Creating Universal Password Policies outside of the Security Container

  • 3701028
  • 11-Jan-2008
  • 26-Apr-2012

Environment

Novell Modular Authentication Service (NMAS) 3.1.3 (and greater)
Novell eDirectory 8.8 SP1 for All Platforms
Novell eDirectory 8.7.3.9 for All Platforms
Novell iManager 2.6

Situation

NMAS 3.1.3 (from Security Services 2.0.4 patch) and greater provide the ability to create Universal Password Policies outside of the Security Container with the New iManager Password Management/Universal Password Plug-in.

The new plug-in is named "Password Administration Plug-in for iManager 2.6" (PwdManagementPlugins_iMAN_2_6.npm)

Resolution

To get the latest Password Management/Universal Password Plug-ins:

1. Go to https://download.novell.com | in the Keyword field search for "Password Management"
2. Select "Password Administration Plug-in for iManager 2.6"
3. Download the "PwdManagementPlugins_iMAN_2_6.npm"


To install the Password Management/Universal Password plug-ins, do the following:

1. Login to iManager
2. Select the "Configure" Icon (man behind the desk)
3. From the left Nav, expand the "Plug-in Installation" task and select the "Available Novell Plug-in Modules" link.
4. Select "Add" | Browse to the downloaded NPM from above (PwdManagementPlugins_iMAN_2_6.npm)
5. Select "Novell Identity Manager - Password Management"and click install.
6. After the install is complete. Logout of iManager and restart tomcat.

Note: the new Password Management Plug-ins are included in the Identity Manager 3.5 plugins. if you have the IDM 3.5 plug-ins, you do not need to install the PwdManagementPlugins_iMAN_2_6.npm


Using the New Universal Password Plug-in to create Universal Password Policies outside of the Security Container.

1. Install new Password Management/Universal Password iManager Plug-in (steps given above)
2. Install Security Services 2.0.4 (or greater)
3. Manually extend the schema from the Security Services 2.0.4 patch (or greater). (Schema files to be extended are: nmas.sch, nspm.sch, notf.sch, and nsimpm.sch) See eDirectory Documentation for instructions on extending schema. The Identity Manager 3.5 install extends the schema for you, therefore if you have IDM 3.5 installed you can skip this step.
4. Login to iManager | Expand the "Passwords" role | Select the "Password Policies" task.
5. Select "New" (this starts the Password Policy Wizard)
6. In the "Container to create the policy in:", select the Browse button and browse to the container you wish to create the Password Policy in. In this example, I'll create a password policy called "Users Universal Password Policy" in the ou=users.o=novell container. Once you have the correct container to create the Password Policy selected, continue on with the Password Policy Wizard selecting the necessary options as desired.