Authentication type
Allows you to select the default authentication method for users when connecting to the cluster. There are currently four
options available:
|
• |
UserID/Password: Uses a user ID and password that you define in HAM. This option allows you to set the remaining parameters of the security
settings related to password complexity and features in this dialog.
|
|
• |
RSA SecurID: Uses RSA SecurID tokens. In this case, you must have the RSA Ace Agent installed and correctly configured on the servers.
Selecting this option disables all the other parts of the dialog box (except the Group IP address validation) as the settings
cannot be used in conjunction with RSA SecurID. Note that for this authentication method to work, you must select the same
option during the installation of the server software.
|
|
• |
Windows Domain: Uses the currently active Windows domain account of the user (the account they are currently logged on with to the Windows
domain). This option covers both the Windows domain and the Active Directory Service. This option also disables all the other
parts of the security tab (except the Group IP address validation) as the settings cannot be used in conjunction with the
Windows Domain authentication method.
|
|
• |
Novell iChain: Uses the currently active Novell iChain account (the account they are currently logged on with to the Novell iChain server
and Novell eDirectory server in the backend). This option also disables all the other parts of the security tab (except the
Group IP address validation) as the settings cannot be used in conjunction with the Novell iChain method.
|
User cannot change password
Disables the Change password button on the client's ActiveX control toolbar, preventing them from changing their passwords.
Password must contain a digit
Enhances password complexity.
User must change password on first sign on
Forces users to replace the passwords assigned to them by the administrator and define their own new passwords the first time
they connect to the cluster.
Minimum password length
Defines a minimum acceptable length policy for user passwords. If the field is set to zero, any password length will be acceptable,
even an empty password.
Password never expires
Deselect the check box to force users to change their passwords at regular intervals set by the Expiry period field. The Warning period field defines the number of days before the end of the Expiry period during which HAM sends the user a warning notification
to change their password. The notification stops once the user changes the password. If the user does not change the password
by the end of the expiry period, they cannot sign on until they change it.
Enable grace login policy
Defines a policy to block users who attempt to sign on with the wrong password. The Number of attempts field defines the number of times the user can enter a wrong password before the account is locked. The Reset interval time field defines the time (in minutes) after which the system automatically unlocks a locked account.
Group IP address validation
Defines IP address filters or access lists for the users. HAM allows you to define up to four subnets. HAM accepts connections
only from users having IP addresses belonging to the defined subnets. For example, if you define 10.1.1 and 10.1.2 then HAM
only gives access to users with IP addresses in the ranges 10.1.1.0 to 10.1.1.255 and 10.1.2.0 to 10.1.2.255.