IBM Security Directory Server back-end authentication

To enable back-end authentication for IBM Security Directory Server

  1. Identify the IBM Security Directory Server server based on the IBM Security Directory Server back-end server records in OneSpan Authentication Server.
  2. Bind to IBM Security Directory Server using the security principal DN and password defined for the IBM Security Directory Server back-end server record if principal details specified.
  3. Search the IBM Security Directory Server back-end server for the user to be authenticated based on the User Object Class Name and the User ID Attribute Name attributes defined during setup.
  4. Try to authenticate with IBM Security Directory Server using a bind with the user ID and password of the user to be authenticated.

If authentication fails, the attributes retrieved during the search will be used to determine the cause of the failure.

In addition, you will also need to do the following:

  • Configure OneSpan Authentication Server to authenticate via LDAP SSL.
  • Set up a back-end server record for IBM Security Directory Server. This means to register it as a back-end server for OneSpan Authentication Server via the Administration Web Interface.

When registering a IBM Security Directory Server back-end server for OneSpan Authentication Server, ensure that the location entered in the IBM Security Directory Server back-end server record is the same as that shown on the Tivoli Web Administration > View Edit > Issued To > cn=serverid.

OneSpan Authentication Server only supports the Simple binding with SSL option as the client authentication mechanism for binding with the supported instances of IBM Security Directory Server.