274
ZENworks 10 Configuration Management System Administration Reference
n
ov
do
cx (e
n)
16
Ap
ril 20
10
For example, in the second row, the user’s initial login, user source, and ZENworks login credentials
match. As a result, the user can log in to the ZENworks Management Zone and the ZENworks login
dialog box does not appear.
As another example, in the third row, the user’s initial login credentials are using credentials from a
different domain and are different than the ZENworks login credentials. As a result, the user can log
in to the ZENworks Management Zone, but the ZENworks login dialog box appears.
32.2.2 Shared Secret
When using Shared Secret authentication, you must install and configure the Novell Identity
Assurance Solution Client. For more information, and for a list of supported smart card readers and
smart cards, see the Identity Assurance Solution Client documentation on the
Novell Documentation
Web site (http://www.novell.com/documentation/)
.
Authentication in to ZENworks by using Smart Card is currently supported only on Windows XP
and terminal sessions of Windows Server 2003 device.
When a user uses a smart card to log in to eDirectory, the user is automatically logged in to
ZENworks provided the schema of the eDirectory specified when the user source is added has been
extended using novell-zenworks-configure tool.
For more information on adding the user source, see
Section 31.2.1, “Adding User Sources,” on
page 258
.
For more information on extending the eDirectory schema, see
“Extending the eDirectory Schema
to enable Shared Secret Authentication” on page 275
.
If the eDirectory schema is not extended, then
Shared Secret
is not available as an authentication
mechanism. Consequently, a ZENworks login dialog box is displayed when the user on the managed
device attempts to log in to eDirectory using a smart card. After the user specifies the eDirectory
username and password, that password is stored in Novell SecretStore. The next time the user uses a
smart card to log in to eDirectory, the password is retrieved from SecretStore and the user is logged
in to the ZENworks without having to specify the password.
No
No
No
No
Yes
No
Yes
No
Yes
Yes
Windows
login
matches
user
source
login?
ZENworks also
uses Username/
Password
authentication?
Member of
same
domain?
Member of
different
domain?
Windows and
ZENworks
credentials
match?
Can log in to
Management
Zone?
ZENworks
login dialog
box appears?