Configuring Local Authentication - Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual

Identity server guide
Table of Contents

Advertisement

Configuring Local Authentication

2
To guard against unauthorized access, Access Manager supports a number of ways for users to
authenticate. These include name/password, RADIUS token-based authentication, and X.509 digital
certificates. You configure authentication at the Identity Server by creating authentication contracts
that the components of Access Manager (such as an Access Gateway) can use to protect a resource.
Figure 2-1
illustrates the components of a contract:
Local Authentication
Figure 2-1
User Store
Classes
User stores: The user directories to which users authenticate on the back end. You set up your
user store when creating the Identity Server cluster configuration. See
"Configuring Identity User Stores," on page
Classes: The code (a Java class) that implements a particular authentication type (name/
password, RADIUS, and X.509) or means of obtaining credentials. Classes specify how the
Identity Server requests authentication information, and what it should do to validate those
credentials. See
Section 2.2, "Creating Authentication Classes," on page
Methods: The pairing of an authentication class with one or more user stores, and whether the
method identifies a user. See
Contracts: The basic unit of authentication. Contracts can be local (executed at the server) or
external (satisfied by another Identity Server). Contracts are identified by a unique URI that can
be used by Access Gateways and agents to protect resources. Contracts are comprised of one or
more authentication methods used to uniquely identify a user. You can associate multiple
methods with one contract. See
page
94.
This section also explains how to configure authentication when the user store supports password
expiration services, when a request allows any contract to be used for authentication, and when you
want to control authenticating directly to the Identity Server.
Section 2.5, "Using a Password Expiration Service," on page 96
Section 2.6, "Specifying Authentication Defaults," on page 98
Section 2.7, "Managing Direct Access to the Identity Server," on page 99
A
B
Methods
76.
Section 2.3, "Configuring Authentication Methods," on page
Section 2.4, "Configuring Authentication Contracts," on
Contracts
URI
URI
A
B
Local
External
Section 2.1,
88.
Configuring Local Authentication
2
92.
75

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER and is the answer not in the manual?

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents