2.2 NMAS Software

NMAS is included as a bundled product with Novell eDirectory and NetWare. NMAS is also available as part of the Security Services bundle, available from the Novell Download Web Site. The software image includes the following:

2.2.1 Server and Client Software Installation

NMAS server-side software must be installed with eDirectory 8.7.3 or later. NMAS client-side software must be installed on each client workstation that will access the network using the NMAS login methods. After installation, NMAS is managed using iManager or ConsoleOne.

The NMAS client software now ships with the Novell Client for Windows 4.9.0 or later.

2.2.2 Login Method Software and Partners

All NMAS login methods (server software, plug-ins, and snap-ins) are installed using the Method Installer utility. Several currently supported login methods are available on the NMAS software image.

NMAS software includes support for a number of login methods from third-party authentication developers. Refer to the eDirectory Partners Web site for a list of Novell partners.

Each partner that develops login methods for NMAS addresses network authentication with unique product features and characteristics. Therefore, each login method will vary in its actual security properties.

Novell has not evaluated the security methodologies of these partner products, so although these products might have qualified for the Novell Yes, Tested & Approved or Novell Directory Enabled logos, those logos relate to general product interoperability only.

We encourage you to carefully investigate each partner's product features to determine which product will best meet your security needs. Also note that some login methods require additional hardware and software not included with the NMAS product.

2.2.3 Universal Password

For information on Universal Password, see the Section 7.0, History of Novell Passwords.

2.2.4 iManager and ConsoleOne Management

You can manage NMAS using iManager or ConsoleOne. Novell iManager is a Web-based utility for managing eDirectory. ConsoleOne is the Java* authored, GUI-based utility for managing eDirectory. Specific property pages in each utility let you manage login methods, login sequences, enrollment, and graded authentication.

By default, NMAS installs the standard NDS password login method. Additional login methods can be installed using ConsoleOne and a wizard launched from the Authorized Login Methods container using the Create New Object option. Post-login methods can be installed using a wizard launched from the Authorized Post-Login Methods container using the Create New Object option.

During the installation of these modules, NMAS extends the eDirectory schema and creates new objects in the Security container in the eDirectory tree. These new objects are the Authorized Login Methods container, the Authorized Post-Login Methods container, the Security Policy object, and the Login Policy object. All login methods are stored and managed in the Authorized Login Methods container. All post-login methods are stored and managed in the Authorized Post-Login Methods container.