Confused on VLF-ONE User Management
Posted: Thu Apr 06, 2017 11:59 pm
I am really confused on how you are supposed to manage users in VLF-ONE.
Let me recap what I am trying to do and hopefully someone can tell me what I am missing.
We deploy to a development/test iSeries and a production iSeries. We authenticate the user with their iSeries credentials and get their iSeries group profile on successfull authentication. I then use that iSeries group profile to map to a VLF-ONE user (akin to a Role) and that manages the access to different Applications / Business Objects via the VLF-ONE User. At lot of that info came from http://vlforum.lansa.com.au/viewtopic.php?f=3&t=1221.
The VLF Logon Handler enables Framework Security swaps the UserProfileToCheck with the mapped VLF profile.
iSeriesProfile => VLF User
QSECOFR => ADMIN_USR
QPGMR => ADMIN_USR
GROUPCR => CREDIT_USR
Of course when running locally, the iSeries Profile is not used and I log in directly as the VLF User ADMIN_USR.
This works great locally where I can use the VLF tool to create the VLF profiles. Its when I try to do the same on the iSeries that I am running into problems. This would not be a problem if I could use the XML file, but this document tells me I cannot use it for VLF-ONE. http://docs.lansa.com/14/EN/lansa048/in ... 8_2000.htm
So I have to get these profiles into the iSeries some other way.
With Framework Sercurity enabled, I cannot log in (my iSeries group being QPGMR) because I am not authorized to the Framework. Makes sense, because I have no profiles in the framework to use.
If I disable Framework Security, I can get to the Users and Groups object, but I get the warning that Framework Security is not enabled and will not be saved for this framework.
Ok, so I can't use the VLF-ONE Administration Application to create a user until I can get a user in VLF-ONE. It seems like the chicken/egg problem.
The VLF Tools that use locally only seem to work locally, I don't see how I can tell it to go to the development iSeries instead of my local SQL Server.
I've read about exporting and importing users, but that seems to only work for VLF-WIN, and this quote in the docs "Note Condition: The import feature is part of VLF-WIN. The imported data is useable by VLF-WIN and VLF-ONE." http://docs.lansa.com/14/EN/lansa048/in ... 8_0020.htm makes no sense to me. This doc says that I can import from the XML file, http://docs.lansa.com/14/EN/lansa048/in ... 8_0020.htm, ok, that tool is not in VLF-ONE so how do I get that tool to talk to the development server?
Other parts in the docs say to "Log in as the Admin User ...".
How in the world do you get that Admin user in VLF-ONE in the first place?
Let me recap what I am trying to do and hopefully someone can tell me what I am missing.
We deploy to a development/test iSeries and a production iSeries. We authenticate the user with their iSeries credentials and get their iSeries group profile on successfull authentication. I then use that iSeries group profile to map to a VLF-ONE user (akin to a Role) and that manages the access to different Applications / Business Objects via the VLF-ONE User. At lot of that info came from http://vlforum.lansa.com.au/viewtopic.php?f=3&t=1221.
The VLF Logon Handler enables Framework Security swaps the UserProfileToCheck with the mapped VLF profile.
iSeriesProfile => VLF User
QSECOFR => ADMIN_USR
QPGMR => ADMIN_USR
GROUPCR => CREDIT_USR
Of course when running locally, the iSeries Profile is not used and I log in directly as the VLF User ADMIN_USR.
This works great locally where I can use the VLF tool to create the VLF profiles. Its when I try to do the same on the iSeries that I am running into problems. This would not be a problem if I could use the XML file, but this document tells me I cannot use it for VLF-ONE. http://docs.lansa.com/14/EN/lansa048/in ... 8_2000.htm
So I have to get these profiles into the iSeries some other way.
With Framework Sercurity enabled, I cannot log in (my iSeries group being QPGMR) because I am not authorized to the Framework. Makes sense, because I have no profiles in the framework to use.
If I disable Framework Security, I can get to the Users and Groups object, but I get the warning that Framework Security is not enabled and will not be saved for this framework.
Ok, so I can't use the VLF-ONE Administration Application to create a user until I can get a user in VLF-ONE. It seems like the chicken/egg problem.
The VLF Tools that use locally only seem to work locally, I don't see how I can tell it to go to the development iSeries instead of my local SQL Server.
I've read about exporting and importing users, but that seems to only work for VLF-WIN, and this quote in the docs "Note Condition: The import feature is part of VLF-WIN. The imported data is useable by VLF-WIN and VLF-ONE." http://docs.lansa.com/14/EN/lansa048/in ... 8_0020.htm makes no sense to me. This doc says that I can import from the XML file, http://docs.lansa.com/14/EN/lansa048/in ... 8_0020.htm, ok, that tool is not in VLF-ONE so how do I get that tool to talk to the development server?
Other parts in the docs say to "Log in as the Admin User ...".
How in the world do you get that Admin user in VLF-ONE in the first place?