Configuring single sign-on

You can connect to an IBM® SPSS® Modeler Server that is running on any supported platform using Single Sign-On. To connect using Single Sign-On, you must first configure your IBM SPSS Modeler server and client machines.

If you are using Single Sign-On to connect to both IBM SPSS Modeler Server and IBM SPSS Collaboration and Deployment Services, you must connect to IBM SPSS Collaboration and Deployment Services before you connect to IBM SPSS Modeler.

IBM SPSS Modeler Server uses Kerberos for Single Sign-On.

Kerberos is a core component of Windows Active Directory, and the following information assumes an Active Directory infrastructure. In particular:

  • The client computer is a Windows computer that is joined to an Active Directory domain
  • The client user has logged in to the computer using a domain account. The mechanism used to log in is unimportant and may employ a smart card, fingerprint, etc.
  • IBM SPSS Modeler Server can validate the client user's credentials by reference to the Active Directory domain controller

This documentation describes how both Windows and UNIX servers can be configured to authenticate this way. Other configurations may be possible but are untested.

To inter-operate with most modern, secure Active Directory installations, you must install the high-strength encryption pack for Java because the required encryption algorithms are not supported by default. You must install the pack for both client and server. An error message such as Illegal key size is displayed on the client when a server connection fails because the pack is not installed. See Installing unlimited strength encryption.