[HOME]           [About Us]           [[Products]]           [News]           [Contact Us]                                                                  [Site Map]

 

 

 

[Overview]

      Architecture

      Standards

      [AD Integration]

 

MatchLogon GINA

MatchLogon Server

SAP/R3 Integration

Technologies Supported

Authentication Scenarios

Auditing & Admin

Procedure

Problems with Passwords

Why fingerprinting?

Sequential What?

Behind the scenes

System Requirements

 

MatchLogon with fingerPIN - Overview > Active Directory integration & Support

 

MatchLogon fully supports and utilizes Microsoft Windows Active Directory (AD). AD technology was introduced with Windows 2000 to replace the traditional Windows NT SAM database. The following is a partial list of major AD advantages and their relevance for MatchLogon:

 

·                     Multi-master domain model

·                     Load balancing

·                     Support for complex (n-tier) domain configurations and "sites"

·                     Automatic data replication of both operating system and third-party data

·                     Robust fail-over capability

·                     Extensible schema

·                     Tightly integrated with the Domain Name System (DNS)

·                     Global Catalog

 

Customers gain considerable robustness through AD, and can substantially lower their Total Cost of Ownership (TCO) for MatchLogon enabled AD domains. MatchLogon integrates with many of the fail-over and data replication services that the operating system provides. AD's multi-master domain model allows the domain to function normally in the case where a Domain Controller (DC) becomes unavailable. As long as the domain consists of more than one DC, there is no single designated DC to process information updates.

 

In case of a DC failure, and assuming the worst case scenario, only the last data that was received but not replicated across the domain/forest is lost. As long as the DC becomes available again, the updated data may not even be lost but may just be unavailable until the DC goes live once again. AD's use of DNS and its Global Catalog sub-system greatly supports service discovery and reduces network bandwidth usage. The information maintained by the operating system is made available in a standardized and straightforward form.

 

MatchLogon fully leverages these mechanisms to provide data replication, a robust and fast server discovery to its clients on the network.

 

MatchLogon AD Data

To support and make full use of AD, MatchLogon extends the AD schema by extending existing Computer and User classes with new attributes. These attributes contain fingerprint, password, settings and other support information. MatchLogon AD data is opaque to AD and other AD enabled applications. The data is digitally signed and encrypted using cryptographic algorithms specified by the customer when they are installing the MatchLogon Server software and specifying the unique Enterprise Key of the organization.

 

Extension of the AD Schema is optional. MatchLogon could instead use existing attributes such as Photo, Audio, etc., which as a rule are not used in the domain of the organization. Using existing attributes is ideal for evaluations and pilots.

 

Jump to other product categories:

[V-STARS]     [coatings]     [infotech]     [cryogenics]     [machined components]     [consulting]

 

                                                                                                                                                                                                                                                Copyright © 2007 DNP Global