Comtarsia Software Overview
Introduction
At Rutgers University, IT administrators have had access to a central LDAP server for use as a directory and authentication service. This allows Rutgers NetID authentication on end-user PC's and in computer labs. On the Windows 2000 and XP platforms, and IT administrator was able to make use of software called “pGina” to allow LDAP authentication. However, pGina was not an option with the introduction of Windows Vista and then Windows 7, the prominence of 64-bit, and the decreased development of pGina and lack of support on Windows 7 x64. Support in particular for Windows 7 x64 (but also for previous platforms such as XP and 2003) was found in new software, “Comtarsia Logon Client”.
About Comtarsia Software
Comtarsia is a German-based company that creates and supports software that provides authentication capabilities to directory services such as LDAP.
Generally, version 2006 software is designed to support Windows 2000/XP/2003. Version 2008 software is designed to support the Windows Vista, 7, and 2008 platforms.
Comtarsia web site (English):
http://signon.comtarsia.com/index_en.html
Key Software for Rutgers
The most important piece of software for Rutgers, and the reason for purchase, is the Comtarsia LDAP Logon Client, specifically version 2008, which supports Windows 7 (including 64-bit).
The “SignOn Gate” software is also useful in that it allows a computer using any of the Logon Client software to create or synchronize accounts on Active Directory or other directory server on-the-fly, rather than work with local accounts. This software is server-based, as Logon Clients connect to it to have the accounts created or synchronized.
Download Links
The following download link is available for all Comtarsia software. One can download the software directly from Comtarsia, and then license the product using the keys provided in the software portal.
http://signon.comtarsia.com/main/en/Download
Licensing
Through a membership program through Comtarsia called the “Comtarsia Academic Free License Program”, all of Comtarsia's software is licensed to all departments of Rutgers University. The membership ends on August 31, 2013. The license keys are fully functional and valid for an unlimited time with product builds released within the membership period.
Each piece of software is licensed using a license file. The file names and associated software are shown below:
- key041 - Comtarsia Logon Client 2006
- key042 - Comtarsia Logon Client 2008
- key501 - Comtarsia SignOn Gate Proxy 2006
- key401 - Comtarsia SignOn Gate Agent 2006
- key601 - Comtarsia LDAP Directory Replicator 2006
- key802 - Comtarsia Web Gateway 2008
Support Information
Original adopter, technical contact:
The original adopter and tester of Comtarsia LDAP Logon Client 2008 was Andy Mudrak. He would be happy to field any questions about the software or its
uses.
Andy Mudrak
Systems Architect
School of Communication and Information
Rutgers, The State University of New Jersey
ajmudrak@rutgers.edu
732-932-7500 ext. 8901
Other known adopters and possible technical contacts:
Brian Luper, Project Manager, OIT – Central Systems & Services (central computer labs)
Support from Comtarsia
Support requests can be made to Comtarsia during the licensing period. To do so, one must provide a “code word” to validate the support request. The
support code word is available in the Support can be contacted via e-mail:
support@comtarsia.com
There is also a web-based knowledge base on Comtarsia's web site:
http://signon2.comtarsia.com/main/en/Support/Main
Brian Luper's group has had success with support requests to Comtarsia, they have been reported to be open to customizations and have been easy to work with.
Descriptions of Software
LDAP Logon Client 2008
This version supports Windows Vista, Windows 7 and Windows Server 2008, and works with either 32-bit or 64-bit editions of each OS.
Comtarsia Logon Client 2008 allows authentication and integration of Windows workstations into an LDAP managed network.
- Full support of LDAP password policies
- High security through SSL / TLS
- Group management by same name or mapping list
- Windows policy support: pol-files or group policies
- Roaming profile and home directory management
- Resource assignment for aliases, network drives and printers
- LDAP managed network applications
- System management features: scripts with special permissions and directory replication
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
Example Configuration for Comtarsia LDAP Logon Client 2008 with the Rutgers LDAP Server
This setup information is taken from a working example used at the School of Communication and Information computer labs, running Windows 7 x64 and the Comtarsia LDAP Logon Client 2008.
The following configuration is designed to provide LDAP (NetID) authentication, which will log into a local user account. If the account does not exist locally, one will be created on the fly.
The system on which this is configured should have the RULink CA certificate installed in the computer's “Trusted Certificate Authority” certificate store. This can be obtained at: http://idms.rutgers.edu/ldap/certificates.shtml
- Global
- Logon session: "enabled domain login" not checked
- LDAP
-
Server
LDAP Host: ldap.rutgers.edu
LDAP Port: 636
Timeout: 10
ServerType: OpenLDAP
SSL Mode: SSL with trusted server certificate
BaseDN: OU=People,DC=rutgers,DC=edu
-
Users
Append BaseDN checked
User Object
UserDN Prefix: uid=
UserDN Suffix is blank
UserDN Mode: Static DN
[default] Object Class: Person
[default] UserObject required not checked
[default] Password Attribute: userPassword
[default] UTF8 password not checked
-
Groups
[default] Query Base is blank
[default] Query Scope: Sub Tree
[default] Filter is blank
- Logon
- Logon Policy (defaults if not mentioned)
Checked box for "don't display last username"
For "Disable Password Change", checked all boxes
RACF Logon Client 2008
This version supports Windows Vista, Windows 7 and Windows Server 2008, and works with either 32-bit or 64-bit editions of each OS.
Comtarsia Logon Client 2008 allows authentication and integration of Windows workstations into a RACF managed network.
- Full support of LDAP password policies
- High security through SSL / TLS
- Group management by same name or mapping list
- Windows policy support: pol-files or group policies
- Roaming profile and home directory management
- Resource assignment for aliases, network drives and printers
- LDAP managed network applications
- System management features: scripts with special permissions and directory replication
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
Domino Logon Client 2008
This version supports Windows Vista, Windows 7 and Windows Server 2008, and works with either 32-bit or 64-bit editions of each OS.
Comtarsia Logon Client 2008 allows authentication and integration of Windows workstations into a Domino managed network.
- Full support of LDAP password policies
- High security through SSL / TLS
- Group management by same name or mapping list
- Windows policy support: pol-files or group policies
- Roaming profile and home directory management
- Resource assignment for aliases, network drives and printers
- LDAP managed network applications
- System management features: scripts with special permissions and directory replication
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
LDAP Logon Client 2006
This version supports Windows 2000, Windows XP and Windows Server 2003.
Comtarsia Logon Client 2006 allows authentication and integration of Windows workstations into an LDAP managed network.
- Full support of LDAP password policies
- High security through SSL / TLS
- Group management by same name or mapping list
- Windows policy support: pol-files or group policies
- Roaming profile and home directory management
- Resource assignment for aliases, network drives and printers
- LDAP managed network applications
- System management features: scripts with special permissions and directory replication
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
RACF Logon Client 2006
This version supports Windows 2000, Windows XP and Windows Server 2003.
Comtarsia Logon Client 2006 allows authentication and integration of Windows workstations into a RACF managed network.
- Full support of LDAP password policies
- High security through SSL / TLS
- Group management by same name or mapping list
- Windows policy support: pol-files or group policies
- Roaming profile and home directory management
- Resource assignment for aliases, network drives and printers
- LDAP managed network applications
- System management features: scripts with special permissions and directory replication
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
Domino Logon Client 2006
This version supports Windows 2000, Windows XP and Windows Server 2003.
Comtarsia Logon Client 2006 allows authentication and integration of Windows workstations into a Domino managed network.
- Full support of LDAP password policies
- High security through SSL / TLS
- Group management by same name or mapping list
- Windows policy support: pol-files or group policies
- Roaming profile and home directory management
- Resource assignment for aliases, network drives and printers
- LDAP managed network applications
- System management features: scripts with special permissions and directory replication
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
Web Gateway 2006
The Comtarsia Web Gateway is the universal Single Sign On solution for web applications with user/password respectively Smart Card/Token logon on a web portal.
The Comtarsia Web Gateway is a Middleware solution, with which a central authentication against a LDAP or Active Directory and the access to all websites respectively portals is enabled. The product Comtarsia SignOn Gate takes over the automatic user management and password synchronization on all target domains and systems. The central web browser logon via the Comtarsia Web Gateway and the position of trust between the web applications and the Comtarsia Middleware enables a controlled access to all resources in the network with a high amount of security and comfort.
Through the automatic „Session Password Generation“ and the synchronization on the user database of the non PKI capable web portals the direct access to the web portal via password authentication is prohibited and only possible via the central LDAP password respectively via the Smart Card / Token logon.
- Supported Portal authentication types
- Form based Authentication
- HTTP Basic/NTLM Authentication
- Certificate based Client Authentication
- Application using Comtarsia SSO API
- Supported web server:
- Microsoft IIS Version 5.0 and 6.0
- Apache 1.3/2.0/2.2 under Windows and Linux
- Each Web server with CGI Support under Windows and Linux
-
Authentication via user/password or Smart Card Authentication
- A balanced mode is possible and not transparent for the user.
- Smart Card Features
- Individual, per application/workstation configurable, timeout / logout-behavior: After a certain timeout period the user can be prompted to repeat the password / PIN entry or to be redirected automatically to a logout page, or the web browser can be closed.
- On the removal of the Smart Card by the user can also be reacted immediately with a predefined action.
- Therefore timeouts can be determined for highly security critical applications, which are stricter than guidelines of the local system.
-
Supported portal user databases
- Windows Local Users
- Windows or Samba domains
- Active Directory
- Domino
- Oracle
- LDAP
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
LDAP Directory Replicator
The Comtarsia LDAP directory replicator enables time-scheduled unidirectional replication of one or more LDAP directories on defined target-directories and target-systems.
Operated as autonomous server-solution, Comtarsia LDAP Directory Replicator can be applied for the replication of the entire LDAP realm or only for random OU's or objects.
In combination with the products Comtarsia Logon Client and Web Gateway, a synchronisation of complete user objects, groups and attribute on chosen target systems, independent of user logons, can be realised.
-
Supported LDAP Servers:
- IBM Tivoli Directory Server
- IBM z/OS SecureWay (RACF)
- OpenLDAP
- Novell eDirectory
- Active Directory
- Lotus Domino
- Oracle Internet Directory
- Time-scheduled Synchronisation:
- Any number of replication jobs can be defined
- Any number of source directory servers possible
- Flexible Queries:
- The object to be replicated can be selected via flexible queries. The whole realm or only defined OU's and/or objects for replication can be defined very flexible
- Synchronisation of target-directories and target-systems:
- Direct Comtarsia SignOn Gate control and automatic generation of SignOn requests
- SignOn Agents take over automatically user administration and user synchronisation on the target-directories and target-systems
- Extensive Log-functionality of the complete replication processes
- Extensive caching-functionality:
- Minimal load of LDAP server and target systems by replication cycle
- Enhanced performance of replication cycle via intelligent replication logics
- Reduced size of data transfer
- System requirements
- Comtarsia LDAP directory replicator is available for following server operating systems:
- Windows Server 2000
- Windows Server 2003
- Windows Server 2008
Download
Comtarsia software can be downloaded directly from their website.
http://signon.comtarsia.com/main/en/Download
Documentation
Comtarsia software documentation is located on their website:
http://signon.comtarsia.com/main/en/Manuals
For more information, contact
hedrick@rutgers.edu.
Last updated:
Tuesday, 20-Jul-2010 14:55:51 EDT
©
2010
Rutgers, The State University of New Jersey. All rights reserved.
