Since passwords are typically hashed on each system in a non-reversible, fashion and since different systems use incompatible password hashes, password synchronization must be an active process that takes place whenever users change their passwords.
There are really just two ways to synchronize passwords. Hitachi ID Password Manager supports both of the possible mechanisms for password synchronization:
- Transparent synchronization:
Hitachi ID Password Manager can be configured to intercept native password changes on certain systems and:
- Apply a password policy beyond the one built into the system where a native password change first happened and potentially reject the initial password change
- Automatically synchronize the user's other passwords, on other systems, to the same value
Systems that can trigger password synchronization are Active Directory, Windows servers, OID, Linux and Unix (various), iSeries and z/OS (optional component).
- Web-based synchronization:
Users authenticate to the Hitachi ID Password Manager web portal, using any browser, by keying in their NOS or directory ID and password. They can then set a single password on one or more of their own IDs on one or more systems.
Hitachi ID Password Manager is a complete solution for managing passwords and other credentials, intended for users in a medium to large enterprise. It supports password synchronization, password reset, token management, unlock of encrypted filesystems and much more.