Previous Topic: Impersonation Template

Next Topic: RADIUS CHAP/PAP Template

MS Passport Template

Use this table when configuring an authentication scheme based on the scheme type MS Passport. The structure fields referenced in the table are in Sm_PolicyApi_Scheme_t.

Information Type

Value Assignment and Meaning

Scheme type

nType=Sm_Api_SchemeType_MSPassport

The scheme type MS Passport.

Description

pszDesc=description

The description of the authentication scheme.

Protection level

nLevel=value

A value of 1 through 1000. The higher the number, the greater degree of protection provided by the scheme. Default is 1.

Library

pszLib="smauthmspp"

The default library for this scheme type.

Parameter

pszParam=param

The following information, separated by semicolons:

  • A DN for an anonymous user. Format:

anonuser=anonUserDN

If you specify an anonymous user DN, the protection level is 0.

  • The search string for looking up a user in a user directory of the specified type. Format:

attribute=nameSpace:attrib=searchSpec

Valid namespaces are LDAP, AD, ODBC, WinNT, and Custom.

  • The registration URL. The URL can be a custom URL or a SiteMinder form. Formats:

registrationurl=URL (custom URL)
registrationurl=FORM=URL (SiteMinder form)

Example using an LDAP attribute and a custom URL:

attribute=LDAP:altSecurityIdentities=
Kerberos:%s@company.local;registrationurl
=http://passport.xanadu.local/registration/passportreg.asp

Shared secret

pszSecret=""

Set to an empty string. Not applicable to this scheme.

Is template?

bIsTemplate=0

Set to false (0) to indicate that the scheme is not a template. Any other value is ignored.

Is used by administrator?

bIsUsedbyAdmin=0

Set to false (0)-scheme is not used to authenticate administrators.

Save credentials?

bAllowSaveCreds=0

Set to false (0) to indicate that user credentials won't be saved.

Is RADIUS?

bIsRadius=0

Set to false (0)-scheme is not used with RADIUS agents.

Ignore password check?

bIgnorePwCheck=1

Set to true (1)-ignore password checking.


Copyright © 2010 CA. All rights reserved. Email CA about this topic