Verify AD rights have been assigned correctly to enable users to run SecureLogin after running adsschema.exe

  • 7940488
  • 19-Aug-2009
  • 26-Apr-2012

Environment

Novell SecureLogin SSO



Situation

After running adsschema.exe, how can I verify AD rights have been assigned correctly to enable users to run SecureLogin and save credentials such as usernames and passwords against their user object?

Verifying AD rights for SecureLogin

Resolution

Using adsschema.exe, rights are assigned to the SELF object at the container level and are inherited by all user objects in the container. To verify users have been assigned the appropriate rights to run SecureLogin SSO and save credentials to the Directory, perform the following tasks:

  • Right click on the Container e.g. Users and select Properties from the menu
  • At the Security tab, select Advanced and the Permissions tab will appear (Note: in this case there are 6xSELF which correspond to the 6x SSO attributes).
  • Click on the SELF permissions that “Apply To” User objects and click Edit
  • The protocom-SSO attributes will appear under the SELF entry. Verify all of the protocom-SSO permissions have been applied.

Additional Information

Note: To view the permissions from the user object’s perspective, navigate to the user object > properties > security > advanced> effective permissions tab.