Deprecated. IBM Security Directory Server is officially no longer supported and will be completely removed in a future version of OneSpan Authentication Server!
To enable back-end authentication for IBM Security Directory Server
Identify the IBM Security Directory Server server based on the IBM Security Directory Server back-end server records in OneSpan Authentication Server.
Bind to IBM Security Directory Server using the security principal DN and password defined for the IBM Security Directory Server back-end server record if principal details specified.
Search the IBM Security Directory Server back-end server for the user to be authenticated based on the User Object Class Name and the User ID Attribute Name attributes defined during setup.
Try to authenticate with IBM Security Directory Server using a bind with the user ID and password of the user to be authenticated.
If authentication fails, the attributes retrieved during the search will be used to determine the cause of the failure.
In addition, you will also need to do the following:
Configure OneSpan Authentication Server to authenticate via LDAP SSL (see Configuring SSL for back-end authentication).
Set up a back-end server record for IBM Security Directory Server. This means to register it as a back-end server for OneSpan Authentication Server via the Administration Web Interface (see BACK-END – IBM Directory (tab)).
When registering a IBM Security Directory Server back-end server for OneSpan Authentication Server, ensure that the location entered in the IBM Security Directory Server back-end server record is the same as that shown on the Tivoli Web Administration > View Edit > Issued To > cn=serverid.
| UserID format | Source of user ID |
|---|---|
| UserID | Common name of the user |
| MYREALM\userid | Fully qualified domain name + common name of the user |
| userid@mydomain.com | Common name attribute of the user + fully qualified domain name |
OneSpan Authentication Server only supports the Simple binding with SSL option as the client authentication mechanism for binding with the supported instances of IBM Security Directory Server.
Configuring SSL for back-end authentication
Configuring OneSpan Authentication Server to authenticate via LDAP SSL requires binding an SSL certificate with the Bind with SSL option and importing the certificate into OneSpan Authentication Server. You can use an SSL certificate from a trusted certification authority (CA), or generate a self-signed certificate using the Global Security Kit.
When using a self-signed certificate that was generated by IBM Security Directory Server, it must be created as a binary DER-encoded file (.der). This file needs to be converted to PEM format, and then imported into OneSpan Authentication Server.
To convert a DER-encoded certificate and import it to OneSpan Authentication Server
Convert the binary DER-encoded certificate file (.cer) to an ASCII-armored certificate file (.pem) using the following command:
openssl x509 ‑inform DER ‑outform PEM ‑in certname.cer ‑out certname.pem
where certname is the name of the self-signed CA certificate.
OneSpan Authentication Server ships with a specific version of the OpenSSL utility. We recommend that you use this version for any procedures involving the openssl command.
By default, this specific version of OpenSSL is located in %PROGRAMFILES%\VASCO\IDENTIKEY Authentication Server\bin on Windows and in /opt/vasco/ias/bin on Linux, respectively.
Depending on your platform, do one of the following:
If you are using Ubuntu Server:
Change the extension of the certificate file to .crt and copy it to the CA certificate store:
mv certname.pem certname.crt
cp certname.crt /usr/local/share/ca-certificates
Update the CA certificate store:
update-ca-certificates
If your are using another Linux distribution or Microsoft Windows:
Obtain the hash of the .pem file:
openssl x509 ‑in certname.pem ‑noout ‑subject_hash
Rename certname.pem to hashvalue.0, where hashvalue is the hash value calculated by the openssl command.
For example, if the hash result is 54321, the file name would be 54321.0.
Copy the renamed certificate file (hashvalue.0) to the following location, depending on the platform:
/etc/ssl/certs (Linux)
%PROGRAMFILES%\VASCO\IDENTIKEY Authentication Server\certs (Windows, default).
On Linux, ensure that the run user of OneSpan Authentication Server can access the certificate file. If required, change access rights and/or file ownership with the chmod and chown commands.
Restart the OneSpan Authentication Server service or daemon, respectively.
The new certificate files are read only when the service/daemon starts.
After importing the certificate file into OneSpan Authentication Server, enable SSL on the IBM Security Directory Server instance (via the Security Properties page).