IBM SAM E-SSO Server Policies Best Practices For PoTs and PoCs
IBM SAM E-SSO Server Policies Best Practices For PoTs and PoCs
IBM Tivoli Access Manager for Enterprise Single Sign-On : IMS Server Policies and Configuration Quick Guide for PoCs
Provision First User Provision IMS administrator (ensure that the user is in AD/LDAP before this) AccessAdmin->User Interface Policy assignment attribute : memberOf (if you want to use AD group as the assignment attribute) Enable delete user button: Enabled Length of the authorization code, in characters: 4 AccessAdmin->Login Allow form-based login to AccessAdmin from remote machine: True
AccessAssistant and Web Workplace Policies Second factor authentication required.. : No Display personal authentication : No Wallet Policies Enable automatic sign-on for personal authentication services : No
Sign Up Policies Enable Automatic Sign-Up AccessAgent Policies->Display Policies AccessAgent feedback link: <company_email> AccessAgent Policies->Engina Policies Enable Application Launch from EnGINA: Yes Display Label for Application Launch: I forgot my password Command line for application launch: C:\Program Files\Internet Explorer\iexplore.exe k http://<tamesso server name>/aawwp/app/reset_password_front_page.jsp AccessAgent Policies->Desktop Inactivity Policies Desktop Inactivity Action: Lock Computer AccessAgent Policies->Logon/Logoff Policies Enable TAM ESSO Network Provider
2009 IBM Corporation
Password Policies->Password Change Policies Force provisioned users : No Self-Service Policies->Self-Service Registration and Bypass Enable self-service registration : Yes Wallet Policies Wallet caching option : Always cache Default automatic sign-on password entry option : Automatic Logon Enable automatic sign-on for personal authentication services : No Enable auto-learning: No Sign Up Policies Option for specifying secret : Secret not required
Ideally, for most authentication services Default automatic sign-on password entry option to Automatic Logon
Recommendations?