...
Info | ||
---|---|---|
| ||
Active Directory Authentication types Flowster Studio uses two values for the authentication type in the Active Directory entries: Secure and Secure Socket Layer. The Secure one: requests secure authentication. When this flag is set, the WinNT provider uses NTLM to authenticate the client. Active Directory Domain Services uses Kerberos, and possibly NTLM, to authenticate the client. When the user name and password are a null reference (Nothing in Visual Basic), ADSI binds to the object using the security context of the calling thread, which is either the security context of the user account under which the application is running or of the client user account that the calling thread is impersonating. The Secure Socket Layer one: Attaches a cryptographic signature to the message that both identifies the sender and ensures that the message has not been modified in transit. Active Directory Domain Services requires the Certificate Server be installed to support Secure Sockets Layer (SSL) encryption. Active Directory supports both Kerberos and NTLM. Windows will first try Kerberos and if all the requirements are not met, it will fallback to NTLM. Kerberos is the default authentication method for AD but it can fallback to NTLM in some cases, but that is handled by Windows itself. Kerberos is used every time a login to an AD is made. As an example, accessing file share by name like \server1\share would invoke Kerberos and should succeed given proper permission. But accessing same file share using IP address would invoke Kerberos first and fail (as there is no SPN for IP Address) and then fail over to NTLM. Here are some links for a better understanding of how the two protocols are working: https://msdn.microsoft.com/en-us/library/bb742516.aspx https://blogs.msdn.microsoft.com/chiranth/2013/09/20/ntlm-want-to-know-how-it-works/ |
User Roles
Flowster Studio defines following user roles and permissions:
- SuperAdmins - users that have full control over parent tenant. They can access without restriction all components of Flowster Studio and have access to modify tenant's data.
- Admins - users that have limited control over parent tenant. They can be created by superadmins or other admins. The limited permissions are defined and managed in Administrator → Security → Admin Permissions page.
- Users - users with no access on Administrator, they are permitted only to login and use Portal, Webpps and get explicitly permissions on Portal → Workflows from other users with superadmins/admins roles.
Users are grouped in Security Groups of the type presented above. The membership and permission of the user is valid only on the parent tenant. If the same user exists in another tenant, the role and permissions will be defined when accessing that tenant via Switch Tenant option in Administrator/Portal/Designer.
Security Groups
SuperAdmins type security group
...