Identity Manager Password Synchronization


In addition to the synchronization of data between disparate systems such as eDirectory, Active Directory, and NT domains, Identity Manager Bundle Edition also enables you to synchronize passwords between these systems. Identity Manager Password Synchronization for Windows, known as PasswordSync, allows passwords to be transparently and securely synchronized between eDirectory and the Active Directory/NT domains for which you have Identity Manager drivers configured.

PasswordSync uses filters and agents to capture changes to passwords and securely pass those changes to included systems. Identity Manager is capable of understanding object mappings across systems so that each user object is associated with the proper object in every other system. Because of this, synchronizing passwords across the systems becomes much easier.

The specifics of how PasswordSync is installed depends on the systems involved. For example, because Microsoft clients forward password change requests to their respective Domain Controllers for processing, PasswordSync Filters are installed on all Domain Controllers in Active Directory and NT environments. On the other hand, because Novell clients never send passwords across the network, PasswordSync filters for eDirectory are installed on the client workstation and are part of the Novell clients that ship with OES NetWare.

Unfortunately, because password synchronization with Identity Manager relies on PasswordSync filters and agents communicating the changes throughout the environment, if a password is synchronized through an unsupported mechanism, the synchronization will not occur. One example of this is an LDAP client such as Novell eGuide. If you use an LDAP client to change your eDirectory password, the change will not be synchronized to your Active Directory and/or NT Domain environments because the PasswordSync filters are never involved in the process. Similarly, if a password is changed from a non-Windows environment, the change will not be synchronized.

Bottom line here: Use PasswordSync if you can be confident that password changes will only occur in one of the Windows methods supported by PasswordSync. For example:

  • Workstation running the Novell client

  • Workstation not running the Novell client

  • Windows server or workstation running Microsoft Management Console

  • Windows workstation or server running ConsoleOne

  • Workstation or server running Novell iManager

For more information on configuring and using PasswordSync, see the OES online documentation.



    NovellR Open Enterprise Server Administrator's Handbook SUSE LINUX Edition
    Novell Open Enterprise Server Administrators Handbook, SUSE LINUX Edition
    ISBN: 067232749X
    EAN: 2147483647
    Year: 2005
    Pages: 178

    flylib.com © 2008-2017.
    If you may any questions please contact us: flylib@qtcs.net