Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Table of Contents

Introduction

Definition
English
borderColorgreen
borderWidth1
titleBGColor#ddffcc
borderStylesolid
title
The Security Enhanced Directory Manager features enhanced security and control on user management.


Simply go

...

to System Settings -> Directory Manager Settings to enable and configure.


Image Modified

Figure 1: Security Enhanced Directory Manager Properties

Children Display
alltrue
styleh4
pageKBv4:Security Enhancements

...

Panel
borderColorred
titleColorwhite
titleBGColor#f45555
titleDisabling Plugin

Once the plugin is enabled, users' password would be stored using a new encryption method. Disabling the plugin would cause all the users not to be able to login anymore as the default encryption method is effectively changed.

If you decide to stop using the plugin, you will need to replace all the affected users' password in dir_user table with a new password based on md5 hash.

Notification

Panel
borderColorred
titleColorwhite
titleBGColor#f45555
titleImportant

Setting up the Notification tab in this Enhanced Security Directory Manager is important and highly recommended. Do not skip the setup and remember to test sending email out to make sure that the email server settings is correct.

Image Modified

Email notification will be sent out on these important events:-

  • User Creation: email is sent when the admin creates a new user in "Setup User".
  • Password Reset: email is sent when the admin resets the user's password by checking the "Force Password Change" checkbox in "Setup Users > Edit User > Admin Setting".
  • Forgot Password: email is sent when the user clicks the forget password link on the login page.
  • Account Lockout: email is sent when the wrong password exceeds the limit set in "Failed Login Attempts for Account Lockout".


Image Modified