13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Table of Contents<br />

Table of Contents<br />

1 <strong>In</strong>troduction........................................................................................................ 11<br />

1.1 Available Guides......................................................................................................... 11<br />

1.2 System Requirements.................................................................................................11<br />

1.2.1 Requirements Specific to Active Directory................................................................. 11<br />

1.2.2 Requirements Specific to ODBC Database................................................................. 12<br />

1.3 Software Components................................................................................................ 13<br />

1.3.1 Required Components........................................................................................... 13<br />

1.3.2 Optional Components............................................................................................ 14<br />

1.3.3 Extra Utilities....................................................................................................... 15<br />

2 Active Directory Schema......................................................................................16<br />

2.1 Schema Extensions.....................................................................................................16<br />

2.1.1 Added Object Classes............................................................................................ 16<br />

2.1.2 Added Attributes.................................................................................................. 16<br />

2.1.3 Added Permission Property Sets.............................................................................. 19<br />

2.2 Active Directory Auditing............................................................................................20<br />

2.3 Custom Search Options...............................................................................................21<br />

2.3.1 Saved Queries...................................................................................................... 21<br />

2.3.2 Using the Custom Search <strong>for</strong> <strong>Digipass</strong>...................................................................... 22<br />

2.3.3 Using the Custom Search <strong>for</strong> Users......................................................................... 23<br />

2.4 Active Directory Replication Issues............................................................................ 25<br />

2.4.1 Old Data Used After Attribute Modified..................................................................... 25<br />

2.4.1.1 Single <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> using more than one Domain Controller....................................................25<br />

2.4.1.2 <strong>Administrator</strong> and <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> using different Domain Controllers...........................................26<br />

2.4.1.3 Multiple <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>s Using Different Domain Controllers.......................................................26<br />

2.4.1.4 Two <strong>Administrator</strong>s Modifying the Same Attribute................................................................. 26<br />

2.4.2 Old Data Used Overwrites New Data........................................................................ 27<br />

2.4.3 Factors Affecting Replication Issues......................................................................... 27<br />

2.4.4 Solutions and Mitigations....................................................................................... 28<br />

2.4.4.1 <strong>Digipass</strong> Cache.................................................................................................................28<br />

2.4.4.2 Identification Threshold Setting.......................................................................................... 29<br />

2.4.4.3 <strong>Administrator</strong> Connection Strategy......................................................................................29<br />

2.4.4.4 Set a Preferred Server.......................................................................................................30<br />

2.4.4.5 Use Preferred Server Only Option....................................................................................... 31<br />

2.5 DPADadmin Utility...................................................................................................... 32<br />

2.5.1 Extend Active Directory Schema............................................................................. 32<br />

2.5.2 Set Up <strong>Digipass</strong> Containers in Domain..................................................................... 34<br />

2.5.2.1 Prerequisite <strong>In</strong><strong>for</strong>mation.................................................................................................... 34<br />

2.5.2.2 Set Up <strong>Digipass</strong> Configuration Container..............................................................................34<br />

2.5.2.3 Command Syntax............................................................................................................. 34<br />

2.5.3 Assign <strong>Digipass</strong> Permissions to a Group................................................................... 34<br />

2.5.3.1 Pre-requisites...................................................................................................................34<br />

2.5.3.2 Command Syntax............................................................................................................. 35<br />

2.5.4 Upgrade RADIUS Profile <strong>In</strong><strong>for</strong>mation....................................................................... 35<br />

2.5.5 Delete all <strong>Digipass</strong>-Related Data from Active Directory............................................... 36<br />

2.5.5.1 Run Delete Script on a Domain...........................................................................................36<br />

3 ODBC Database....................................................................................................38<br />

3.1 Database Support....................................................................................................... 38<br />

3.1.1 Unicode Support................................................................................................... 38<br />

© 2006 VASCO Data Security <strong>In</strong>c. 3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!