ZCM Pass-through authentication is not working with Novell IDM Client Login Extension (CLE)

  • 7005081
  • 26-Dec-2009
  • 30-Apr-2012

Environment

Novell ZENworks 10 Configuration Management with Support Pack 1 - 10.1
Novell ZENworks 10 Configuration Management with Support Pack 2 - 10.2
Novell Identity Manager 3.5.1

Situation

1.  IDM CLE Installed (Microsoft environment only, no Novell Client).  The IDM CLE reconfigures the registry  \HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL\ (GinaDLL) from the Microsoft GINA (msgina.dll ) to the IDM CLE GINA (MSGinaExtension.dll) .

a.  Deploy the ZCM Adaptive Agent - no problem.

b.  The ZCM agent installation does not change the GINA to NWGINA.DLL .  Pass-through User authentication does not work, however, login through the Adaptive Agent works.

c.  Manually changing the GinaDLL registry key to nwgina.dll allows the ZENworks Adaptive Agent to allow pass-through user authentication, however, doing this breaks the IDM Client Login Extension. The Forgotten Password prompt on the GINA disappears.

2.  ZENworks Adaptive Agent Installed (Microsoft environment only, no Novell Client).  The Adaptive Agent changes the GinaDLL registry key to nwgina.dll .

a.  The installation of the 'IDM Client Login Extension for Novell Identity Manager 3.5' fails with the error:
 
"This installer requires Novell Client 4.91 SP 3 or later to be installed, or for the GINA to be set to the Microsoft GINA.
 
The GINA is set to "nwgina.dll", not to the Microsoft GINA.  Please uninstall the product that set the GINA to "nwgina.dll" and then try again."

b.  Changing the GinaDLL registry key to msgina.dll allows the install of the IDM CLE, but then back to the same problems as in item 1.

Resolution

This is fixed in version 10.2.1 - see KB 7003766 "ZENworks 10 Configuration Management 10.2.1 - update information and list of fixes" which can be found at https://www.novell.com/support