Hello,
You can absolutely do this.
If you return an external user header, groups header and extra attributes headers, WebSEAL will build a credential for that user (and populate the specified groups) for a user thy doesn't exist in ISAM LDAP.
You can do the same from AAC Authentication Service or Federation Runtime by setting the POC mode to External User.
To authenticate against a database you'll probably have to write a full EAI App since those capabilities are not build into the JavaScript extensions. A hybrid approach would be to have AAC Authentication Mechanisn call to an external REST service which Does the DB work.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------
Original Message:
Sent: Sat May 16, 2020 09:14 AM
From: Jahanzaib Sarwar
Subject: ISAM: EAI/InfoMap user authentication for non-directory users
Hello all,
ISAM's EAI and InfoMap capabilities allow us to implement custom authentication logic for users which reside in ISAM's LDAP or any federated directory.
I need to know whether, using EAI/InfoMap, would it be possible to authenticate the users which are not present in ISAM's LDAP or any of the federated directories? In other words, would it be possible to create a user credential for a user not present in any of the federated directories by using EAI/InfoMap?
The goal is to authenticate users from a database and these users do not reside in ISAM LDAP or any of the Federated Directories.
Looking forward to your valueable comments..
Best regards,
------------------------------
Jahanzaib Sarwar
------------------------------