3.5 Configuring Access Manager for NESCM
To use a smart card with Access Manager, you need to configure Access Manager to use the
eDirectory server where you have installed the Novell Enhanced Smart Card Login Method for
NMAS (NESCM). You then need to create a contract that knows how to prompt the user for the
smart card credentials. The last task is to assign this contract to the protected resources that you want
protected with a smart card. The following sections describe prerequisites and the tasks:
Section 3.5.1, "Prerequisites," on page 125
Section 3.5.2, "Creating a User Store," on page 125
Section 3.5.3, "Creating a Contract for the Smart Card," on page 127
Section 3.5.4, "Assigning the NESCM Contract to a Protected Resource," on page 131
Section 3.5.5, "Verifying the User's Experience," on page 131
Section 3.5.6, "Troubleshooting," on page 132
3.5.1 Prerequisites
Make sure you can authenticate to the eDirectory server using the smart card from a
workstation.
The NESCM method needs to be installed on the eDirectory server and the workstation.
See
"Installing the Method" (http://www.novell.com/documentation/iasclient30x/
nescm_install/data/b7gx5la.html)
and Administration Guide (http://www.novell.com/documentation/iasclient30x/
nescm_install/data/bookinfo.html).
The NESCM method needs to be configured. See
www.novell.com/documentation/iasclient30x/nescm_install/data/b7tf2gi.html)
Novell Enhanced Smart Card Method Installation and Administration Guide (http://
www.novell.com/documentation/iasclient30x/nescm_install/data/bookinfo.html).
Provision your smart card according to your company policy.
Make sure you have a basic Access Gateway configuration with a protected resource that you
want to protect with a smart card. For more information, see the
SP1 Installation Guide
3.5.2 Creating a User Store
The Identity Server must be configured to use the eDirectory replica where you have installed the
NESCM server method.
If you have already configured the Identity Server to use this replica, skip this section and
continue with
Section 3.5.3, "Creating a Contract for the Smart Card," on page
If your Identity Server is using a different user store, you need to configure the Identity Server.
To configure the Identity Server for the eDirectory replica that has the NESCM method:
1 In the Administration Console, click Devices > Identity Servers > Edit > Local> User Stores >
New.
in the
Novell Enhanced Smart Card Method Installation
and the
Novell Access Manager 3.1 SP1 Setup
Configuring Advanced Local Authentication Procedures 125
"Configuring the Server" (http://
Novell Access Manager 3.1
Guide.
127.
in the
Need help?
Do you have a question about the ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER and is the answer not in the manual?