Novell Identity Manager 3.6.1 Integration Module for Mainframes

April 02, 2010

1.0 Overview

The Novell® Identity Manager 3.6.1 Integration Module for Mainframes comes with two provisioning options: Bidirectional and Fan-Out. With these options, you have the full range of capabilities to satisfy your authentication and data provisioning needs.

2.0 OS Version Support

Connected Platform

Versions Supported byBidirectional Driver

Versions Supported byFan-Out Platform Services

z/OS*

1.9, 1.10 (see Note), 1.11

1.8, 1.9, 1.10

Java*

1.4.2, 1.5, 1.6

N/A

Core Driver Platform

Versions Supported by Core Driver

Windows*

Any supported by the Identity Manager version in use.

Linux*

Any supported by the Identity Manager version in use.

Solaris*

Any supported by the Identity Manager version in use.

NOTE:Support by the RACF Bidirectional Driver for z/OS 1.10 requires program temporary fix (PTF) UA44635 and PTF UA43624 from IBM*.

2.1 Security System Version Support

Security System

Versions Supported byBidirectional Driver

Versions Supported byFan-Out Platform Services

RACF*

(supported z/OS version)

(supported z/OS version)

Top Secret*

9, 12, 14

8

ACF/2*

Not Available

9, 12

3.0 Feature Overview

Feature

Bidirectional

Fan-out

Data Publishing from Platform to Identity Manager

Yes

No

Data Subscribing from Identity Manager to Platform

Yes

Yes

Provisioning to Hundreds of Platforms with a Single Driver

No

Yes

Bidirectional Password Synchronization

Yes

Yes

Administrative Password Resets from Platform

Yes

No

Administrative Password Resets to Platform

Yes

Yes

End User Password Replication to and from Platform

Yes

Yes

Authentication Redirection

No

Yes

Enforcement of Universal Password Rules on Platform Login

No

Yes

Universal Password Replication Support

Yes

Yes

Event Triggered Rexx Scripts for Provisioning

Yes

Yes

Event and Poll Based Publishing

Yes

No

Role-Based Entitlements and Approval Workflow

Yes

No

Audit Enabled

Yes

Yes

Password Self Service Support

Yes

Yes

iManager Plug-In

Yes

Yes

Password Failure Email Notification Support

Yes

No

APIs to Simplify Programmatic Directory Access

No

Yes

4.0 Bidirectional Overview

The Bidirectional driver provides complete integration with Identity Manager for full data and password synchronization. This driver provides data customization with Identity Manager policies, using standard security system commands. Each subscribed eDirectory™ data change event is converted into a security system command. Security system commands are captured and published to Identity Manager for appropriate eDirectory updates.

5.0 Fan-Out Overview

The Fan-Out driver provides for delegated logic and control to your system administrators. You can process any Identity Manager data change event with a script on the platform. The Fan-Out driver provides for fan-out to hundreds of systems from a single driver. Authentication redirection provides login support for Universal Password, accessing a central repository for login and password rules. Full bidirectional password synchronization is also supported.

The Fan-Out driver is the natural upgrade path from Novell Account Management. The same extensible scripts are supported to manage users and groups on target platforms, and the same Authentication Services API is supported. In future releases, the Fan-Out driver will provide tighter integration with Identity Manager, while continuing to provide the flexibility to manage all aspects of the user experience using extensible scripts.

The Fan-Out driver has two components: the core driver and Platform Services. The core driver provides event fan-out to target platforms running Platform Services. A single core driver can support many platforms running Platform Services, regardless of platform operating system.

6.0 Documentation Conventions

A trademark symbol (® , TM, etc.) denotes a Novell trademark; an asterisk (*) denotes a third-party trademark