User's Manual

Using the CMC Directory Service 279
Incorrect Smart Card PIN
Check to see if the Smart Card has been locked out due to too many
attempts with an incorrect PIN. In such cases, the issuer of the Smart Card
in the organization will be able to help you get a new Smart Card.
Unable to Log into CMC as an Active Directory User
If you cannot log into the CMC as an Active Directory user, try logging
into the CMC without enabling the Smart Card logon. You also have the
option of disabling the Smart Card Logon through the local RACADM
using the following commands:
racadm config -g cfgActiveDirectory -o cfgADSCLEnable 0
racadm config -g cfgActiveDirectory -o cfgADSSOEnable 0
Using the CMC with Generic LDAP
A CMC administrator can now integrate the LDAP server user logins with the
CMC. This integration requires configuration on both LDAP server and the
CMC. On the LDAP server, a standard group object is used as a role group. A
user who has CMC access will be a member of the role group.Privileges are
still stored on the CMC for authorization similar to the working of the
Standard Schema setup with Active Directory support.
To enable the LDAP user to access a specific CMC card, the role group name
and its domain name must be configured on the specific CMC card. You can
configure a maximum of five role groups in each CMC. Table 5-41shows the
privileges level of the role groups and Table 8-1 shows the default role group
settings.