22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

480 Lotus Security Handbook<br />

Similar to the other mapping option, this option may often be supported via the<br />

implementation of a Directory synchronization tool to handle the population of the<br />

new LDAP attribute in LDAP.<br />

This option is new to Domino 6, and thus is supported in Domino 6.x, but is not<br />

supported in Domino 5.x or earlier.<br />

11.10 Domino Password Checking<br />

Password Checking is a client authentication feature that ensures that users are<br />

forced to change their passwords at regular intervals and also include protection<br />

for the user base. Consider the following example: If someone were to acquire a<br />

Notes user ID file – and, of course, be able to know the password of this Notes ID<br />

– they would normally be free to access the server using this copy of the Notes<br />

ID. However, when Password Checking is enabled, the moment the victim<br />

changes their password on their legitimate Notes ID file, it results in the server<br />

also being aware of the change. Any attacker then trying to gain access with the<br />

stolen copy of the Notes ID file will be refused access to the server.<br />

When the administrator enables password checking, that person can specify a<br />

Required Change Interval (which is measured in days) that forces users to<br />

change the passwords on their Notes user ID files within that interval of time. The<br />

Notes client will prompt a user to change their password as the expiration date of<br />

the password draws closer. In addition to the change interval the administrator<br />

can specify a Grace Period. This is a time (again, measured in days) that<br />

indicates the interval of time (after the expiration of a password) the user has to<br />

change their password. In both R5 and Version 6, after the Change Interval +<br />

Grace Period elapses, the user will effectively be denied access to the server<br />

until the administrator resets their account in the user's Person document. This is<br />

a different behavior from that of pre-Notes R4.67 clients. The following<br />

discussion focuses on R5 and Version 6 clients.<br />

11.10.1 The Notes and Domino password checking system<br />

The Notes and Domino password checking system can be split up into two main<br />

components: the Notes client and the Domino server (we integrate iNotes a little<br />

bit later). At this stage, it's important to point out that most of the work that goes<br />

into enforcing a Domino Server lockout (resulting from the application of the<br />

password checking feature) is actually carried out on the Notes client. Before we<br />

can explain the full working process, it is necessary to take the time to provide an<br />

initial explanation of the components involved.<br />

With an enabled Notes user ID, users can be made aware of an upcoming<br />

password expiration before they have even clicked on a database icon or

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!