260
ZENworks 10 Configuration Management System Administration Reference
n
ov
do
cx (e
n)
16
Ap
ril 20
10
Authentication Mechanisms
page
Select the mechanism used to authenticate users to the ZENworks
Management Zone. The available mechanisms depend on whether
you are configuring a Novell eDirectory or a Microsoft Active
Directory user source.
Kerberos:
Active Directory only. Enables Kerberos*
authentication in which the Active Directory server generates a
Kerberos ticket that Novell Common Authentication Services
Adapter (CASA) uses to authenticate the user, instead of using
a username and password. Kerberos authentication is often
used with smart cards.
Username/Password:
eDirectory or Active Directory. Enables
simple authentication using a username and password.
Shared Secret:
eDirectory only. Enables a user to
automatically log in to ZENworks when a smart card is used to
log in to eDirectory. This option is enabled only if the schema
of the eDirectory specified in the
Connection Information page
is extended using the novell-zenworks-configure tool.
If
Shared Secret
is not selected as an authentication
mechanism, a ZENworks login dialog box is displayed when
the user on the managed device attempts to log in to
eDirectory using a smart card. After the user specifies the
eDirectory username and password, that password is stored in
Novell SecretStore. The next time the user uses a smart card
to log in to eDirectory, the password is retrieved from
SecretStore and the user is logged in to the ZENworks without
having to specify the password.
If you select both available mechanisms (
Kerberos
and
Username/
Password
for Active Directory or
Username/Password
and
Shared
Secret
for eDirectory), ZENworks Configuration Management
attempts to use the first mechanism for authentication. If
authentication fails, the next mechanism is used. For example, if
you select
Kerberos
and
Username/Password
for Active Directory,
ZENworks Configuration Management first attempts to use
Kerberos authentication. If Kerberos authentication fails, simple
Username/Password authentication is used.
Wizard Page
Details