13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Active Directory Schema<br />

2.4.2 Old Data Used Overwrites New Data<br />

The problems above are exacerbated when the old in<strong>for</strong>mation used on the second Domain<br />

Controller is updated based on the old in<strong>for</strong>mation. As the updated record on the second<br />

Domain Controller now has a later modification date, the end result is that the changed<br />

in<strong>for</strong>mation on the first Domain Controller is overwritten incorrectly.<br />

Example<br />

An administrator connects to DC-01 and sets a User's PIN from '1234' to '9876'. The User<br />

logs in through the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>, which connects to DC-02. The User enters the new Server<br />

PIN and his One Time Password. However, the PIN set on DC-01 has not yet been replicated<br />

to DC-02, so because the PIN entered does not match the old PIN still recorded in the<br />

<strong>Digipass</strong> record on DC-02, the login fails.<br />

Because the Policy setting of Identification Threshold is in use, his login failure is written<br />

back to the <strong>Digipass</strong> record. When replication occurs, the <strong>Digipass</strong> record on DC-02 has the<br />

latest modification date – and is copied to DC-01, wiping out the original PIN setting made<br />

by the administrator. Both DC-01 and DC-02 now consider '1234' to be the correct Server<br />

PIN <strong>for</strong> the <strong>Digipass</strong>.<br />

Time DC-01 DC-02<br />

10:45 Replication<br />

10:46 <strong>Administrator</strong> changes User's PIN from 9876<br />

to 1234.<br />

10:48 User login (with new PIN of 1234) fails.<br />

<strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> writes failure in<strong>for</strong>mation to<br />

<strong>Digipass</strong> record.<br />

10:50 Replication<br />

Active Directory finds last instance of the <strong>Digipass</strong> blob having been modified.<br />

Active Directory overwrites DC-01 <strong>Digipass</strong> record with DC-02 <strong>Digipass</strong> record.<br />

The example timeline above shows how the problem can occur.<br />

The problem shown in the example above may also occur in a Force PIN Change set by an<br />

administrator.<br />

2.4.3 Factors Affecting Replication Issues<br />

A number of factors determine the likelihood and severity of the Active Directory issues<br />

described:<br />

Redundancy and load-balancing settings <strong>for</strong> the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong><br />

There are a number of <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> configuration settings which may affect replication issues:<br />

Preferred Server<br />

The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> will attempt to connect to the named Domain Controller, rather than<br />

simply polling the domain <strong>for</strong> an available Domain Controller.<br />

Preferred Server Only<br />

The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> may be restricted to connecting only to the Domain Controller named in<br />

the above setting. If this is enabled, the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> will not switch to any other Domain<br />

Controller, so it will never retrieve data older than its own.<br />

Max. Bind Lifetime<br />

The maximum bind lifetime controls how long the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> will stay connected to a<br />

Domain Controller be<strong>for</strong>e polling the domain <strong>for</strong> a Domain Controller connection.<br />

© 2006 VASCO Data Security <strong>In</strong>c. 27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!