13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Active Directory Schema<br />

2.4.1.2 <strong>Administrator</strong> and <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> using different Domain Controllers<br />

The administrator may not be connected to the same Domain Controller (via the<br />

Administration <strong>In</strong>terfaces) as the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>.<br />

Example<br />

An administrator changes a User's Server PIN through the Active Directory Users and<br />

Computers extension, which is connected to DC-01. The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> connects to DC-03. The<br />

User attempts a login using the new PIN, which fails because DC-03 is not yet aware of the<br />

change of Server PIN.<br />

Time DC-01 DC-03<br />

9:02 Replication occurs<br />

9:03 <strong>Administrator</strong> changes a User's Server PIN<br />

from 1234 to 9876.<br />

9:04 User attempts to log in using new PIN<br />

(9876) and the login fails.<br />

9:05 Replication occurs<br />

<strong>Digipass</strong> record changes are replicated between DC-01 and DC-03.<br />

The example timeline above shows the sequence of events.<br />

2.4.1.3 Multiple <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>s Using Different Domain Controllers<br />

Multiple <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>s may connect to different Domain Controllers in a domain or site.<br />

Example<br />

A User changes their own PIN during a login through one <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> which connects to DC-<br />

01. The server on which the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> is installed becomes unavailable, and the User<br />

attempts another login via the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> on a backup server, which connects to DC-02.<br />

The login fails because DC-02 is not yet aware of the change of Server PIN.<br />

Time DC-01 DC-02<br />

11:54 Replication occurs<br />

11:55 User changes their Server PIN from 1234 to<br />

9876 during login.<br />

The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> records the PIN change in<br />

the <strong>Digipass</strong> record.<br />

11:57 User attempts to log in using new PIN<br />

(9876) and the login fails.<br />

11:59 Replication occurs<br />

<strong>Digipass</strong> record changes are replicated between DC-01 and DC-02.<br />

The example timeline above shows the sequence of events.<br />

2.4.1.4 Two <strong>Administrator</strong>s Modifying the Same Attribute<br />

Two administrators attempt to modify the same attribute on a single User account or <strong>Digipass</strong><br />

record within the same replication interval. The later modification will overwrite the earlier<br />

when replication occurs.<br />

© 2006 VASCO Data Security <strong>In</strong>c. 26

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!