4.1 About Credentials

After you have created an Application Definition and activated it for single sign-on, the first time you log on, the user is prompted to enter credentials in a SecureLogin dialog box. SecureLogin stores and associates these credentials with the Application Definition and uses it in subsequent logins.

You can display and manage these credentials in the Logins page of the Administrative Management Utility and the My Logins pane of the Personal Management Utility.

Since individual Application requirements determine the credentials that users must enter when manually logging in, only those credentials are stored and remembered by SecureLogin. For example, if users have an application that only requires username and password, SecureLogin encrypts and stores the username and password for subsequent logins. Alternatively, some applications require the user to enter domain and database names, IP Addresses and check boxes selected on web pages, and SecureLogin can handle all of these on the user’s behalf.

Credentials stored in a directory environment apply to all associated objects. For example, if users access an application located on a specific domain, and they are required to manually select or type of the domain address, then you can configure the domain as a credential in the Logins pane at the organizational unit level. This removes the requirement for users to manually enter the domain location when they log in. You can then change the domain at any time without notifying users.

Application credentials such as e-mail, finance system, HR system, and the travel system are typically stored for user objects and only apply to (and can be used by) the particular user. For example, John’s application credentials are encrypted and stored against John’s user object and only available to him. When he starts an application, SecureLogin retrieves, decrypts, and enters the credentials on John’s behalf.