
10 Identity Manager 3.6.1 Password Management Guide
novdocx (en) 13 May 2009
Section 1.2, “Password Synchronization Flow,” on page 10
Section 1.3, “Password Policy Enforcement,” on page 11
Section 1.4, “Password Policy Enforcement Notifications,” on page 11
Section 1.5, “Password Policy Assignments,” on page 11
Section 1.6, “Password Synchronization Status,” on page 12
Section 1.7, “Password Self-Service,” on page 12
1.1 Universal Password and Distribution
Password
Identity Manager requires Universal Password for both password synchronization and password
self-service. Universal Password synchronizes the various passwords (Universal, NDS®, Simple,
and Distribution) stored in the Identity Vault and provides password policies that define the rules for
creating and replacing passwords in the Identity Vault.
Universal Password is explained in detail in the Novell Password Management 3.2 Administration
Guide (http://www.novell.com/documentation/password_management32).
To control password synchronization between the Identity Vault and connected systems, Identity
Manager uses the Distribution password. When a password is received from a connected system, it
is stored as the Distribution password. When a password is sent to a connected system, the
Distribution password is sent.
You can choose to synchronize the Distribution and Universal passwords or not synchronize them. If
you synchronize the passwords, your Identity Vault passwords and connected system passwords will
be the same. If you don’t synchronize the passwords, your Identity Vault passwords will be different
than your connected system passwords; in essence, you are “tunneling” passwords among connected
systems without affecting the passwords (Universal, NDS, or Simple) in your Identity Vault.
1.2 Password Synchronization Flow
Identity Manager supports the following levels of password synchronization:
Bidirectional: Identity Manager accepts passwords from a connected system and distributes
passwords to the connected system. Users can change their passwords in the connected system
or in the Identity Vault.
Some connected systems can’t provide the user’s actual password, which means they don’t
support full bidirectional password synchronization. However, they can provide data (first
name, last name, and so forth) that the connected system’s driver policies use to create an initial
password. After the initial password is created from connected system data, no more password
information is sent from the connected system. Passwords flow only from the Identity Vault to
the connected system.
To the connected system: Identity Manager distributes passwords from the Identity Vault to
the connected system only.
To the Identity Vault: Identity Manager distributes passwords from the connected system to
the Identity Vault only.