The information in this article applies to:
SUMMARY
The Already Verified Authentication option is specified on the Security tab
of the COM Transaction Integrator (COMTI) Remote Environment (RE)
Properties dialog box.
MORE INFORMATIONRationale for Using "Already Verified Authentication"When using integrated host security with MTS package credentials or Windows NT user credentials, mainframe credentials cannot be ascertained by COMTI or the client application.COMTI and SNA Server act as a trusted entity, verifying the user's identity first. Therefore, there is no need to send a password to the mainframe, which would waste more cycles to check it on the mainframe side. Rationale for Ignoring "Already Verified Authentication" When Using COMTI Security OverrideIn this case, COMTI has direct access to the mainframe credentials. If COMTI would send only the user ID, an application could easily guess at one or another user ID, because user IDs are similar in most installations. Without having to know a password, the application could do things on the mainframe using the pilfered user ID.Identify security (ATTACHSEC=IDENTIFY in the CICS Connection definition) implies that the local logical unit (LU) on the computer has already verified the identity of the user, so the host can trust you. However, in the case of the application override, that is not true; COMTI is unable to determine who the user is. Additional query words:
Keywords : CTIAdmin CTIRE CTISecurity |
Last Reviewed: August 17, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |