HP-UX DCE Version 2.0 Release Notes
About This Document
In This Version
Chapter 18
• Extended Registry Attribute (ERA) facility— provides a means to
define arbitrary attribute types; to attach instances of those types to
principals, groups, and organizations; and to insert attributes in a
principal's credentials for use by specialized security applications.
For example, the ERA facility could be used to support single sign-on
across non-UNIX platforms and legacy systems by associating
additional security information with users and groups.
• Extended logon capabilities — provide the following features:
— Pre-authentication, which improves the security of
authentication by eliminating passive attacks on the Key
Distribution Center.
— Login denial, which permits limitation on the number of
successive invalid attempts and Security Server enforcement of
password expiration.
— Password management, which permits strength checking of
user-selected passwords according to site policies and automatic
generation of random plaintext passwords.
• ACL Manager Library — provides server writers with an ACL
manager for use with all servers.
• Group override — customizes group name mapping from host to host
to allow DCE to adapt to various operating system conventions.
• Internationalization interfaces — message catalogs for all
user-visible messages.
• Character code set interoperability — allow development of RPC
applications that automatically convert character data from one code
set to another.
• Interface Definition Language (IDL) compiler performance
enhancements — smaller stub size and a number of new IDL
constructs.
• RPC performance enhancements — allows additional client sockets
during peak usage and optimizes RPC run-time packets.
• Subtree operations — allows large-scale administrative name
changes within cells.
• Distributed Time Service (DTS) remote administration.