Pass-through authentication scenarios

Use the pass-through authentication scenarios to identify the appropriate configuration for your directory server environment.

You can configure pass-through authentication for the following basic scenarios:

  • Attribute mapping is set, and the entry is in the authentication server.
  • Attribute mapping and password migration is set, and the entry is in the authentication server.
  • Attribute mapping is not set, and the entry is not in the authentication server.
  • Attribute mapping is set by using the ibm-ptaReferral auxiliary object class.
  • Pass-through authentication is set to Active Directory Global Catalog.

If you use a single pass-through server for a subtree in a distributed directory, you must configure the pass-through interface on all the back-end servers. If you use multiple pass-through servers for the same subtree, then you must configure the required pass-through interface on the appropriate back-end servers.