Novell Nsure Identity Manager Integration Module for Linux and UNIX

August 18, 2006

1.0 Overview

The Novell® Nsure™ Identity Manager Integration Module for Linux* and UNIX* comes with two provisioning options: Bidirectional and Fan-Out. With these options, you have the full range of capabilities to satisfy your authentication and data provisioning needs.

2.0 Version Support for Linux and UNIX OSes

Platform

BidirectionalVersion Support

Fan-out Version Support

AIX

5.1, 5.2, 5.3

4.33, 5.1 (APAR IY37250), 5.2, 5.3

HPUX

11, 11i

11, 11i

Solaris Sparc

8, 9, 10

2.6, 7, 8, 9, 10

Solaris x86

10

N/A

SUSE Linux (32 bit) SLES, SLED

8, 9, 10

7, 8, 9

Red Hat Linux (32 bit) AS, ES

2.1, 3, 4

2.1, 3

Debian

N/A

2.1, 3

FreeBSD

N/A

4.8, 4.9

3.0 Feature Overview

Feature

Bidirectional

Fan-out

Data Publishing from Platform to Identity Manager

Yes

 

Data Subscribing from Identity Manager to Platform

Yes

Yes

Provisioning to Hundreds of Platforms with a Single Driver

 

Yes

Bidirectional Password Synchronization

Yes

 

Administrative Password Resets from Platform

Yes

 

Administrative Password Resets to Platform

Yes

Yes

End User Password Replication to and from Platform

Yes

Yes

Authentication Redirection

 

Yes

Enforcement of Universal Password Rules on Platform Login

 

Yes

Universal Password Replication Support

Yes

Yes

Event Triggered Shell Scripts for Provisioning

Yes

Yes

Event and Poll Based Publishing

Yes

 

Role-Based Entitlements

Yes

 

Nsure Audit Enabled

Yes

Yes

Password Self Service Support

Yes

Yes

iManager Plug-In

Yes

Yes

Password Failure Email Notification Support

Yes

 

APIs to Simplify Programmatic Directory Access

 

Yes

4.0 Bidirectional Overview

The Bidirectional driver provides complete integration with Identity Manager for full data and password synchronization. This driver provides data customization with Identity Manager policies, using standard security system commands. Each subscribed eDirectory™ data change event is converted into a security system command. Security system commands are captured and published to Identity Manager for appropriate eDirectory updates.

5.0 Fan-Out Overview

The Fan-Out driver provides for delegated logic and control to your system administrators. You can process any Identity Manager data change event with a script on the platform. The Fan-Out driver provides for fan-out to hundreds of systems from a single driver. Authentication redirection provides login support for Universal Password, accessing a central repository for login and password rules. Full bidirectional password synchronization is also supported.

The Fan-Out driver is the natural upgrade path from Novell Account Management. The same extensible scripts are supported to manage users and groups on target platforms, and the same Authentication Services API is supported. In future releases, the Fan-Out driver will provide tighter integration with Identity Manager, while continuing to provide the flexibility to manage all aspects of the user experience using extensible scripts.

The Fan-Out driver has two components: the core driver and Platform Services. The core driver provides event fan-out to target platforms running Platform Services. A single core driver can support many platforms running Platform Services, regardless of platform operating system.

6.0 Legal Notices

Novell, Inc. makes no representations or warranties with respect to the contents or use of this documentation, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, Novell, Inc. reserves the right to revise this publication and to make changes to its content, at any time, without obligation to notify any person or entity of such revisions or changes.

Further, Novell, Inc. makes no representations or warranties with respect to any software, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, Novell, Inc. reserves the right to make changes to any and all parts of Novell software, at any time, without any obligation to notify any person or entity of such changes.

Any products or technical information provided under this Agreement may be subject to U.S. export controls and the trade laws of other countries. You agree to comply with all export control regulations and to obtain any required licenses or classification to export, re-export, or import deliverables. You agree not to export or re-export to entities on the current U.S. export exclusion lists or to any embargoed or terrorist countries as specified in the U.S. export laws. You agree to not use deliverables for prohibited nuclear, missile, or chemical biological weaponry end uses. Please refer to www.novell.com/info/exports/ for more information on exporting Novell software. Novell assumes no responsibility for your failure to obtain any necessary export approvals.

Copyright © 2006 Novell, Inc. All rights reserved. No part of this publication may be reproduced, photocopied, stored on a retrieval system, or transmitted without the express written consent of the publisher.

Novell, Inc. has intellectual property rights relating to technology embodied in the product that is described in this document. In particular, and without limitation, these intellectual property rights may include one or more of the U.S. patents listed at http://www.novell.com/company/legal/patents/ and one or more additional patents or pending patent applications in the U.S. and in other countries.

For Novell trademarks, see the Novell Trademark and Service Mark list.

All third-party trademarks are the property of their respective owners.