

Administration Guide › Tenant Management › Reauthentication After Password Change
Reauthentication After Password Change
Perform this procedure if you require that tenant users to re-authenticate when they change their passwords in the Change My Password task.
Follow these steps:
- Enable ODBC Session Store Policy Servers as follows:
- Set the X11 DISPLAY variable.
- Issue the command: /opt/CA/siteminder/bin/smconsole
- Login to CSP console and use the Modify Agent Configuration task.
Select CAM-AgentObj and make sure that the FCCCompatMode is set to no.
- Create a response Response in domain tenantDomain and create the following attribute:
- Attribute: WebAgent-OnReject-Redirect
- Attribute Kind: Static
- Variable Value: /siteminderagent/forms/reauthenticate.fcc:validate
- Create a policy Policy in the domain tenantDomain.
- Select Add All for User Directories.
- Add two rules in tenant_ims_realm:
<Rule1>:
Resource: *task.tag=ChangeMyPassword
Regular Expression: checked
Action: Web Agent Actions, GET and POST
<Rule2>:
Resource: *task.tag=ChangeMyPassword
Regular Expression: checked
Action: Authorization events, OnAccessValidateIdentity
- Add the response Response to Rule2.
- Commit the creation.
- In the Policy Server, run the command tool xpsexplorer and make the following change:
- Modify policy Policy, set ValidateIdentity to true.
- Restart each policy server configured for high availability.
- Restart the policy engine in each Secure Proxy Server configured for high availability.
Copyright © 2015 CA Technologies.
All rights reserved.
 
|
|