22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

460 Lotus Security Handbook<br />

server, the server can connect to the remote foreign LDAP directory server to<br />

look up the user name and password to do the authentication.<br />

Attention: A server can always use a Domino directory in the directory<br />

assistance database for client authentication if the directory is assigned the<br />

same domain as the server's domain, regardless how the Directory<br />

Assistance document is configured.<br />

You use an Internet Site document or the Ports → Internet Ports tab of the<br />

Server document to control the types of client authentication an Internet protocol<br />

server allows.<br />

Names accepted for name-and-password authentication<br />

If a server uses name-and-password security to authenticate Internet clients, you<br />

select the types of names that the server can accept from clients. On the<br />

Security → Internet Access tab of the Server document in the primary Domino<br />

Directory, select “More name variations with lower security” or “Fewer name<br />

variations with higher security” (the default). The selection applies to name and<br />

password authentication using any directory, including the primary Domino<br />

Directory.<br />

Though a server can accept a name other than a distinguished name from a<br />

client to search for a user's entry in a directory, it is always the user's<br />

distinguished name in the directory entry that the server compares to trusted<br />

rules in the Directory Assistance document to determine whether to authenticate<br />

the client. For example, suppose a user is registered in a directory with the<br />

distinguished name cn=alice browning,o=Acme, but the user configures the<br />

name alice browning on the client. During authentication, the server searches for<br />

an entry that contains the name alice browning. When it finds the entry, it can<br />

only authenticate the client if “cn=alice browning,o=acme” matches a trusted<br />

naming rule for the directory.<br />

A user's distinguished name is also used as the basis for access control in<br />

Domino, so you should use users' distinguished names in database ACLs, in<br />

groups used in database ACLs, in access lists in Server documents, and in Web<br />

server File Protection documents.<br />

Encountering duplicate names during client authentication<br />

If a server finds more than one directory entry containing the name presented by<br />

the client that corresponds to a valid distinguished name for authentication,<br />

within one directory or across directories, the server authenticates the client<br />

using the entry with the valid password or X.509 certificate. If more than one<br />

such entry has a valid password or X.509 certificate and the same distinguished

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!