Global Security Forum

Security Global Forum

Our mission is to provide clients with an online user community of industry peers and IBM experts, to exchange tips and tricks, best practices, and product knowledge. We hope the information you find here helps you maximize the value of your IBM Security solutions.

 View Only
Expand all | Collapse all

How to get information from Security Directory Server 6.4 users

  • 1.  How to get information from Security Directory Server 6.4 users

    Posted Tue October 12, 2021 01:29 PM
    Hello to everybody

    I have implemented IBM SDS 6.4 like authentication tool for Portal Server 8.5 (yes old version, bussines). Security has asked me to get some information from the admin users such as:
    • creation date
    • last access
    • role
    • id
    • status
    I have tested Server audit log but I have not find all the information requested. 

    My questions is how to get such information using only SDS, not cognos or another tool.

    Thank you for your help.

    regards

    ------------------------------
    Ismael Gutierrez E
    IT Consutant Senior

    Please, stay safe!
    Take care of you and your loved ones.
    ------------------------------


  • 2.  RE: How to get information from Security Directory Server 6.4 users

    Posted Wed October 13, 2021 03:26 AM
    Let me take a shot at this - although I am convinced that the expectations from Security is not going to be fulfilled...
    So let me explain that first - when looking at how you portal is authenticating/authorization it is the portal that defines some of the attributes e.g. id/role/status and maps that to some back-end system- in your case an ldap server - so you need to have that knowledge to answer some of the questions.

    So let's answer the easy ones :

    In general it seems that the policies have not been considered when setting up your portal - that is unfortunate because doing this as an afterthought is not optimal and MAY require changes to you setup. I normally would go for a combination of ISDS audit log with a well defined audit level combined with the attributes as outlined above - but nothing of this is working out without also having the using application (here you portal) in the loop...

    HTH

    ------------------------------
    Franz Wolfhagen
    IAM Technical Architect for Europe - Certified Consulting IT Specialist
    IBM Security Expert Labs
    ------------------------------