Troubleshooting domain controller connection problems

A number of factors can contribute to connection problems when trying to connect to the domain controller. Review the following table to determine how to resolve potential domain controller connection problems

Table 1. Common EIM domain controller connection problems and solutions
Possible problem Possible solutions
You can not connect to the domain controller when using IBM® Navigator for i to manage EIM. Domain controller connection information may by incorrectly specified for the domain that you want to manage. Complete these steps to verify domain connection information:
  • Expand Security > All Tasks > Enterprise Identity Mapping. Click Domain Management. Right-click the domain that you want to manage and select Properties
  • Verify that the name of the Domain controller is correct and that Parent DN, if specified, is correct.
  • Verify that Connection information for the domain controller is correct. Ensure that the Port number is correct. If Use secure connection (SSL or TLS) is selected, the directory server must be configured to use SSL. Click Verify Connection to verify that the you can use the specified information to establish a connection to the domain controller successfully.
  • Verify that the user information in the Connect to Domain Controller panel is correct.
The operating system or applications can not connect to the domain control to access EIM data. For example, EIM mapping lookup operations performed on behalf of the system are failing. This may be happening because the EIM configuration is incorrect on the system or systems. Verify your EIM configuration. Expand Security > All Tasks > Enterprise Identity Mapping. Click Configuration. Right-click the selected domain and select Properties and verify the following:
  • Domain page:
    • The domain controller name and port numbers are correct.
    • Click Verify Configuration to verify that the domain controller is active.
    • The local registry name is specified correctly
    • The Kerberos registry name is specified correctly.
    • Verify that Enable EIM operations for this system is selected.
  • System user page:
    • The specified user has sufficient EIM access control to perform a mapping lookup, and the password is valid for the user. See the online help to learn more about the different types of user credentials.
      Note: If you have changed the password for the specified system user in the directory server, you must change the password here as well. If these passwords do not match, then the system user can not perform EIM functions for the operating system and mapping lookup operations fail.
    • Click Verify Connection to confirm that the user information specified is correct.
Configuration information appears to be correct but you can not connect to the domain controller.
  • Ensure that the directory server that acts as the EIM domain controller is active. If the domain controller is an IBM i platform, you can use IBM Navigator for i and follow these steps:
    1. Expand Network > Servers > TCP/IP Servers.
    2. Verify that the IBM Tivoli® Directory Server for IBM i has a status of Started. If the server is stopped, right-click IBM Tivoli Directory Server for IBM i and select Start
After you verify connection information and that the directory server is active, try to connect to the domain controller by following these steps:
  1. Expand Security > All Tasks > Enterprise Identity Mapping.
  2. Click Domain Management.
  3. Right-click the EIM domain to which you want to connect and select Connect.
  4. Specify the user type and the required user information that should be used to connect to the EIM domain controller.
  5. Click OK.