7.2 Configuring NetIQ Advanced Authentication Framework Settings for Forgotten Password

You can configure the NAAF settings so that all the NAAF web service details are registered in the SSPR server. This helps the NAAF users to use any authentication method for resetting their password. If users enroll the device for authentication on the NAAF server, they can choose the specified method to reset their password during a forgotten password process.

An SSPR administrator needs to perform the following to enable NAAF users to reset their password during the forgotten password process:

  1. On the Configuration Editor page, click Settings.

  2. Click NAAF.

  3. Configure the following settings:

Field

Description

NAAF Web Service URL

Specify the URL for NAAF appliance web service. For example, https://www.example.com/api/v1

NAAF Web Service Server Certificate

Click Import From Server to import the certificate for using the NAAF services.

NAAF User Identifier

Click Add Value to include the user identifier that is specified in the NAAF web service. The value must be specified in the format of repository\username. You can also use macros instead of username.

NAAF Login Methods

Select the required methods for the users specified in NAAF User Identifier.

The NAAF users must enroll their devices depending on the authentication method. Otherwise they cannot use the device to authenticate during forgotten password process.