Prepare an Active Directory server
- Install Active Directory:
- Install Windows 2000 or 2003 Server, which includes Active Directory.
- Install required Service Packs.
- Required if using Active Directory 2000:
Install Windows 2000 High Encryption Pack, which is required to enable SSL.
- To install Internet Information Services (IIS), which is required to export server certificates and must be installed before installing Certificate Services:
- Open the Control Panel and select Add/Remove Programs.
- Choose Add/Remove Windows Components.
- Choose the Internet Information Services (IIS) component and then click Next.
- Follow the instruction of the Windows Components Wizard. The Windows Server CD is needed.
- If you plan on using Active Directory over SSL, install Certificate Services:
- Open the Control Panel and select Add/Remove Programs.
- Choose Add/Remove Windows Components.
- Select Certificate Services and then click Next.
- Select Stand-alone root CA and then click Next.
You can also choose other options depends on you needs.
- Fill in CA identifying information and then click Next.
- Follow the instruction of the Windows Components Wizard. The Windows Server CD is needed.
- Create the WebSphere Portal administrative user:
- Create a new user with the Windows administrative tools.
There is a 20 character limitation for the user account name.
- Set the password for the new user.
- Activate the new user with the Windows administrative tools. Set the msDS-UserAccountDisabled attribute to false.
- Enable SSL for Active Directory. Required to set passwords during sign up and user creation:
- Install an Enterprise Certificate Authority on a Windows 2000 Domain Controller, which installs a certificate on a server or install a third-party certificate on the Domain Controller.
- Click...
Start | All Programs | Administrative Tools | Active Directory Users and Computer | domain_name (right-click) | Properties | Group Policy tab | Default Domain Policy group policy | Edit | Computer Configuration | Windows Settings | Security Settings | Public Key Policies | Automatic Certificate Request Settings
- Use the wizard to add a policy for Domain Controllers.
When these requirements are complete, all domain controllers request a certificate and support LDAP over SSL using port 636.
Parent topic:
Prepare user registries on Windows