Lotus Notes LDAP Queries

According to the manual, Ironport has a problem resolving some variations of Lotus Notes email addresses. It seems if the email address isn't specifically listed in the Name and Address Book, then the LDAP query will fail.
Is there anyway to workaround this issue? I just installed a new box and its has been nice to see alot of emails being rejected by the LDAP lookup, however some people have gotten used to using implied variations of email addresses like Firstname_Lastname . This format isn't listed in the NAB, but it should be accepted as valid email.
The only thing I can think of is to have the Notes people add aliases for each user, but I think they'll probably throw something at me!
Thanks,
Tony

According to the manual, Ironport has a problem resolving some variations of Lotus Notes email addresses. It seems if the email address isn't specifically listed in the Name and Address Book, then the LDAP query will fail.
We are using Domino for user, mail-in and group address lookups (both primary and alias addresses) without problems. LDAP will give "user doesn't exist" result if the exact address can't be found. In Domino it's possible to have LDAP lookup into multiple address book, even bind multiple 3rd party LDAP serves behind one Domino LDAP server. (This is configured in directory assitance database.)
In the LDAP tree I get all mail addresses but not the aliases.
You didn't mention if you are using anonymous LDAP query or authenticated LDAP query. The anonymous LDAP query uses different access rights than authenticated query and is configured differently.
I assume you did anonymous query as you can see primary address but not alias. It's important to remember that the alias address is listed in different Domino field than primary Internet address.
You have to include both "InternetAddress" and "ShortName" Domino fields in default configuration document's LDAP settings (if you make a anonymous LDAP queries). These are set in "Anonymous users can query" field of "LDAP Configuration"
You should have at least the following included in "Anonymous users can query":
"InternetAddress" Domino field linked to "mail" LDAP attribute
"ShortName" Domino field linked to "uid" LDAP attribute
The accept query in IronPort configuration will then look like:
(|(mail={a})(uid={a}))
This should solve both primary and alias addresses...

Similar Messages

  • Lotus Notes & LDAP with EP 7

    Hello All,
    We are planning to integrate Lotus Notes with EP 7.0 I would like to know if Lotus Notes is an LDAP or do we need a seperate LDAP Server.
    We are also planning to use Windows based authentication for the Portal, do we need to have an LDAP or can we use the Lotus Notes as an LDAP Server as well, I would appreciate any help or suggestions you can offer.
    Please do let me know if Lotus Domino is an LDAP Server as well.
    Best Wishes,
    John.

    Hello John,
    for windows integrated authentication you simply configure the SPNego LoginModule which comes with the NetWeaver product UME.
    SPNego can technically work together with different user stores such as Microsoft AD, Novell eDirectory, ABAP user store and others. It is also technically feasable to connect Lotus LDAP functionality to the NetWeaver UME on project base.
    Summarizing: technically it can work but it require consultancy / project work since this configuration is not covered by the standard.
    If you need more information or assistance please contact me.
    Regards
    Michael

  • Cisco Phone Control and Presence 8.6.1.1185 with IBM Lotus Notes 8.5.2 (Integrated Sametime Client 8.0.2) - No presence status visible

    Hi community,
    I am trying to integrate Cisco Unified Presence 8.6.1.10000-34 with IBM Lotus Notes 8.5.2 with the integrated Sametime Client version 8.0.2 via the Cisco Plugins 8.6.1.1185.
    Phone control is working fine, whereas the presence status is not shown (= no handset symbol next to the Sametime user). When I look in the preferences of the plugin, I can see that the plugin has connected successfully to the CUCM (8.6.2.20000-2),whereas the connection to the CUPS has not been established.
    The user id as well as the password are all the same on all systems. Here is a description of what I have configured via the ciscocfg.exe tool:
    Feature Control:
    - Enable Phone Status -> checked
    - Enable Dial Using Cisco IP Communicator -> unchecked (not required)
    - Enable Control Desk Phone -> checked
    - Default Mode -> Control Desk Phone
    Control Desk Phone Settings:
    - Voicemail Pilot Number -> left blank (no voicemail)
    - Cisco Unified Communications Manager
         - Servers -> IP address of CUCM
         - Read Only -> unchecked
         - Use as Default CUCM -> checked
         - Synchronize Credentials -> checked
              - Use Sametime Credentials -> checked
    Use Secure Connection: -> not required
    LDAP Phone Attributes: -> not required
    Phone Status Settings:
    - Cisco Unified Presence Servers -> IP address of CUPS
    - Read Only -> unchecked
    - Synchronize Credentials -> checked
         - Use Sametime Credentials -> checked
    - Sametime User ID Mapping
         - Use Business Card Attribute -> MailAddress
         - Remove Domain -> checked
    - Display Off-Hook Status Only -> unchecked
    At the moment I don't see an error in the configuration, but maybe I am wrong. Could anyone please tell me what the error could be?
    Thanks a lot in advance!
    Kind regards,
    Igor

    Hi all,
    here are some additions to my above post:
    Servers and clients used:
    1x CUCM 8.6.2.20000-2
    1x CUPS 8.6.1.10000-34
    1x IBM Lotus Domino Messaging Express Server 8.5.2
    1x Sametime Entry Server 8.5.2 (on top of the Domino server)
    2x IBM Lotus Notes 8.5.2 with integrated Sametime 8.0.2
    2x Cisco Phone Control and Presence with Lotus Sametime (PCAP) 8.6.1.1185
    2x Cisco Unified Personal Communicator 8.5.5.19839
    Setup:
    - CUCM, CUPS and CUPC are working fine, i.e. Desk Phone control via CUPC, as well as availability and presence status are working without issues
    - IBM Lotus Domino server is the LDAP Directory, the Sametime Entry Server is installed on top of the Domino server and uses the Domino Directory
    - User ID and password on CUCM/CUPS match the ShortName field and password in Domino
    - The PCAP plug-in has been manually deployed to both Notes clients with the following configuration:
         - Enable Phone Status -> active
         - Desk Phone Control -> active
         - no credential synchronization for CUCM and CUPS, i.e. every user must fill the user details himself
         - Sametime User ID Mapping is implemented via the LDAP Attribute uid (which is equal to the user id in CUCM)
         - LDAP configuration filled in with details of the Domino server
    Phone Control is working fine, also the connection to the LDAP server (Domino) is fine. However, when I type in the credentials for the CUPS server login, I can see (in Troubleshooting pane) that the user (pparker) is connected to the CUPS server for a short period of time and then gets disconnected. After that no connection is possible to the CUPS server, i.e. status is always disconnected.
    I have collected the Tomcat (EPASSoap00010.log and security00010.log) logs via RTMT and compared them to the logs from the PCAP plugin. The relevant time period is from 15:14 to 15:17. In the Tomcat logs I can see that the authentication is successful (see attached files), however in the log of PCAP plugin I can see the following messages:
    2012/02/03 15:14:35.281 WARNUNG Credential is rejected. Nothing to retry ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.answerChallenge() ::thread=CT_CALLBACK.1 ::loggername=com.cisco.sametime.phonestatus.cup
    2012/02/03 15:14:35.281 WARNUNG #### Connection rejected presence server ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.onPresenceServerConnectionRejected() ::thread=CT_CALLBACK.1 ::loggername=com.cisco.sametime.phonestatus.cup
    2012/02/03 15:14:35.281 WARNUNG Credential is rejected. Nothing to retry ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.answerChallenge() ::thread=CT_CALLBACK.2 ::loggername=com.cisco.sametime.phonestatus.cup
    2012/02/03 15:14:35.281 WARNUNG #### Connection rejected presence server ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.onPresenceServerConnectionRejected() ::thread=CT_CALLBACK.2 ::loggername=com.cisco.sametime.phonestatus.cup
    I don't understand why the connection is rejected although the Sametime Internal ID and CUPS User ID match. Does anyone know what the issue could be?
    All posts are very much appreciated!
    Thanks a lot in advance!
    Kind regards,
    Igor

  • Address Book sync with lotus Notes is possible

    Hi,
    I'd like to know if it is possible to sync Personal Address book with lotus notes?
    Or there are Ip phone services that can query address book of lotus notes?
    Regards
    MC

    I developed an application for a German customer who is using Lotus Domino too.This application should be accesed through Services button on IP Phone This application queries Domino directory or Notes Personal Address Book via WebServices and displays results on IP phone. You can find a User Manual in german on my website http://www.arsnet.eu/workshop/iBOS20-Cisco-DE-pptA4.pdf . I can develop this Application in English too.
    Regards, Robert

  • Log ldap queries and authentication on Windows Server 2003

    Good afternoon
    I am in the process of decommissioning a Windows 2003 R2 domain controller and I want ensure that no custom applications are using this DC solely for authentication and LDAP queries (unfortunately this is not documented anywhere), and if there are find out
    there IP's so I can get there configuration changed to point at another domain controller.
    Could someone recommend a good way of doing this? Perhaps a 3rd party tool?
    Thanks in advance!

    Hello,
    without any documentation about fix use of this specific DC you can just plug the network cable and wait. Inform users about this and ask them to report asap if they realize not working programs.
    Additional check login scripts, GPO settings and other scripts that may run with scheduled tasks on every server.
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://msmvps.com/blogs/mweber/
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.

  • Urgent: Lotus Notes and TREX

    Hi,
    We are planning to use SAP’s TREX to search for word documents and ppts embedded within Lotus Notes. However, we have a couple of queries regarding our requirement and would appreciate your help.
    1) Is it possible to use the TREX server for indexing documents within Lotus Notes without an Enterprise Portal platform (For Ex., Is it possible to set TREX as the default search engine of Lotus Notes?)?
    If the above is not feasible then please read requirement 2:
    2) We are currently running Lotus Domino 6.5 and the portal platform is NW 04, SP15. I understand that there was a limitation of not being able to connect the portal with any Lotus Notes repository having version greater than 5.0.8. Does this restriction still exist?
    Any help would be greatly appreciated and suitably rewarded.
    Thanks & Regards,
    Vibhu

    Hello Vibhu,
    regarding 1) in the notes client, the search button actually contains a dropdown. This dropdown list may also contain HTTP URLs (e.g. in the standard R6 client you find AIL, Altavista and some other search engines linked). You may think of adding the TREX URL also there
    regarding 2) please use the KM repository manager by Conet for doing so. To do so, please take a look athe the portal Content portfolio here on SDN or direcly access the business packgage at:
    https://www2.iviewstudio.com/sdn/detail_view/index.cfm?action=package_information&CatalogSet=Vendor%20Content&ItemID=17344&CFID=7410541&CFTOKEN=5471887
    Regards
    Michael

  • Tool for building LDAP queries

    are there any visual or non visual tools for building LDAP queries ??
    thanks and regards
    Renjith.

    I've had great success with JDeploy - you can download it here:
    http://www.tiobe.com/jdeploy.htm
    IF not, you might want to check out the resource listing at google:
    http://directory.google.com/Top/Computers/Programming/Languages/Java/Development_Tools/Deployment/?il=1
    Best regards,
    Bj�rn B�rresen

  • ACS Authentication against Lotus Notes

    Hi Team, is it possible to authenticate Users via ACS against Lotus Notes, similar to MS AD? Regards, Michael

    I don't think it is possible to use ACS with Lotus notes for user authentication. These are the external databases supported with ACS.
    a) Windows User Database
    b) Generic Lightweight Directory Access Protocol (LDAP)
    c) Novell NetWare Directory Services (NDS) when used with Generic LDAP
    d) LEAP Proxy Remote Authentication Dial-In User Service (RADIUS) servers
    e) Token servers
    f) Open Database Connectivity (ODBC)-compliant relational databases (ACS for Windows)

  • Authentication against Lotus notes engine

    Hello All,
    I have a requirement to develop an application to authenticate the user against the Lotus notes Engine.... which I think is the LDAP.
    Any pointers to more information will be very helpful...
    Thanks and Regards
    Pradeep Bhojak

    I don't think it is possible to use ACS with Lotus notes for user authentication. These are the external databases supported with ACS.
    a) Windows User Database
    b) Generic Lightweight Directory Access Protocol (LDAP)
    c) Novell NetWare Directory Services (NDS) when used with Generic LDAP
    d) LEAP Proxy Remote Authentication Dial-In User Service (RADIUS) servers
    e) Token servers
    f) Open Database Connectivity (ODBC)-compliant relational databases (ACS for Windows)

  • LDAP Queries - Load balance - Cache

    Hello,
    i have configured LDAP Queries with Multiple-host-options: "Laod-balance". 2 LDAP hosts are defined in this querie
    Can anyone tell me what happens if the defined LDAP hosts are not available?
    Are users cached by Ironport appliance or is there always a new querie for every recipient?

    It will keep going between the two. If you want it to use a primary unless it is unavailable, you would pick failover.
    As for if both are unavailable, there is a configuration option on the listener that allows you to accept if ldap is unavailable. You will see your work queues grow until the ldap returns.
    The ldap is cached if they are already in the list it knows about. You can setup information on how many entries to cache and for how long. Under ldapconfig->edit->pick the ldap server configuration->server->cache.

  • Lotus Notes documents migration into Solution Manager

    We have been using Lotus notes application for maintaining only documentation in our landscape. But now, the plan is to move all the documentation from Lotus notes to SAP Solution Manager and use it as a document management system from now....
    Could anyone please answer the following queries:
    1) Does LSX environment help/enhance the migration ?. If not, are there any tools/accelerators/functions/automatic methods for mas uploading?
    2) This documentation is not project specific documentation. Where do you think this must go in Solution Manager?
    In the custom area of BPR?. If yes, please do let me know the procedure for the same.
    3) Would it be possible to link the documents to functional domains/ business scenarios/ business processes in the BPR?
    4) Lotus notes provides access to all the versions (Draft/Approved/Reviewed) of a document. Would it be possible to have the same features even in Solution Manager?
    5) What all document types does Solution Manager recognize?.
    I think the Lotus notes documents can be converted to 'Word' format and then put in Solution Manager. Besides this, is there any other common format which is recognized by both the tools?
    6) Standard SAP Solution manager does not provide indexed search. So, in order to retrieve a document later what indexing nomenclature/guidelines do you recommend?
    Has anyone done/faced with this kind of requirement. The idea now is to use Solution manager as a document management system. The efforts/process/timelines information if already known would be of great help to start with for us....
    Could you also provide the trade offs b/n Solution Manager and SAP knowledge warehouse (KW)?
    Hoping for some replies ...

    we also had the same requirement to migration from LN to SolMan Documentation base but there is no such tool (yet?)
    What you can do you can migrate from any ARIS like platform to SolMan:
    http://en.sap.info/ids-scheer-announces-migration-program-to-aris-platform/4058
    You do have versioning in SolMan and you can upload any kind of document via SOLAR01
    regarding the indexing you can either use SAP SES or connect TREX, this is documented in the customizing (SPRO)
    TREX will also be the prerequisite to make use of KM in SolMan
    nesimi

  • Lotus Notes. Which one for Mavericks?

    Hello,
    I have upgraded to Mavericks.
    I used Lotus Notes, for work email, replicating my company database.
    Since the upgrade Notes 7.02 started crashing everytime I was trying to download new emails or to replicate the database.
    New attemps to install different versions failed (8.5 or 9.0 social).
    Is there any version of Lotus Notes that is compatible with Mavericks?
    Thanks a lot.

    Did you remember to rename or move Notes.app? It conflicts with Apple's Notes.app. I used to use Lotus for work but they also provided standard IMAP and LDAP interfaces that worked great with standard Apple Mail, Calendar, and Contacts apps. Notes uses Java so you will have to have the latest and greatest Java available.
    We have Gmail now so I can't help much more. If it is any consolation, Lotus worked better Gmail.

  • Setting scheduled Mail on BO with Lotus Notes SMTP Server

    Hi,
    I'm trying to setup a scheduled email but the SMTP Server is using Lotus Notes.
    When I try to setup I've got error stating that smtp 504 - command parameter not implemented.
    Is there any specific settings for scheduled email using Lotus Notes SMTP Server?
    Regards,
    Budi Setiawan

    Welcome to the forums.
    In the most general of terms, smtp is smtp, imap is imap, pop is pop, still ugly, and best avoided in favor of imap, and they interoperate.
    As for your case, you face some choices...
    ...either run your local group's mail on your Mac OS X Server (which you apparently cannot do here?) and set up the corporate DNS and configure the corporate employee directory (LDAP, Microsoft GAL, whatever) to forward mail to your mail server...
    ...or you need to configure your mail clients to use your organization's smtp/pop/imap server running within your target environment (and get the smtp/pop/imap support enabled, if it's not already enabled)...
    ...or you need to figure out how to break this protocol and mail server and version deadlock with your management...
    Lotus/Domino has had SMTP/POP/IMAP services for a decade or so, and there are various postings around the 'net reporting successful connections from Apple mail into Lotus/Domino servers, so your local Mac OS X clients should connect into most any Domino server around, if it's enabled for any of the "standard" mail clients that are in use, including Apple's Mail.app, Mozilla's Thunderbird and Seahorse, Microsoft's Outlook Express, etc.

  • Secure Search Lotus Notes and NTFS?

    How can I do secure search with Lotus Notes and NTFS sources? When configuring Identity Management, I have to choose between Lotus and MSAD. And user names are different between both directories. Any chance to secure both sources with one query?

    If user names are different on the two systems, you can't combine them in a single SES instance. You only log on once to SES, so the system wouldn't be able to tell which username to use for each system.
    However, this can be done via the federation architecture. You need two SES instances, one connected to AD and one connected to the Lotus Notes native identity plugin.
    You will then need to have an attribute in your AD which contains the Notes username. Let's call it LNNAME.
    You would then create a federated source on the instance connected to AD, which collects results from the instance connected to the Notes plugin.
    When you define your federated source, there is a field called "Search User Attribute". This is the name of the AD attribute which contains the Notes username - LNNAME in our example.
    SES then authenticates the user against AD. It then runs federated queries against the Notes system, asserting that the logged in user is a valid Notes user with a certain username, which it gets from the LNNAME attribute.
    Naturally this requires trust between the systems. The Notes system has to trust the AD to correctly authenticate and identify the user - even though the Notes password will never be given.

  • Intergate Lotus Notes with SAP

    Dear All,
    I had do mail configuration in SAP and its working.
    But i want to import all my Lotus Notes contact in SAP. is it possible? How?
    OR can I Intergate Lotus  mailing system with SAP?
    Regards,
    Nisit

    Nisith,
    The approaches that are currently available to integrate SAP R/3 and Lotus Notes are:
    Lotus Connectors:
    Lotus Connectors are system files that are developed using common object model interface, known as Lotus Connector API. They provide optimized access to the enterprise data from Domino. These connectors are installed on the Web Application Server platform of SAP and are used to connect to and to transfer data from the enterprise servers and other enterprise platforms. This Lotus Connector, when used with enterprise integration tools, facilitates to integrate SAP application logic with Domino applications. The Connector was developed using SAP's Remote Function Call Software Development Kit (RFCSDK) and enables execution of any SAP Remote Function Call (RFC) that is remotely callable, all BAPIs and Transactions using Batch Data Input. Using the Lotus Connector for SAP technology ensures that data transfers and queries are processed through the SAP application layer, preserving the business logic and data validations contained in SAP Remote Function Call and transaction interfaces, which comprised of SAP processes. Therefore, reading and writing SAP data is always performed through the application layer and not by directly accessing back-end database tables and by using Lotus Connectors all the business rules provided by RFCu2019s and SAP Transactions are maintained.
    Domino Mail Transfer Agent for R/3:
    A server-based add-ins, Domino MTA is used in bi-directional message transfer amid SAP R/3 and Notes, which leads to the transformation of Dominou2019s inbox into a universal inbox for both Domino and SAP. This tool is used to send messages to and from SAP R/3 to notes. It enables the users to send or receive mails, faxes and also disseminate the data from R/3 system to the notes mailbox. Hence, the users are required to check a common interface for reading the messages from both SAP R/3 and Lotus Notes. The Mail transfer Agent along with providing full attachment support provides users with the rich text support, facilitating R/3 mail users using any other application like Microsoft word as their e-mail editors. In addition, R/3 MTA provides all the transactional support that is required by the users. The users to make sure that the data being transferred from R/3 is properly routed to Domino can also use this support. MTA even enables the users to keep a track of all the messages that are sent or received from R/3 by tracking them in a Notes log file. As mentioned above, the Domino MTA uses add-ins. These add-ins are object client to send mail from Domino to R/3 and object server to receive mail from R/3.
    Lotus Enterprise Integrators (LEI):
    This tool is used to transfer the data both ways between SAP R/3 and Domino applications. LEI are the quickest way to ensure transfer of data and that too without following the tedious task of writing long lines of codes. Also, it facilitates this transfer by taking one end as a source and the other as a target. In this, the data transfer of each type utilizes a different connector such as Oracle connector and Notes connector. These connectors are used in both LEI and Domino Enterprise Connectivity Services (DECS) to ensure bi-directional access of notes and web applications of R/3 data from a Domino server.
    Hope this helps you.
    Rgds
    manish

Maybe you are looking for

  • (Blob Column) Image in email

    Hi All, I am using Oracle 11g. Can anyone please provide any link or code of adding an Image which is stored in the DB Blob column of a table to an Email. Email is being sent through Pl/sql procedure written for it. Please let me know if you need any

  • How to control read/unread status of email

    I would like to be able to simply view (in the preview pane) emails without them being marked as 'read'. Is there a way to do this in the Mac mail client (Snow Leopard)? When I actually open the email, it would then be marked as 'read'. Outlook for W

  • Fixed assets depreciation; Message no. AU 390

    Dear Sirs, recently when we're accessing a fixed asset by using the fixed assets browser ( AW01N) we’re getting the following message: “<i>Values for Ordinary deprec. have changed in dep. area 40 in fiscal year 2007</i>”. By following the message’s s

  • How can I guarantee the consistency of tracsaction

    Hi, We have a product called SMS(Subscribe Management System). It is a CCB(Customer Care Billing) System used in DVB domain, and contains two server: billing server and customer server. Billing server is written using C++, Customer server is written

  • I am getting Payroll error in "Customizing Error in Work Schedule Rule"

    Hi, Iam using SAP HR ECC6.0. While running payroll i am facing an error saying "Customizing Error in Work Schedule Rule". I checked all my work schedule related configuration everything is correct. I have checked the Manual Work Schedule Creation. My