts.
- Start application server and login to administrative console using the AD admin user credentials. (Perform steps 1 & 2 if requred)
- Goto Security > Global security, then expand Web and SIP security and select SPNEGO Web authentication.
- On the SPNEGO Filters list click New. In the General Properties panel complete the following details.

- Click Apply and you return to the SPNEGO Web authentication panel.
- Click Enable SPNEGO and select the locations for Kerberos configuration and keytab files. Click Apply and Save.

- Goto Security > Global security. Under Authentication click on the link Kerberos configuration, set values as followed, click OK and Save.

- Perform Step 3. Click on the Repository Identifier name. Save the setting again as it is and notice the change in the Login properties field under Security.

- Goto Security > Bus security. Select ifsbus and then select Security under Additional Properties. In the Security for bus ifsbus panel, under Related Items, goto JAAS - J2C authentication data.
- Click on jmsuser alias and change/set the password for user IFSWEBSPHEREMSGUSER to the LDAP password for this user. Click OK and Save changes.
- Goto Security > Security domains and click on IFSREALM. Change setting under User Realm as shown below.

- Click OK and Save changes.