Ask the Expert

Synching passwords between an iSeries and Windows network

Is it possible to synch passwords between an iSeries and a Windows network? And, is there a way to synch password between multiple iSeries'?

    Requires Free Membership to View

While Windows users can use commonly available terminal emulators to access their iSeries from their desktops, this doesn't truly synch the passwords between the two systems. Emulators are simply a pass through for the iSeries user ID and password from the Windows front end to the iSeries in the back.

The best approach would be to use single-sign on (SSO). SSO accomplishes both tasks at once – synchs your Windows passwords to your iSeries back-end and synchs the iSeries passwords for multiple systems to each other.

Fortunately, IBM has upgraded iSeries in recent years to include Kerberos functionality, which can be used for authentication in Windows 2000, 2003 and XP. Kerberos makes it easier to merge the two disparate systems – Windows, a distributed PC-based network system, and iSeries, a mainframe system – into a common authentication set up.

Kerberos requires a Key Distribution Center (KDC) for creating, managing and distributing the keys used in authentication systems, SSO or otherwise. Both domain controllers can host the KDC now that iSeries has KDC functionality with the release of i5/OS V5R3, formerly known as OS/400.

Your Windows clients will need iSeries Access for Windows or iSeries Navigator to hook up to the iSeries to complete the SSO implementation. One fundamental problem with SSO links between Windows and iSeries occurs when combining the registries used by each to store user authentication information. However, iSeries uses Enterprise Identity Mapping (EIM), a new technology developed by IBM starting with the V5R2 release to solve this problem.

Obviously, SSO deployments can be quite complicated and require a thorough understanding of your network architecture, applications and user needs and habits.

This was first published in December 2005

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: