68
Identity Manager 3.6.1 Password Management Guide
no
vd
ocx
(e
n)
13
Ma
y 20
09
Verify that the Identity Vault object contains the correct value in the Internet EMail Address
attribute.
In the Notification Configuration task, check the SMTP server and the e-mail template. See
Section 5, “Configuring E-Mail Notification,” on page 25
.
E-mail notifications are non-invasive. They do not affect the processing of the XML document that
triggered the e-mail. If they fail, they are not retried unless the operation itself is retried. Debug
messages for e-mail notifications are written to the trace file.
Error When Using Check Password Status
The Check Password Status task in iManager causes the driver to be perform a Check Object
Password action.
Make sure that the connected system supports checking passwords. See
Section 3, “Connected
System Support for Password Synchronization,” on page 15
.
This operation is not available through iManager if the driver manifest does not indicate that
the connected system supports password-check capability.
If the Check Object Password action returns -603, the Identity Vault object does not contain an
nspmDistributionPassword attribute. Check the Identity Manager attribute filter, and the
Synchronize Universal to Distribution
option within the password policy.
If the Check Object Password action returns
Not Synchronized
, verify that the driver
configuration contains the appropriate Identity Manager password synchronization policies.
Compare the password policy in the Identity Vault with any password policies enforced by the
connected system, to make sure they are compatible.
The Check Object Password action checks the Distribution password. If the Distribution
password is not being updated, Check Object Password might not report that passwords are
synchronized
Helpful DSTrace Commands
+DXML
: To view Identity Manager rule processing and potential error messages.
+DVRS
: To view Identity Manager driver messages.
+AUTH
: To view NDS password modifications.
+DCLN
: To view NDS DCLient messages.
A.5 Scenario 5: Synchronizing Application
Passwords to the Simple Password
This scenario is a specialized use of password synchronization features. Using Identity Manager and
NMAS, you can take a password from a connected system and synchronize it directly to the Identity
Vault Simple Password. If the connected system provides only hashed passwords, you can
synchronize them to the Simple Password without reversing the hash. Then, other applications can
authenticate to the Identity Vault by using the same clear text or hashed password through LDAP or
the Novell Client, with NMAS components configured to use the Simple Password as the login
method.
Summary of Contents for IDENTITY MANAGER 3.6.1 - PASSWORD MANAGEMENT
Page 4: ...4 Identity Manager 3 6 1 Password Management Guide novdocx en 13 May 2009...
Page 8: ...8 Identity Manager 3 6 1 Password Management Guide novdocx en 13 May 2009...
Page 18: ...18 Identity Manager 3 6 1 Password Management Guide novdocx en 13 May 2009...
Page 24: ...24 Identity Manager 3 6 1 Password Management Guide novdocx en 13 May 2009...
Page 33: ...Configuring E Mail Notification 33 novdocx en 13 May 2009 7 Scroll to the Actions section...
Page 38: ...38 Identity Manager 3 6 1 Password Management Guide novdocx en 13 May 2009...
Page 78: ...78 Identity Manager 3 6 1 Password Management Guide novdocx en 13 May 2009...