22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

246 Lotus Security Handbook<br />

Session-based name-and-password authentication<br />

Session-based name-and-password authentication is the alternative to<br />

name-and-password authentication for Web clients, and includes additional<br />

functionality that is not available with basic name-and-password authentication.<br />

A session is the time during which a Web client is actively logged onto a server<br />

with a cookie. To specify settings that enable and control session authentication,<br />

the Web Site document or the Server document should be edited, depending on<br />

the desired configuration.<br />

Furthermore, there are two selections for enabling session-based authentication:<br />

single and multi-server options. The single server option causes the server to<br />

generate a cookie that is honored only by the server that generated it, while the<br />

multi-server option generates a cookie that allows single sign-on with any server<br />

that shares the Web SSO configuration document.<br />

To use session-based authentication, Web clients must use a browser that<br />

supports cookies. Domino uses cookies to track user sessions.<br />

Features of session-based name-and-password authentication<br />

Using session-based name-and-password authentication provides greater<br />

control over user interaction than basic name-and-password authentication. For<br />

example, it is possible to customize the form in which users enter their name and<br />

password information. It also allows users to log out of the session without<br />

closing the browser.<br />

Customized HTML log-in form<br />

An HTML log-in form allows a user to enter a name and password and then use<br />

that name and password for the entire user session. The browser sends the<br />

name and password to the server using the server’s character set. For HTTP<br />

session authentication, a user can enter a name using any printable characters<br />

in Unicode. The user password, however, must be entered in any printable<br />

characters in US-ASCII.<br />

Note: The range of printable characters excludes control characters.<br />

Domino provides a default HTML form ($$LoginUserForm), which is provided<br />

and configured in the Domino Configuration database (DOMCFG.NSF). You can<br />

customize the form or create a brand new one to contain additional information<br />

that can be presented to the user. For example, you can modify the form to have<br />

a look and feel consistent with the rest of your Internet or intranet site.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!