Single Sign On between Messenger Express and Delegated Administrator

Hello,

I am working with old versions of both ME and DA. Long story short, this is because of using a packaged product. We can't upgrade until the vendor does.

So, that being said, I'm trying to setup the best experience for my users. I'm on:

iPlanet Messaging Server 5.2 HotFix 2.10 (built Dec 26 2005)

iDA for Messaging and Collaboration 1.2

SSO between ME and DA works intermittently. Maybe 60% of the time. A colleague suggested I look at the session cookie being set by messenger express to debug this. In his testing, he noticed that every time the cookie contained a non alpha-numeric character, SSO failed. Sure enough, I validated his testing and reproduced the same results.

For example, a cookie like this succeeds and causes no problems:

ssogrp1-msg50: kOyCPoZ0gKw

Cookies like these, however, fail to SSO into DA :

ssogrp1-msg50: ab+WblyWTsY

ssogrp1-msg50: N8/9P9iaEng

Any ideas? Has this ever been logged as a defect or patched? Or, am I just out of luck because my app versions are antiquated at this point and I need to wait for the opportunity to upgrade? Is it possible to configure iDA to only allow alphanumeric characters in the session cookie?

Thanks :- )

[1261 byte] By [saspyrisona] at [2007-11-26 13:24:24]
# 1
Hi,I'm pretty sure you are hitting an old iDA bug (4949005 - SSO fails between webmail and iDA depends on characters of SessionID). This was fixed in iDA over 2 years ago (iDA1.2hf1.6). You should patch your iDA install.Cheers,Shane.
shane_hjortha at 2007-7-7 17:58:08 > top of Java-index,E-Mail, Calendar, & Collaboration,Sun Java System Messaging Server...
# 2
You know, after I posted that I searched through sunsolve bugs and found that same thing. The vendor provided stock 1.2, so I downloaded 1.2p2 and the problem I described was resolved. Thanks for the reply though!
saspyrisona at 2007-7-7 17:58:08 > top of Java-index,E-Mail, Calendar, & Collaboration,Sun Java System Messaging Server...
# 3
Yep. that bug is indeed fixed with 1.2p2. You did the right thing.
jay_plesseta at 2007-7-7 17:58:08 > top of Java-index,E-Mail, Calendar, & Collaboration,Sun Java System Messaging Server...
# 4
I'm the colleague Scott mentioned. Is this issue fixed in the WIndows iDA 1.2p1 patch? If not, is there any chance of a Windows iDA 1.2p2 patch?
JohnDalbeca at 2007-7-7 17:58:08 > top of Java-index,E-Mail, Calendar, & Collaboration,Sun Java System Messaging Server...
# 5

Hi,

The bug will only be fixed in patch releases after hotfix 1.06, namely 1.2p2. I wasn't able to find any copy of a Windows iDA 1.2p2 patch although I was able to find ida-1.2hf1.06 which fixes this particular issue. You would need to log a Sun support call to get a copy.

Regards,

Shane.

shane_hjortha at 2007-7-7 17:58:08 > top of Java-index,E-Mail, Calendar, & Collaboration,Sun Java System Messaging Server...
# 6
Hi Shane,What kind of support contract would we need to log a support call? Would I be able to have our vendor (SunGard HE) log the support call instead?Thanks,John
JohnDalbeca at 2007-7-7 17:58:08 > top of Java-index,E-Mail, Calendar, & Collaboration,Sun Java System Messaging Server...
# 7
Hi John,You should be able to get the vendor to log the support call. A lot of the cases we work with at Sun involves vendors/partners for another customer. It may be worth pointing the Sun support person at the forum thread so they have context to the
shane_hjortha at 2007-7-7 17:58:08 > top of Java-index,E-Mail, Calendar, & Collaboration,Sun Java System Messaging Server...