A
PPENDIX
A: A
UTHENTICATION
O
PERATIONS
M86 A
UTHENTICATOR
M86 S
ECURITY
U
SER
G
UIDE
199
Work flow in environments
Windows environment
1. The administrator stores the M86 Authenticator client
(authenticat.exe) in a network-shared location that a
login script can access.
2. Using a Windows machine, an end user logs on the
domain, or logs on the eDirectory tree via a Novell client.
3. The end user’s login script evokes authenticat.exe.
4. The M86 Authenticator client determines the authentica-
tion environment by examining the Windows registry,
then retrieves the username and domain name using
either Windows or Novell APIs, and sends this informa-
tion (LOGON event) to the Web Filter.
5. The Web Filter looks up the groups to which the end user
belongs (Windows AD, PDC, or eDirectory through
LDAP), and determines the profile assignment.
6. The Web Filter sets the profile for the end user with user-
name (including the group name, if it is available) and IP.
7. The M86 Authenticator client continually sends a “heart-
beat” to the Web Filter—with a specified interval of
seconds between each “heartbeat”—until the end user
logs off.
8. The end user logs off, and the M86 Authenticator client
sends a LOGOFF event to the Web Filter. The Web Filter
removes the user's profile.
NOTE
: The M86 Authenticator can handle up to 20 logons per
second.