首页> 外国专利> Method and system for enforcing password policy for an external bind operation in a distributed directory

Method and system for enforcing password policy for an external bind operation in a distributed directory

机译:在分布式目录中为外部绑定操作实施密码策略的方法和系统

摘要

The invention describes techniques for enforcing password policy within a distributed directory environment that includes one or more distributed directory servers and a proxy server that acts as an intermediate agent between a client and the distributed directory environment. In one aspect, the proxy server is enhanced to support the passing (from the backend server to the client) of password policy controls. In particular, controls returned from a backend server are parsed and cached (for re-use) for the life of a given client connection. According to another aspect, the proxy server ensures that all compare operations for a single user's password are directed to the same backend server in the distributed directory environment. This insures that a user's most current password is used, and that failed operation counts, resets and operational attributes are up-to-date. According to still another aspect, the proxy server enforces password policy on bind plug-ins and, in particular, through a pair of pre-bind and post-bind extended operations. In particular, pre-bind processing includes checking if an account is locked. Post-bind processing includes checking for expired passwords, grace logins and updating failed/successful bind counters.
机译:本发明描述了用于在包括一个或多个分布式目录服务器和充当客户端与分布式目录环境之间的中间代理的代理服务器的分布式目录环境内实施密码策略的技术。一方面,增强了代理服务器以支持密码策略控件的传递(从后端服务器到客户端)。特别是,在给定客户端连接的生命周期内,将从后端服务器返回的控件进行解析和缓存(以供重用)。根据另一方面,代理服务器确保针对单个用户的密码的所有比较操作都被定向到分布式目录环境中的同一后端服务器。这样可以确保使用了用户的最新密码,并且失败的操作计数,重置和操作属性都是最新的。根据另一方面,代理服务器对绑定插件,特别是通过一对预绑定和后绑定扩展操作,实施密码策略。特别地,预绑定处理包括检查帐户是否被锁定。绑定后处理包括检查过期的密码,宽限登录以及更新失败/成功的绑定计数器。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号