Cascading Authentication

When you specify multiple authentication mechanisms for an InterSystems Service, InterSystems IRIS uses cascading authentication to manage user access to the system. InterSystems IRIS attempts to authenticate using the specified mechanisms in turn until one succeeds or until they all fail. The cascade depends upon the particular scenario.

Scenario 1: A InterSystems IRIS password user exists in the InterSystems IRIS system.

  1. Kerberos.

  2. OS-based.

  3. Instance Authentication

Scenario 2: An LDAP or Delegated user exists

  • No other authentication mechanism is tried.

Scenario 3: User name does not exist in InterSystems IRIS System

  1. LDAP.

  2. Delegated.

  3. Unauthenticated.

