Configuring SSO in the browser
To configure your browser to authenticate SSO, complete the following task in your browser.
This is required only if Windows authentication method is configured for SAML in the Enabling the SAML Web browser SSO.
- Microsoft Internet Explorer
- Chromium
- Mozilla Firefox
- Admin UI
- https://<ipmserver.ipm.com>:<port>
- Persona-based UI
- https://<ipmserver.ipm.com>:<port>/mdm_ui
Note: The context root for the Admin UI is
/and for the Persona-based UI is
/mdm_ui. These are specified in the SAML properties and only these URL patterns are intercepted by the SAML web SSO TAI.
Microsoft Internet Explorer
- Open Microsoft Internet Explorer browser.
- Select
- Select Local intranet and click Sites to display the list of trusted sites.
- Select the following first two options.
- Include all local (intranet) sites not listed in other zones.
- Include all sites that bypass the proxy server are checked.
- Click Advanced and add the URL of the Identity Provider to list of trusted sites.
- Click Custom level, under User Authentication, and Logon, select Automatic logon with current username and password security setting.
- Select the Enable Integrated Windows Authentication is selected. section, ensure that
- Click OK and restart Microsoft Internet Explorer.
- Similar steps are applicable for the Trusted sites.
tab.
Chromium
If you are using Google Chromium, it automatically fetches all the settings that are done in the Microsoft Internet Explorer for the SSO.To import bookmarks from Microsoft Internet Explorer.
- Open Chromium browser.
- At the upper right, click More.
- Select .
- Select the program that contains the bookmarks you would like to import.
- Click Import and Done.
Mozilla Firefox
- Open the Mozilla Firefox browser.
- In the URL field, enter about:config, and press Enter.
- Ignore the warning, and click I accept the risk!.
- In the Search field, enter network.negotiate-auth.trusted-uris. This preference lists the trusted sites for Kerberos authentication.
- Double-click network.negotiate-auth.trusted-uris.
- In the Enter string value field, enter the Fully Qualified Domain Name (FQDN) of the host running the Product Master, and click OK.