IBM Security Verify

 View Only
  • 1.  SCIM Interface on Verify Access, Password Policy

    Posted Thu November 17, 2022 01:59 PM
    Hi team, When the SCIM interface is used to add new users and to change the passwords of existing users, I understand that the verify access password policy is not taken into account. In these cases, the password policy that is taken into account is the LDAP password policy? Thanks in advance

    ------------------------------
    David Vicenteño Sanchez
    ------------------------------


  • 2.  RE: SCIM Interface on Verify Access, Password Policy

    Posted Thu November 17, 2022 03:05 PM

    David,

     

    If you set the password via the ISAM schema it should pay attention to the Verify Access password policy.  Here is the description of the password field from the ISAM schema:

     

    "The User's clear text password.  This attribute is intended to be used as a means to specify an initial password when creating a new User or to reset an existing User's password.  The field is optional and can be used to replace the 'password' field in the core schema if you wish to use the ISAM password policy."

     

    I hope that this helps.

     

    Scott A. Exton
    Senior Software Engineer
    Chief Programmer - IBM Security Verify Access

    IBM Master Inventor

    cid4122760825*<a href=image002.png@01D85F83.85516C50">

     

     






  • 3.  RE: SCIM Interface on Verify Access, Password Policy

    Posted Thu November 17, 2022 04:53 PM
    great Scott !!!, I tested it and it worked perfectly, another question about the same topic, when you use the scim interface to add users, is it possible to indicate in which ldap branch users will be hosted? Or are users always hosted in the branch that was established in the SCIM configuration? ex:



    Thanks in advance.
    Regards

    ------------------------------
    David Vicenteño Sanchez
    ------------------------------



  • 4.  RE: SCIM Interface on Verify Access, Password Policy

    Posted Thu November 17, 2022 05:29 PM

    David,

     

    This is not a part of the standard SCIM specification, but back in ISAM 9.0.6 the 'registrySuffix' entry was added to the schema to allow you to specify the registry suffix for a particular user.  Take a look at the what's new guide for 9.0.6: https://www.ibm.com/docs/en/sva/9.0.6?topic=overview-whats-new-in-this-release

     

    I hope that this helps.

     

    Scott A. Exton
    Senior Software Engineer
    Chief Programmer - IBM Security Verify Access

    IBM Master Inventor

    cid4122760825*<a href=image002.png@01D85F83.85516C50">

     

     






  • 5.  RE: SCIM Interface on Verify Access, Password Policy

    Posted Thu November 17, 2022 08:01 PM
    Great!! Thank you very much Scott, That helps me a lot !!! 

    Regards

    ------------------------------
    David Vicenteño Sanchez
    ------------------------------