1.4 Additional Information

1.4.1 Forcing Users to Change Password Before Grace Login Expires

SecureLogin allows administrators to force users to change their password before the grace login expires.

Scenario: SecureLogin is installed in LDAP mode with eDirectory. When the password expires, the authentication process consumes all the grace logins and users cannot log in. To avoid this, create the following registry keys.

  • GraceDaysBeforePasswordExpire registry of DWORD value. This displays a warning message to the users about the number of days remaining for password expiry.

  • DaysForcePasswordChange of DWORD value. This forces the users to change their password. Although the grace login available, this forces the users to change their password before the grace login expires.

For example, if the password policy is set to change every 90 days, the GraceDaysBeforePasswordExpire can be set to 5 and DaysForcePasswordChange can be set to 3. On the day 85 when users logs in, a message indicating the number of days left before password expiry appears. The users can choose to change the password immediately or change it later.

Similarly, when a users logs in on day 87 another message appears that forces the users to change the password. They cannot continue without changing the password.

NOTE:It is recommended to have the value of grace login to be more than 2. Since SecureLogin utilizes one grace login count for every connection with the directory, it is recommended to set the value of the grace login greater than 2.

1.4.2 Support for Oracle Forms

SecureLogin supports single sign-on to Oracle Forms that uses Java 1.7 or later. If any of these Java components is added in the machine after installing (or upgrading to) SecureLogin, you need to enable SecureLogin to use the newly added Java component. To enable support to the new Java component, run the repair option of the SecureLogin installer.

1.4.3 Enhanced Application Definition Wizard and Theme Change

SecureLogin 8.0 SP1 and later includes more preferences that are added for specific sign-in options. The color of the theme is changed to blue and the color of the SecureLogin icon is also blue.

1.4.4 The SecureLogin Icon Changes Color Indicating Cached Application

NetIQ SecureLogin caches the applications that are launched, and are available for single sign-on. The user can click on the SecureLogin icon and view the list of opened applications. When the applications are cached, the color of the icon changes to orange. When you clear the list of applications, the icon changes to blue, which is the default color of the icon.

1.4.5 Notification Is Displayed

When you launch any application that is available for single sign-on, SecureLogin displays a notification in the system tray indicating that the application can be selected for single sign-on. If you do not want to single sign-on to an application when it is launched then, you can ignore the notification and proceed. When you ignore the notification, the color of the icon changes from blue to orange indicating that web page/ web pages are available for single sign-on. You can view the list of web pages by left clicking the icon once on the system tray and selecting the application to single sign-on. In Windows 10, instead of notification balloon a toast message is displayed.

1.4.6 Display SecureLogin User Name on the Task Bar

You can identify the active SecureLogin user with the help of the visual cue in the task bar. This visual cue displays the details of the active user such as First name, Last name, Full name, Distinguished name, or Default name based on the preference settings. To modify these preferences, refer Display user name on task bar. These preferences will be refreshed every 30 seconds by default. You can also modify the refresh time interval by modifying the value of the registry key UserbarRefreshInterval.

In addition, you can also add prefix to the user name displayed in the task bar. To add prefix, you must set the prefix text as a value for the registry key UserbarPrefix. These registry settings are available at HKEY_LOCAL_MACHINE\SOFTWARE\Protocom\SecureLogin.

SecureLogin does not display the logged in user name by default in the task bar. For user name to be displayed in the task bar, you must right-click the SecureLogin icon on the notification area (system tray) and select Show User bar or you can rightclick on the task bar and select Toolbars -> SecureLogin SSO User.

1.4.7 Keyboard Shortcuts

You can now use the keyboard shortcuts to navigate to the required options.

To view the underlined letters in menu and dialog box options, press the Alt key, on the keyboard. Following is list of hot keys:

Key combination

Result

Ctrl+Shift+A

Launches the New Application window.

Ctrl+L

Launches the Create Login window.

Ctrl+P

Launches the New password policy window

Delete

Deletes the selected application, login, and password policy.