128
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
For example:
https://someservice.com/path/password?user=<USERID>&store=<STOREID>
&returl=<RETURN_URL>&action=expire
NOTE:
If you copy and paste this text, make sure you remove the white space between
<STOREID>
and
&returl
.
The Identity Server fills in these values, which results in the following URL:
https://someservice.com/path/password?user=joe.novell&store=userstore1&
returl=https://myidp.com/nidp/idff/sso&action=expire
Forcing Authentication after the Password Has Changed
The password service can also include parameters on the return URL sent to the Identity Server. The
Identity Server understands the following parameter:
The following example sends this parameter with
https://testnidp.novell.com:8443
as the
base URL of the Identity Server.
<form id="externalForm" action='https://testnidp.novell.com:8443/nidp/idff/
sso?sid=0&id=117&forceAuth=TRUE' method="post">
When the user is redirected to the password management service URL because of an expired
password, the POST data in that redirect contains the
sid=
<>
and
id=
<>
values as part of the value
used for the Identity Server return URL.
Grace Logins
If you specify a password service and do not specify a value for the number of grace logins in
eDirectory, the contract redirects to the password management service only when the grace login
count has reached 0 and the password has expired.
Parameter
Description
<USERID>
Provides the DN of the user with a password that is expired or expiring.
<STOREID>
Provides the name of the user store that authenticated the user before
redirecting the user to the password expiration service.
<RETURN_URL>
Provides the URL at the Identity Server to which the user can be redirected
after the password service completes.
action=expire
Causes the password expiration service to behave as though the user’s
password policy is set to allow the user to reset the password even though the
user’s policy might be set to show the user a hint. The user sees the page to
create a new password rather than seeing a hint for an existing password.
Parameter
Description
forceAuth=TRUE
When the user is returned to the Identity Server, this parameter forces the
user to authenticate with the new password. This eliminates the possibility of
an old password being used in an Identity Injection policy.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...