13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Set Up Active Directory Permissions<br />

5 Set Up Active Directory Permissions<br />

5.1 Permissions Needed by the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong><br />

The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> runs inside Steel-Belted RADIUS, which runs as a Service. The Service runs<br />

as the 'Local System' account rather than as a named user account. There<strong>for</strong>e, when<br />

connecting to Active Directory, the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> connects as the computer account, not a user<br />

account. The permissions that it has within Active Directory are the permissions of the<br />

computer account.<br />

An important exception to this occurs if you install the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> onto a Domain Controller.<br />

Any Service running as 'Local System' on a Domain Controller has all possible permissions to<br />

that Domain. <strong>In</strong> this case, no additional setup of permissions is required. There<strong>for</strong>e, the rest of<br />

this section applies to the case where the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> is not on the Domain Controller.<br />

During installation, the computer account is added to the built-in 'RAS and IAS Servers' group<br />

in the Domain, as it will require the permissions assigned by default to this group.<br />

<strong>In</strong> order to function correctly, the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> requires the following permissions in Active<br />

Directory, that are not granted to 'RAS and IAS Servers' by default:<br />

Read access to the <strong>Digipass</strong> Configuration Container<br />

Read access to all User accounts (or at least, all who might need to be authenticated by<br />

the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>)<br />

Write access to the new attributes that are added to the User class <strong>for</strong> <strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong><br />

<strong>for</strong> <strong>SBR</strong> (these are in the auxiliary class vasco-UserExt)<br />

Full control over all <strong>Digipass</strong> (vasco-DPToken) and <strong>Digipass</strong> Application (vasco-<br />

DPApplication) objects<br />

Create and delete permission <strong>for</strong> <strong>Digipass</strong> (vasco-DPToken) objects in Organizational<br />

Units and containers (specifically the <strong>Digipass</strong>-Pool and Users containers)<br />

5.1.1 Giving Permissions to the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong><br />

During installation, these additional permissions are granted to the 'RAS and IAS Servers'<br />

group automatically.<br />

There is also a manual way to grant these permissions, by running the 'setupaccess' command<br />

at the command prompt:<br />

dpadadmin.exe setupaccess -group “RAS and IAS Servers”<br />

See 2.5 DPADadmin Utility <strong>for</strong> more in<strong>for</strong>mation on the setupaccess command.<br />

As mentioned above, this is not necessary if the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> is installed onto a Domain<br />

Controller.<br />

© 2006 VASCO Data Security <strong>In</strong>c. 62

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!