We are not using SSO/EIM at this time. We dabbled a little with it some years ago.
We are not using MFA for our IBM i applications at this time.
I have heard some interesting tales of people using EIM on IBM i. For example if I have multiple user accounts like ROBSECOFR, ROBACCT, ROBERP, etc then I would need a separate IP address on the IBM i for each account. And when you get into the whole fail over system where PROD is in one subnet and HA is in another subnet this can be fun. The people pursuing this were perfectly fine with this.
This is not to say that ROBSECOFR and TIMSECOFR would need separate IP addresses on the host.
------------------------------
Robert Berendt IBMChampion
------------------------------
Original Message:
Sent: Tue August 01, 2023 01:54 PM
From: Stefano Missoni
Subject: Managing authentication and authorization on IBM i
Hi Robert,
I am looking to see what MFA and SSO options are available for the IBM Series i.
I see Enterprise Identity Mapping (EIM) can implement SSO with an on-premise Active Directory environment, but that is not our optimal path. I noticed Security Verify can federate with Azure, but I wasn't certain that its Series i integration was limited to provisioning local accounts or also providing (brokering) authentication.
Ideally, authorization would be delegated to an identity provider like Azure where Azure's own MFA implementation would govern authentication.
Thank you for the response!
------------------------------
Stefano Missoni
------------------------------
Original Message:
Sent: Tue August 01, 2023 01:14 PM
From: Robert Berendt
Subject: Managing authentication and authorization on IBM i
I'm not sure if I understand the question. We have Security Verify create/update/delete users on IBM i. When someone changes their password in Windows it changes it on IBM i automatically. We have three Power systems with 14 lpars of IBM i.
------------------------------
Robert Berendt IBMChampion