|
Home > Archive > WebSphere Portal Server > January 2008 > SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
You are viewing an archived Text-only version of the thread.
To view this thread in it's original format and/or if you want to reply to
this thread please [click here]
| Author |
SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
|
|
| GERMAN DAVID GIOVANON 2007-12-28, 1:40 am |
| <b>I WANT TO CREATE A <u>SINGLE SIGN ON</u> WITH MICROSOFT ACTIVE DIRECTORY ON LDAP OVER PORTAL. I HAVE READ SOME PEOPLE USE KERBEROS, TAI++ AND SPNEGO, BUT I DON'T KNOW HOW TO USE THEM AT ALL. PLEASE I REALLY NEED SOMEONE TO HELP ME WITH THIS AND GIVE M
E SOME EXPLANATIONS. THANKS...</b><br />
DAVID GIOVANON
| |
|
| WebSphere Portal 6 does not have out-of-the-box SSO support for windows desktop (Kerberos authentication), but it can be configured provided that you have a TAI module that supports that in place.<br />
<br />
If you wish to have help please contact me.<br />
<br />
Oved
| |
| nishant.kansal@wipro.com 2008-01-01, 1:39 am |
| Try the second option mentioned here using Websphere Security. This looks pretty easy to do.<br />
<a class="jive-link-external" href="http://www-1.ibm.com/support/docview.wss?uid=swg21140014">http://www-1.ibm.com/support/docvie...uid=swg21140014</a>
| |
| ovedy@mainsoft.com 2008-01-02, 7:33 am |
| Your suggestion does ndot work for SPNEGO and Kerberos. He is looking for a true windows desktop SSO solution.
| |
|
| Hi Oved,<br />
What do you mean by true SSO ? If my requirement gets fulfilled without custom TAI, then it is fine. SPNEGO and Kerberos are just other ways to achieve it.<br />
<br />
<ul class="jive-dash">
<li>NishK</li>
</ul>
| |
| ovedy@mainsoft.com 2008-01-02, 1:26 pm |
| You are absolutely right. there are many ways to achive SSO and the articles that you sent shows some of them.<br />
<br />
The title of the thread says Kerberos and SPNEGO specifically which allows delegation of the windows desktop credential to the Porta all the way to the database (where you can assign and revoke permissions to database resources based on the user credentia
ls) and thus I refered to it as a requirement.
|
|
|
|
|