|
Sun Identity Management
Solutions for authentication, authorization, provisioning, and auditing
» Download Now
Sun Java System Access Manager FAQ: Authentication
Q: Can I reset the load balancer (LB) cookie with a No. You can reset the LB cookie while creating Q: If one of the Dist-Auth servers fails during authentication, does that server recreate the state? Yes, the failed-over Dist-Auth server reinitiates the authentication request to Access Manager. Q: If failover occurs between Dist-Auth servers during authentication, is the LB cookie reset? If the primary Dist-Auth server for the request fails after the This process is transparent to the user, who is not prompted to log in again after the primary Dist-Auth server fails. Q: How do I configure Access Manager to display different authentication types for different resources? Configure a gateway, as described in "To Configure Resource-Based Resource Management" in Chapter 5, "Managing Policies" in the Access Manager Administration Guide. Q: How do I publish certificates in Sun Java System Directory Server? Use the
Q: How do I authenticate users with This code example demonstrates how to authenticate users with the user-name and password credentials and how to obtain an SSO Token. You can run this example within a stand-alone application or within a servlet. Note: Ensure that the relevant Java archive (JAR) filesthat is, For details, see Chapter 1, "Using the Client SDK" in the Access Manager 7.1 Developer's Guide. Q: Does the authentication process between the Dist-Auth server and Access Manager support authentication chaining with multiple steps? Yes. Q: How can I find out what At the time of authentication, go to Dist_auth_protocol The name of the Dist-Auth server that started the authentication process is displayed. After successful authentication, Access manager inserts the output value into the Q: What happens if the Access Manager instance fails during authentication? In case of an Access Manager failure during authentication, the request goes to the second Access Manager server, which checks whether the original server is up. If it is, the second server forwards the request to the original server. Otherwise, the second server recreates Q: What is stored in the HTTP session of the Dist-Auth application? Can I tune the parameters? The HTTP session of Dist-Auth points to Dist-Auth contains no parameters you can tune for HTTP sessions. Any performance tuning must occur on the Web container instead. For details, see your Web server or other relevant container's tuning guide. Q: Which Active Directory attribute populates the Kerberos Principal that is returned from authentication? That Active Directory attribute is Q: How do I resolve the Do the following:
Q: Why do I get an error message after entering a valid user name and password on the login page? Here are the possible reasons:
To correct the password:
Q: After entering my user name-password credentials, I got a redisplay of the login page. What should I do? When you first reach the login page, Access Manager creates a temporary session that remains valid for 30 seconds only. If you do not successfully log in within that time, Access Manager terminates the session. Between the time you accessed the login page and when you submitted your login credentials, 30 seconds might have elapsed, hence Access Manager could not locate the session and redisplayed the login page instead. You can reconfigure the length of the session on the Access Manager Administration Console. Another reason for a redisplay of the login page is that the cookie domain name in the platform server list is incorrect. Check that list and verify that it contains the correct DNS domain for which the Access Manager server is configured. |
|
Oracle is reviewing the Sun product roadmap and will provide guidance to customers in accordance with Oracle's standard product communication policies. Any resulting features and timing of release of such features as determined by Oracle's review of roadmaps, are at the sole discretion of Oracle. All product roadmap information, whether communicated by Sun Microsystems or by Oracle, does not represent a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. It is intended for information purposes only, and may not be incorporated into any contract.
|
| ||||||||||||