aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
User Authentication Process
2.
Secondly, the user account needs to be located for authentication.
With an FqDN, sufficient information is already provided to find the user account for authentication.
With an RDN, the principal name and password are used to bind and search for the user account. Searching
starts from the base DN, e.g. 'Administration.Mechelen.CORP', specified in the aXsGUARD Identifier
Configuration Tool.
3.
Once a user account is located, binding (i.e. back-end authentication), can be completed.
If the bind on the back-end server succeeds, the user authentication on the aXsGUARD Identifier is
successful.
If the bind on the back-end server fails, the authentication on the aXsGUARD Identifier fails.
Limitations
There are some limitations to Novell e-Directory back-end authentication:
Windows 2000 is not supported. The version of Windows used with LDAP back-end authentication must be
Windows 2003 or higher.
The version of Novell e-Directory used for LDAP back-end authentication must be version 8.7 or higher.
The base DN, principal name and password need to be specified in the Configuration Tool (see section
the administration interfaces) for binding (see step 2 above) to search for a RDN user account. The base DN
serves as the starting point for searches in the LDAP hierarchy.
Only one set of principal name, password and base DN (for binding) can be added in the aXsGUARD Identifier
Configuration Tool. This restricts authentication to a single back-end server for Relative Distinguished Names
(RDN). Authentication for Fully Qualified Distinguished Names (FqDN) can be supported by multiple back-end
servers.
Note:
1) A single domain can have multiple back-end servers, because they can be operating in fail-
over (or replication) strategy (see section
2) If there is no back-end server for a specific domain, a back-end server with no domain
specified is used (see section
3) aXsGUARD Identifier only supports SASL.Digest-MD5 binding as the client authentication
mechanism for binding with the supported back-end authentication servers.
Caution:
With Dynamic User Registration, if a user attempts to authenticate at different times with an RDN
and FqDN, two user accounts are created for a single user.
©
2009 VASCO Data Security
50