HP-UX DCE Version 2.0 Release Notes

About This Document
In This Version
Chapter 18
Extended Registry Attribute (ERA) facility— provides a means to
define arbitrary attribute types; to attach instances of those types to
principals, groups, and organizations; and to insert attributes in a
principal's credentials for use by specialized security applications.
For example, the ERA facility could be used to support single sign-on
across non-UNIX platforms and legacy systems by associating
additional security information with users and groups.
Extended logon capabilities — provide the following features:
Pre-authentication, which improves the security of
authentication by eliminating passive attacks on the Key
Distribution Center.
Login denial, which permits limitation on the number of
successive invalid attempts and Security Server enforcement of
password expiration.
Password management, which permits strength checking of
user-selected passwords according to site policies and automatic
generation of random plaintext passwords.
ACL Manager Library — provides server writers with an ACL
manager for use with all servers.
Group override — customizes group name mapping from host to host
to allow DCE to adapt to various operating system conventions.
Internationalization interfaces — message catalogs for all
user-visible messages.
Character code set interoperability — allow development of RPC
applications that automatically convert character data from one code
set to another.
Interface Definition Language (IDL) compiler performance
enhancements — smaller stub size and a number of new IDL
constructs.
RPC performance enhancements — allows additional client sockets
during peak usage and optimizes RPC run-time packets.
Subtree operations — allows large-scale administrative name
changes within cells.
Distributed Time Service (DTS) remote administration.