You are viewing limited content. For full access, please sign in.

Question

Question

Mobile Config - What is a license?

asked on September 25, 2019

Mobile Config has a section for entering your STS url. It does not say why or what it is for but assuming it is important, since we use STS, I enter the site in there. It says:

"The Directory Server STS does not match the one in license."

Then secretly after I leave the configuration, it removes what I entered and saved.

What is a license?

0 0

Answer

APPROVED ANSWER
replied on October 2, 2019

Ah support gave me a fix. I just have to download the following 2 DLLs manually and add them to the bin folder, then it allows me to save and doesn't warn me about any matching issues. 

https://support.laserfiche.com/kb/1014081/list-of-changes-for-the-laserfiche-mobile-server-10-4-1-hotfix-1014081

0 0

Replies

replied on September 26, 2019

I encountered the same warning recently when configuring Web Client.  I had a laserfiche engineer on site for an audit and was told to disregard the warning.

0 0
replied on September 26, 2019

I am not too concerned with the warning, but I am concerned with my changes being removed after successfully saving and leaving the page every time. I know that STS is working and we already have the STS site specified in the Forms config.

I just think the mobile app has been acting strange and is unusable in this environment so I am looking to anything for an issue.

1 0
replied on September 27, 2019

Chad,

You only need to configure STS (Secure Token Service) if any of the repository or forms servers you configure for mobile access uses SSO (Single Sign-On). There's an SSO checkbox for the servers on the mobile configuration page.
 

The mobile server needs a license and it's usually downloaded from LFDS (the Laserfiche Directory Server).  To avoid some configuration errors in version 10.4 the Mobile Server enforces it runs on license (.licx file) issued by the same LFDS server you have configured (otherwise authentication could fail). However the code check had a glitch and in some scenarios (where STS and LFDS are separate, one outside one inside the network) it incorrectly prevents you from configuring STS. This is what you seem to be running into. This has been fixed in version 10.4.1.
If you are running on an earlier (103.x or older) or 10.4.1 you should not have this problem, only in 10.4.0.
If this is not true for you please contact technical support. If you are running on 10.4.0 you can downgrade to 10.3.x or upgrade to 10..4.1

 

 

0 0
replied on September 27, 2019

I know we are using STS for forms and we have it configured in the forms configuration so that we can have non-ldap participant users.

We have not setup Single Sign On yet - which is a feature to allow cross credential sharing between Forms and Web Client.

We are on 10.4.1 of Mobile and 10.4.2 of DS.

They only have one DS server and all products are licensed by the same DS server.

I guess going back to the original question, what does the directory server's address does not match mean? Server's have many things called addresses, from IP, Machine Name, DN, etc. These are just means to find the server, but usually are not being matched to anything.

 

0 0
replied on October 1, 2019 Show version history

To clear up some confusion, STS is the service you set up to achieve SSO. If you log in using STS, you are using SSO (aka LFDS authentication).

When it comes to the error you are seeing, this means the STS URL you entered does not match the LFDS URL in the Mobile Server license (which LFDS has generated). This can be a legitimate configuration if your STS instance is on a different machine than the one running LFDS.

0 0
replied on October 1, 2019

Ok this helps get me on the right path. I am providing the URL in the field where I should be entering it, the place where it says enter your STS URL here. I guess I also need to provide it into another field in the license to make sure it matches, but where do I go to do this?

I feel like, if your always matching information, why not just ask for it in one spot?

0 0
replied on October 1, 2019

You cannot manually alter the URL in the license. If you want to check to see which URL the license is using, you can open C:\Program Files\Laserfiche\Mobile\lf.licx and look for the "LicenseServer" value.

Is your STS instance hosted on a different machine than the LicenseServer URL?

0 0
replied on October 1, 2019

The LicenseServer attribute is the machine name of the Directory Server host OS. Not a URL.

Are you sure that is the right attribute?

STS is hosted on the same host OS as Directory Server.

Maybe this is the problem, the LicenseServer needs to show a URL, not a machine name. How do I fix this? Where did this configuration come from?

0 0
replied on October 1, 2019

I recommend opening a case with Support for this for troubleshooting tips.

0 0
replied on October 1, 2019

Ok I can try that, but this might be too technical

0 0
replied on October 1, 2019 Show version history

As a note, it is expected that the attribute in the license file is a host name: the mobile configuration URL validation checks that the hostname in the license file matches the machine name within the web STS url (it's not trying to compare the whole URL to the host name directly).

0 0
replied on October 2, 2019

Ok, so maybe that is not the problem. The URL contains no part of a host name though. Host names of local servers and public websites are two completely different things.

A host name is a way to internally resolve a single local device on your personal network, a website is a public method of resolving an entire network at it's entry point.

0 0
APPROVED ANSWER
replied on October 2, 2019

Ah support gave me a fix. I just have to download the following 2 DLLs manually and add them to the bin folder, then it allows me to save and doesn't warn me about any matching issues. 

https://support.laserfiche.com/kb/1014081/list-of-changes-for-the-laserfiche-mobile-server-10-4-1-hotfix-1014081

0 0
replied on October 25, 2019

Hi,

 

I ignore the warning and save the changes. SSO works in Web Client.

Regards,

1 0
You are not allowed to follow up in this post.

Sign in to reply to this post.