K
Kirk
My company wants to integrate our application to some of our clients'
SSO systems. These systems may be either proprietary, LDAP, or Active
Directory. I have a couple of general questions that I've been unable
to find answers to elsewhere. Your help is appreciated.
1. Once the user is logged in to the machine, is the password
retrievable, or is it just ignored from that point onward?
2. How is the LDAP (or AD) system secured? If it requires a username/
password, do I have to prompt the user? Wouldn't this negate the
benefit of a SSO system? But if we don't require password, how is it
secured? Just by getting the logged on user from the OS?
SSO systems. These systems may be either proprietary, LDAP, or Active
Directory. I have a couple of general questions that I've been unable
to find answers to elsewhere. Your help is appreciated.
1. Once the user is logged in to the machine, is the password
retrievable, or is it just ignored from that point onward?
2. How is the LDAP (or AD) system secured? If it requires a username/
password, do I have to prompt the user? Wouldn't this negate the
benefit of a SSO system? But if we don't require password, how is it
secured? Just by getting the logged on user from the OS?