Security Parameters

Each of these security parameters is set during the initial driver configuration.

Understanding how the parameters work together and work with the operating system will help you define your approach to security for NsureTM Identity Manager data synchronization.


Recommended Security Configurations


Using Identity Manager Remote Loader

Because authentication is dependent on several parameters such as the server support pack, your DNS infrastructure, and policy and registry settings, the most reliable means of authentication is to install the driver on the computer hosting Active Directory and then use the Remote Loader to connect to the DirXML engine, as illustrated in Dual Server Configuration (2). With this configuration, you will be most successful if you set the driver parameters as follows.

Authentication ID: Domain login name, for example Administrator
Authentication Context: [Blank]
Application Password: Password for the service account
Remote Loader Password: Password for the Remote Loader service
Authentication Method: Negotiate
Signing: No
Sealing: No
Use SSL: No


Insulating the Domain Controller

If you do not want to run the driver on your Active Directory domain controller, as shown in Single Server Installation and in Triple Server Configuration, set the driver parameters as follows:

Authentication ID: NT Logon Name or Domain Qualified Name.
Authentication Context: hostname
Password: Password for the specified Authentication ID.
Use Signing: Yes/No, requires Windows 2003 or Windows 2000 with the most recent support pack, and Internet Explorer 5.5 SP2 or later on both servers.
Use Sealing: Yes/No, requires Windows 2003 or Windows 2000 with the most recent support pack, and Internet Explorer 5.5 SP2 or later on both servers.
Use SSL: Yes/No, SSL is required to perform subscriber password check, set, and modify using the simple authentication method.


Using SSL

SSL is recommended if you have selected the simple authentication mechanism, and is required for password synchronization.

Authentication ID: LDAP format Authentication ID
Authentication Context: IP address of domain controller
Password: Password for the specified Authentication ID
Authentication Method: Simple
Use Signing: No
Use Sealing: No
Use SSL: Yes