Skip to main content

developerWorks >  WebSphere  >  Forums  >  WebSphere Portal  >  developerWorks

SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO    Point your RSS reader here for a feed of the latest messages in this thread


Tags for this thread: 

     

 
 

My developerWorks
 Welcome, Guest
Sign in or register
Permlink Replies: 10 - Pages: 1 - Last Post: Nov 6, 2009 10:04 AM Last Post By: JMW98
GERMAN DAVID GI...

Posts: 12
Registered: Dec 24, 2007 09:39:13 AM
SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Dec 27, 2007 10:12:08 PM
Click to report abuse...   Click to reply to this thread Reply
I WANT TO CREATE A SINGLE SIGN ON WITH MICROSOFT ACTIVE DIRECTORY ON LDAP OVER PORTAL. I HAVE READ SOME PEOPLE USE KERBEROS, TAI++ AND SPNEGO, BUT I DON'T KNOW HOW TO USE THEM AT ALL. PLEASE I REALLY NEED SOMEONE TO HELP ME WITH THIS AND GIVE ME SOME EXPLANATIONS. THANKS...
DAVID GIOVANON
Oved

Posts: 11
Registered: Apr 02, 2006 10:36:14 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Dec 31, 2007 04:14:05 AM   in response to: GERMAN DAVID GIOVANON in response to: GERMAN DAVID GIOVANON's post
Click to report abuse...   Click to reply to this thread Reply
WebSphere Portal 6 does not have out-of-the-box SSO support for windows desktop (Kerberos authentication), but it can be configured provided that you have a TAI module that supports that in place.

If you wish to have help please contact me.

Oved
N

Posts: 13
Registered: Sep 07, 2007 05:17:59 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Dec 31, 2007 10:24:23 PM   in response to: GERMAN DAVID GIOVANON in response to: GERMAN DAVID GIOVANON's post
Click to report abuse...   Click to reply to this thread Reply
Try the second option mentioned here using Websphere Security. This looks pretty easy to do.
http://www-1.ibm.com/support/docview.wss?uid=swg21140014
Oved

Posts: 11
Registered: Apr 02, 2006 10:36:14 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Jan 02, 2008 07:47:22 AM   in response to: N in response to: N's post
Click to report abuse...   Click to reply to this thread Reply
Your suggestion does ndot work for SPNEGO and Kerberos. He is looking for a true windows desktop SSO solution.
N

Posts: 13
Registered: Sep 07, 2007 05:17:59 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Jan 02, 2008 10:21:23 AM   in response to: Oved in response to: Oved's post
Click to report abuse...   Click to reply to this thread Reply
Hi Oved,
What do you mean by true SSO ? If my requirement gets fulfilled without custom TAI, then it is fine. SPNEGO and Kerberos are just other ways to achieve it.

  • NishK
Oved

Posts: 11
Registered: Apr 02, 2006 10:36:14 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Jan 02, 2008 10:30:08 AM   in response to: N in response to: N's post
Click to report abuse...   Click to reply to this thread Reply
You are absolutely right. there are many ways to achive SSO and the articles that you sent shows some of them.

The title of the thread says Kerberos and SPNEGO specifically which allows delegation of the windows desktop credential to the Porta all the way to the database (where you can assign and revoke permissions to database resources based on the user credentials) and thus I refered to it as a requirement.
Stegra

Posts: 1
Registered: Nov 06, 2009 05:32:23 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Nov 06, 2009 05:33:31 AM   in response to: Oved in response to: Oved's post
Click to report abuse...   Click to reply to this thread Reply
Is there any new conclusion? Any hints to achive SSO between Windows and Portal?
Akash Bharti

Posts: 130
Registered: Jul 15, 2007 03:08:08 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Nov 06, 2009 06:28:52 AM   in response to: Stegra in response to: Stegra's post
Click to report abuse...   Click to reply to this thread Reply
http://www.ardenagopyan.com/downloads/tutorials/WPS-SPNEGO-TAI.pdf

Thanks
Akash
marcoensing

Posts: 5
Registered: Oct 26, 2009 09:22:07 AM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Nov 06, 2009 07:44:50 AM   in response to: GERMAN DAVID GIOVANON in response to: GERMAN DAVID GIOVANON's post
Click to report abuse...   Click to reply to this thread Reply
Hi David,

Wrote a few things on my page some time ago about setting up SPNEGO with Portal and AD, maybe
this can help you any further.

http://www.lotusconnections.org/wordpress/index.php/category/sso/

Regards,

Marco

ps. better don't use your CAPS key too much, doesn't look/sounds very nice
JMW98

Posts: 181
Registered: Jun 12, 2008 02:41:10 PM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Nov 06, 2009 10:01:41 AM   in response to: GERMAN DAVID GIOVANON in response to: GERMAN DAVID GIOVANON's post
Click to report abuse...   Click to reply to this thread Reply
Are you on 6.1? If so:
http://publib.boulder.ibm.com/infocenter/wpdoc/v6r1/index.jsp?topic=/com.ibm.wp.ent.doc_v6101/config/cfg_spnego.html

That will address login/authentication. VMM configuration will point to MSAD and will cover the authorization side of things.

You might also find this helpful:
http://www-10.lotus.com/ldd/portalwiki.nsf/dx/test-6.1-spnego
(Test infrastructure: Simple and Protected Negotiation Mechanism (SPNEGO) testing with WebSphere Portal 6.1)
JMW98

Posts: 181
Registered: Jun 12, 2008 02:41:10 PM
Re: SSO , ACTIVE DIRECTORY, LDAP , KERBEROS , TAI++ , SPNEGO
Posted: Nov 06, 2009 10:04:08 AM   in response to: GERMAN DAVID GIOVANON in response to: GERMAN DAVID GIOVANON's post
Click to report abuse...   Click to reply to this thread Reply
Also, if you are on 6.0, you might want to use Tivoli Access Manager (TAM) to get SPNEGO support, per:
http://www.redbooks.ibm.com/redpapers/pdfs/redp4339.pdf
 Tags
Help

Use the search field to find all types of content in My developerWorks with that tag.

Use the slider bar to see more or fewer tags.

Popular tags shows the top tags for this particular type of content or application that you're viewing.

My tags shows your tags for this particular type of content or application that you're viewing.

 

MoreLess 


Point your RSS reader here for a feed of the latest messages in all forums