8 Novell Nsure Identity Manager 2.0.1 Administration Guide
Novell Confidential Manual (ENU) 21 December 2004
Filters You Install on the Connected System to Capture Passwords . . . . . . . . . . . . . . . . . . . . . . . . 164
Password Policies You Create for Your Users. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
NMAS Login Methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
Handling Sensitive Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
Use SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
Secure Access to eDirectory and to Identity Manager objects. . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
Review the Security Considerations for Password Management Features . . . . . . . . . . . . . . . . . . . . . 166
Create Strong Password Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 167
Secure Connected Systems That Participate in Password Synchronization . . . . . . . . . . . . . . . . . . . . 167
Follow Industry Best Practices for Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168
Use Nsure Audit to Track Changes to Sensitive Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168
Preparing to Use Identity Manager Password Synchronization and Universal Password. . . . . . . . . . . . . . . . 170
Switching Users from NDS Password to Universal Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170
Changing Passwords Using the iManager Self-Service Console or Novell Client. . . . . . . . . . . . . . . . . . 170
Preparing to Use Universal Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
Replica Planning and Password Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172
Setting Up E-Mail Notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172
New Driver Configuration and Identity Manager Password Synchronization . . . . . . . . . . . . . . . . . . . . . . 172
Upgrading Password Synchronization 1.0 to Identity Manager Password Synchronization . . . . . . . . . . . . . . 174
Upgrading Existing Driver Configurations to Support Identity Manager Password Synchronization . . . . . . . . . . 174
Implementing Password Synchronization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
Overview of Identity Manager Relationship to NMAS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
Scenario 1: eDirectory to eDirectory Password Synchronization Using NDS Password . . . . . . . . . . . . . . 181
Scenario 2: Synchronizing Universal Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183
Scenario 3: Synchronizing eDirectory and Connected Systems with Identity Manager Updating the Distribution
Password. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 193
Scenario 4: Tunneling — Synchronizing Connected Systems but not eDirectory, with Identity Manager Updating the
Distribution Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201
Scenario 5: Synchronizing Application Passwords to the Simple Password . . . . . . . . . . . . . . . . . . . . 206
Setting Up Password Filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 210
Setting Up Password Synchronization Filters for Active Directory and NT Domain . . . . . . . . . . . . . . . . . 210
Setting Up Password Synchronization Filters for NIS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 210
Managing Password Synchronization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211
Setting the Flow of Passwords Across Systems. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211
Enforcing Password Policies on Connected Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
Keeping the eDirectory Password Separate from the Synchronized Password . . . . . . . . . . . . . . . . . . . 214
Checking the Password Synchronization Status for a User . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
Configuring E-Mail Notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
Setting Up the SMTP Server To Send E-Mail Notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
Setting Up E-Mail Templates for Notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
Providing SMTP Authentication Information in Driver Policies. . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
Adding Your Own Replacement Tags to E-Mail Notification Templates. . . . . . . . . . . . . . . . . . . . . . . 219
Sending E-Mail Notifications to the Administrator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 226
Localizing E-Mail Notification Templates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 226
Troubleshooting Password Synchronization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 227
11 Using Role-Based Entitlements 229
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229
Scenario: Setting Up a Business Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230
How Role-Based Entitlements Work . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 231
Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Creating an Entitlements Service Driver Object and Configuring Connected System Drivers . . . . . . . . . . . . . 232
Creating a Driver Object for the Entitlements Driver. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Configuring Drivers to Use Entitlement Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 233
Creating Entitlement Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 234