Job Management Partner 1/Base User's Guide

[Contents][Glossary][Index][Back][Next]


1.2.3 Secondary authentication server

Two authentication servers can be set up in one user authentication block. One authentication server is for normal use; the other is in reserve. These two JP1/Base programs are referred to as the primary authentication server and secondary authentication server, respectively. If the primary authentication server is disabled for any reason, the system automatically switches to the secondary authentication server to prevent operations from being disrupted.

Organization of this subsection
(1) Setting up a secondary authentication server
(2) Connection processing

(1) Setting up a secondary authentication server

To set up a secondary authentication server, specify on each host which host is to serve as the secondary authentication server. If the JP1/Base version, JP1 user settings, or operating permission settings are different between the primary authentication server and the secondary authentication server, an authentication error could occur when JP1/Base switches the authentication servers. To make those settings identical, copy the settings from the primary authentication server to the secondary authentication server.

(2) Connection processing

The following figure shows the flow of processing to connect the user to the secondary authentication server if connection to the primary authentication server fails.

Figure 1-4 Connecting to the secondary authentication server if the connection with the primary authentication server fails

[Figure]

As shown in Figure 1-4, the status changes to the blocked status if the system does not attempt to reconnect to the authentication server after a connection failure. You can check the connection status via the GUI (Windows only) or by a command. The authentication server is shown as Blocked when the status of the connection is blocked.

The table below shows the status of the target authentication server and how to select the target authentication server.

Authentication server status How the target authentication server is selected
Primary authentication server: Available
Secondary authentication server: Available
Host tries to connect to the primary authentication server.
Primary authentication server: Blocked
Secondary authentication server: Available
Host tries to connect to the secondary authentication server.
Primary authentication server: Available
Secondary authentication server: Blocked
Host tries to connect to the primary authentication server. If connection to the primary authentication server fails, the host does not connect to the secondary authentication server.
Primary authentication server: Blocked
Secondary authentication server: Blocked
Host tries to connect to the primary authentication server. If connection succeeds, the blocked status on the primary authentication server is released.
If connection to the primary authentication server fails, the host tries to connect to the secondary authentication server. If connection succeeds, the blocked status on the secondary authentication server is released.
If connection to the secondary authentication server fails, a connection error occurs.

Even if a user intentionally places both authentication servers in the blocked status, if there is an attempt to log in from JP1/IM - View or JP1/AJS - View or an attempt to execute a JP1/AJS job, the system will attempt to connect to an authentication server. If connection succeeds, the system will release the blocked status of one of the authentication servers.

Note that system operation stops if both authentication servers are blocked. You should detect the blocked status as early as possible and eliminate the cause.

To detect the blocked status, JP1/Base can automatically issue a JP1 event if the status of the connection to an authentication server changes. Issuing JP1 events enables JP1/IM - View and other programs to monitor connections to authentication servers. By default, JP/Base does not issue a JP1 event. For details on how to issue a JP1 event, see 2.4.2 Setup for handling possible errors in JP1/Base.

If an error on the primary authentication server is resolved while you are connected to the secondary authentication server, manually release the blocked status of the primary authentication server. For details on how to release the blocked status, see 6.4 Setup for handling the blocked status (using a secondary authentication server).

Note
The target authentication server is switched only in the event of a communication error or if the authentication server has not started. Switching is not performed in response to a typing mistake or incorrect password entered by the executing user.

[Contents][Back][Next]


[Trademarks]

All Rights Reserved. Copyright (C) 2009, Hitachi, Ltd.