User Authentication
32
271
n
ov
do
cx (e
n)
16
Ap
ril 20
10
32
User Authentication
The following sections provide information about authentication of users to a ZENworks
®
Management Zone.
Section 32.1, “User Source Authentication,” on page 271
Section 32.2, “Authentication Mechanisms,” on page 272
Section 32.3, “Credential Storage,” on page 277
Section 32.4, “Disabling ZENworks User Authentication,” on page 277
Section 32.5, “Troubleshooting User Authentication,” on page 278
32.1 User Source Authentication
By default, a user is automatically authenticated to the Management Zone when he or she logs in to
an LDAP directory (Novell
®
eDirectory
TM
or Microsoft Active Directory) that has been defined as a
user source in the Management Zone. User authentication to ZENworks can occur only if the user’s
LDAP directory (or the user’s LDAP directory context) is defined as a user source in ZENworks.
The ZENworks Adaptive Agent integrates with the Windows* Login or Novell Login client to
provide a single login experience for users. When users enter their eDirectory or Active Directory
credentials in the Windows or Novell client, they are logged in to the Management Zone if the
credentials match the ones in a ZENworks user source. Otherwise, a separate ZENworks login
screen prompts the user for the correct credentials.
For example, assume that a user has accounts in two eDirectory trees: Tree1 and Tree2. Tree1 is
defined as a user source in the Management Zone, but Tree2 is not. If the user logs in to Tree1, he or
she is automatically logged in to the Management Zone. However, if the user logs in to Tree2, the
Adaptive Agent login screen appears and prompts the user for the Tree1 credentials.
If a user logs in for the first time in to a device that has more than one user source enabled, the user
is prompted to select the user source and enter the user source credentials. During subsequent logins,
the user is automatically logged in to the same user source selected during the first login. However,
if you do not want the user to be prompted to select the user source during the first login, perform
the following steps to enable seamless login on the device:
1
Open the Registry Editor.
2
Go to
HKLM/Software/Novell/ZCM/ZenLgn/
.
3
Create a DWORD called EnableSeamlessLogin and set the value to 1.
If seamless login is enabled, a user's first login to a device might be slow. This is because all the
existing user sources are searched and the user is logged in to the first user source that matches the
user account. If many users use the same device, subsequent logins might also be slow because the
user information might not be cached on the device.
To reduce the login time, specify the default user source to enable the user to seamlessly log in to the
device:
1
Open the Registry Editor.
2
Go to
HKLM/Software/Novell/ZCM/ZenLgn/
.