• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • EIM Identifier Naming

    June 2, 2015 Patrick Botz

    Enterprise Identity Mapping (EIM) is the technology that allows the IBM i to determine which user profile should be used to establish a connection for a person who has authenticated to an IBM i interface using non-IBM i credentials. EIM is easy to set up, but there is one thing you can do that will save you time and effort later.

    A quick overview of EIM will help explain the tip. EIM consists of three categories of information:

    1. EIM Identifiers representing people and entities (e.g., service userIDs) within the organization that have user IDs
    2. User Registry Definitions representing the various places where userIDs are defined (Active Directory, each IBM i partition, application related user registries, etc.)
    3. Identity Mapping Associations which represent the relationship between a specific user ID in a particular user registry and the EIM Identifier with which it is associated

    EIM Identifiers consist of an identifier name, an optional description, optional additional information–called aliases in iNavigator–and user ID associations for that identifier. In working with customers implementing SSO, I find the first thought most folks have for naming EIM identifier is to use the name of the person represented by the EIM Identifier.

    This makes sense except for one thing: names change. They change due to marriage, divorce, and personal choice. It’s hard to transfer institutional knowledge such as “Jane Doe is really Jane Washington who got married 10 years ago and changed her name” to new administrators. This alone wouldn’t be too big of an issue. However, the only way to change the EIM Identifier name is to delete it. All the other data in or associated with an EIM identifier can be changed, but not the identifier name.

    I recommend that employee numbers be used for EIM Identifier names. Most companies use them and they don’t change. If your company doesn’t use employee numbers, I recommend assigning a unique number for each new identifier. If you have 1,000 employees, for example, you might assign “1” to the first identifier created, “2” to the second, and so on. To make displays and reports look a little neater, you might use “0001”, “0002” and so on instead. It doesn’t matter what value is assigned to which identifier as long as it is unique.

    So how does an administrator know which EIM identifier represents which person? That’s a great question and there’s an easy answer: Put the person’s full name in the description field. This works great because the EIM management GUI in iNavigator shows the identifier name in the first column and the description in the second column. Better yet, you can sort on either field. So if you’re looking for the identifier for a particular person, just sort on the description field and the names will be in alphabetical order. If you want the names to be sorted on last name, just put the last name first in the description field (e.g. “Botz, Patrick” or “Botz, Patrick S” if you are worried about people that share names like “John J Johnson” and “John E Johnson”). The description field can contain nearly any character you can figure out how to enter from a keyboard, so that shouldn’t be an issue either.

    Patrick Botz is President and CTO of Botz & Associates. His expertise includes security strategy, security policy enforcement, password management, single sign-on (SSO), industry and government compliance, and biometrics. He is the architect of the SSO stat! service. Previously he worked as Lead Security Architect at IBM, and he founded the IBM Lab Services security consulting team. You can connect with Pat here.

    RELATED STORY

    Job User Name And Current Job User

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    The Omni User:  Chicago's OMNI Technical Conference, June 4-5, Palos Hills, Illinois
    ASNA:  Create great IBM i-driven smartphone and tablet mobile apps with nothing but plain ol' RPG.
    LaserVault:  FREE ON-DEMAND WEBINAR: Understanding Tapeless Backups. Watch it now >

    SQL Query And Report Tool Gets The ProData Treatment HelpSystems Adds SkyView Partners To Its Security Assets

    Leave a Reply Cancel reply

Volume 15, Number 11 -- June 2, 2015
THIS ISSUE SPONSORED BY:

WorksRight Software
SEQUEL Software
United Computer Group, Inc.

Table of Contents

  • Paging Cursors And Position To
  • Beware The Temporary Table
  • EIM Identifier Naming

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle