To enable this feature, all of the following must be configured:

Enable Authentication before Allocation on the General page of System Settings on the HP SAM administrative console.

Ensure that a certificate from the domain certificate authority is installed on the HP SAM website in IIS on the HP SAM server.

The following option must be enabled via the HP SAM client configuration file on all access devices: AuthenticateBeforeAllocation=1.

There is no setup needed for the web client, but the user must type in the URL using https instead of http (e.g., https://samserver).

Ensure that communication between the access device and the HP SAM Server via SSL (typically port 443) is not blocked by a firewall.

The Allow Expired Password setting in System Settings gives the HP SAM administrator the option to allow users with expired passwords to continue on so that they can change the password using the operating system on the resource.

NOTE: Versions of the HP SAM client prior to HP SAM 2.3 cannot be used when this feature is enabled.

This feature is not compatible with Smart Card single sign-on and must be disabled before using Smart Cards.

84 Chapter 4 Administration