Chapter 5: Configuration

Console Security

5Click Help to access help on these items. See“Administration” on page 95 for details.

Anonymous access - Users can submit anonymous requests. Helpdesk will use a guest worker account for these requests. It is important to not enable this for consoles or folders that contain important Helpdesk commands like the Admin and Worker consoles. Instead, only consoles that offer limited functionality, such as the Guest console, should be configured to permit anonymous access.

Basic authentication - Workers can submit their identification (domain\username) and a password to be authenticated. Passwords are not transmitted using encryption, therefore we do not recommend this method under normal circumstances; however, if Basic Authentication is not enabled then Netscape and Opera users cannot connect to the Helpdesk Worker or Admin entry points.

Integrated Windows Authentication - This uses a cryptographic exchange with the user's Internet Explorer web browser to confirm the identity of the user. You should always configure every entry point to allow Integrated Windows authentication even if you do not expect the users of the consoles in that entry point to use it.

We recommend that all environments use Integrated Windows Authentication for tighter security.

Workers with Internet Explorer 4.01 (or higher) can pass their login credentials without any prompting. If IIS cannot authenticate the user logged in, then a dialog is displayed asking for a new NT credential. Passwords are not transmitted in the clear.

Workers with other browsers (Netscape, Opera) will see a dialog asking for an NT domain\username and a password (basic authentication). Because passwords are passed in the clear, we do not recommend using either Netscape or Opera.

Administrators

Helpdesk administrators are workers who have IIS and NTFS access to the AexHD\Admin console entry point. The Admin console defined in the Admin entry point contains all the administrative functions that Helpdesk provides. Integrated Windows authentication is enabled for the Admin console entry point.

See “Administration” on page 95 for details.

Workers

Workers are users who have been added to the Helpdesk database and created as workers by a Helpdesk administrator using the New worker command. Workers are identified by their NT domain\username and e-mail address.

The Worker entry point is through the Worker console, which contains all the Helpdesk functionality needed to manage work items, assets and contacts.

Altiris Helpdesk Solution User Guide

37