Previous Topic: Replace Web Triggers with Web-Targeted Data In Motion TriggersNext Topic: Color Coding for Incident Rate By Policy Report


Change in AuthenticatedUserType Default Value for ICAP Agent

In the current CA DataMinder release, the AuthenticatedUserType registry value for the ICAP agent defaults to 'auto'. In previous releases, it defaulted to 'DN'.

AuthenticatedUserType specifies what type of user information is included in the ICAP x-header that contains the user credentials. The supported types are  distinguished names (DN), ‘domain\user’ names, and SMTP email addresses. Policy engines use this information to determine which user policy to use when processing the data.

The new 'auto' value enables the ICAP agent to detect the type of user information automatically. Previously, you had to specify which type of user information you wanted the ICAP agent to detect.

When you upgrade to the current CA DataMinder release, you do not need to change the AuthenticatedUserType registry value from ‘DN’ to ‘auto’. However, if you set it to ‘auto’, the ICAP agent is protected against future changes to your proxy server. For example, if your proxy server switches to ICAP authentication based on SMTP addresses, the ICAP agent cannot identify users while AuthenticatedUserType remains set to ‘DN’. Consequently, policy engines apply the Default Policy for Files instead of the policies for the actual users.