User guide

Chapter 2: Environment Setup (SSO Administrators)
2-42
Attributes that must be set for executing certificate authentication (Note)
mail
employeeNumber
uid
serialNumber
dnQualifier
Attributes that must be specified depending on operation:
ssoAuthType
ssoRoleName
ssoCredentialTTL
ssoNotBefore
ssoNotAfter
Attributes that need not be specified:
ssoUserStatus
ssoFailureCount
ssoLockTimeStamp
Note
If the attribute for identifying user information uniquely from the owner name information in the
certificate does not use cn, one of the above attributes must be set.
Object Classes
The user registered in the SSO repository is managed by the following object classes. Always specify
the following object classes when registering user information in the SSO repository:
User information object class Description
top Basic LDAP object class
person
organizationalPerson
inetOrgPerson
User information
ssoUser SSO user information
Attributes
Specify the user ID, password, and authentication method as the attributes of the above object classes.
The following attributes are used in Interstage Single Sign-on: