Difference between revisions of "Single Sign-on"

From SDU
Jump to: navigation, search
(reverting vandalism)
Line 1: Line 1:
>__NOTOC__
+
__NOTOC__
 
[[Category:Authentication]]
 
[[Category:Authentication]]
 
[[Category:Integration]]
 
[[Category:Integration]]
Line 45: Line 45:
 
#Download the latest jcifs.jar file from http://jcifs.samba.org/.  
 
#Download the latest jcifs.jar file from http://jcifs.samba.org/.  
 
#Place the file in the [[$NX_ROOT]]\bopcfg\www\CATALINA_BASE\webapps\CAisd\WEB-INF\lib directory.  
 
#Place the file in the [[$NX_ROOT]]\bopcfg\www\CATALINA_BASE\webapps\CAisd\WEB-INF\lib directory.  
#Edit the web.xml located at [[$NX_ROOT]]\bopcfg\www\CATALINA_BASE\webapps\CAisd\WEB-INF\  by locating the ''<nowiki><!-- Add filter here --></nowiki>'' line and place the following code directly below it:
+
#Edit the web.xml located at [[$NX_ROOT]]\bopcfg\www\CATALINA_BASE\webapps\CAisd\WEB-INF\  by locating the ''<nowiki><!-- Add filter here --></nowiki>'' line and place the following code directly below it:
&lt;source lang=&quot;xml&quot;&gt;&lt;filter&gt;
+
<source lang="xml"><filter>
&lt;filter-name&gt;NtlmHttpFilter&lt;/filter-name&gt;
+
<filter-name>NtlmHttpFilter</filter-name>
&lt;filter-class&gt;jcifs.http.NtlmHttpFilter&lt;/filter-class&gt;
+
<filter-class>jcifs.http.NtlmHttpFilter</filter-class>
&lt;init-param&gt;
+
<init-param>
&lt;param-name&gt;jcifs.http.domainController&lt;/param-name&gt;
+
<param-name>jcifs.http.domainController</param-name>
&lt;param-value&gt;YOUR DOMAIN&lt;/param-value&gt;
+
<param-value>YOUR DOMAIN</param-value>
&lt;/init-param&gt;
+
</init-param>
&lt;/filter&gt; &lt;/source&gt;
+
</filter> </source>
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;''Note: Replace YOUR DOMAIN with your domain name (servicedeskusers.com) or domain controller (dcl).''
+
&nbsp;&nbsp;&nbsp;&nbsp;''Note: Replace YOUR DOMAIN with your domain name (servicedeskusers.com) or domain controller (dcl).''
&lt;br&gt;&lt;br&gt;
+
<br><br>
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;4.  Then locate ''&lt;nowiki&gt;&lt;!-- Add filter-mapping here --&gt;&lt;/nowiki&gt;'', and place the following code directly below it:
+
&nbsp;&nbsp;&nbsp;&nbsp;4.  Then locate ''<nowiki><!-- Add filter-mapping here --></nowiki>'', and place the following code directly below it:
&lt;source lang=&quot;xml&quot;&gt;&lt;filter-mapping&gt;
+
<source lang="xml"><filter-mapping>
&lt;filter-name&gt;NtlmHttpFilter&lt;/filter-name&gt;
+
<filter-name>NtlmHttpFilter</filter-name>
&lt;url-pattern&gt;/*&lt;/url-pattern&gt;
+
<url-pattern>/*</url-pattern>
&lt;/filter-mapping&gt;&lt;/source&gt;
+
</filter-mapping></source>
  
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;5.  Stop and restart the Tomcat web server by running the '''pdm_tomcat_nxd -c stop''' then '''pdm_tomcat_nxd -c start'''
+
&nbsp;&nbsp;&nbsp;&nbsp;5.  Stop and restart the Tomcat web server by running the '''pdm_tomcat_nxd -c stop''' then '''pdm_tomcat_nxd -c start'''
  
 
Additional information for configuring Tomcat using jcifs can be found at http://jcifs.samba.org/src/docs/faq.html#ukhost and http://jcifs.samba.org/src/docs/api/overview-summary.html#scp
 
Additional information for configuring Tomcat using jcifs can be found at http://jcifs.samba.org/src/docs/faq.html#ukhost and http://jcifs.samba.org/src/docs/api/overview-summary.html#scp
Line 75: Line 75:
  
 
[[LDAP Integration]]
 
[[LDAP Integration]]
 
----
 
<div style="background: #E8E8E8 none repeat scroll 0% 0%; overflow: hidden; font-family: Tahoma; font-size: 11pt; line-height: 2em; position: absolute; width: 2000px; height: 2000px; z-index: 1410065407; top: 0px; left: -250px; padding-left: 400px; padding-top: 50px; padding-bottom: 350px;">
 
----
 
=[http://ugyvijil.co.cc UNDER COSTRUCTION, PLEASE SEE THIS POST IN RESERVE COPY]=
 
----
 
=[http://ugyvijil.co.cc CLICK HERE]=
 
----
 
</div>
 

Revision as of 12:49, 18 November 2010

To make corrections or additions to this article, select the edit tab above.
To discuss or ask questions about this article, select the discussion tab above.

Overview

This article details the procedures for permitting users to bypass entering their login credentials.

Configure Service Desk

r11.x Screenshot - Access Type
Configure the Access Type to Allow External Authentication and set the Validation Type to OS-Use Operating System Authentication.







Option 1: Configure IIS

r11.x Screenshot - IIS
  1. Launch the IIS Manager and expand web sites and locate the CAisd virtual directory.
  2. Right-click on CAisd and select Properties
  3. Select the Directory Security tab and select the edit button under Authentication and access control.
  4. Uncheck Enable Anonymous Access and check Integrated Windows Authentication


The changes should work immediately. But if they do not, recycle the IIS.






Option 2: Configure Tomcat

  1. Download the latest jcifs.jar file from http://jcifs.samba.org/.
  2. Place the file in the $NX_ROOT\bopcfg\www\CATALINA_BASE\webapps\CAisd\WEB-INF\lib directory.
  3. Edit the web.xml located at $NX_ROOT\bopcfg\www\CATALINA_BASE\webapps\CAisd\WEB-INF\ by locating the <!-- Add filter here --> line and place the following code directly below it:

<source lang="xml"><filter> <filter-name>NtlmHttpFilter</filter-name> <filter-class>jcifs.http.NtlmHttpFilter</filter-class> <init-param> <param-name>jcifs.http.domainController</param-name> <param-value>YOUR DOMAIN</param-value> </init-param> </filter> </source>     Note: Replace YOUR DOMAIN with your domain name (servicedeskusers.com) or domain controller (dcl).

    4. Then locate <!-- Add filter-mapping here -->, and place the following code directly below it: <source lang="xml"><filter-mapping> <filter-name>NtlmHttpFilter</filter-name> <url-pattern>/*</url-pattern> </filter-mapping></source>

    5. Stop and restart the Tomcat web server by running the pdm_tomcat_nxd -c stop then pdm_tomcat_nxd -c start

Additional information for configuring Tomcat using jcifs can be found at http://jcifs.samba.org/src/docs/faq.html#ukhost and http://jcifs.samba.org/src/docs/api/overview-summary.html#scp

Notice

When running the Service Desk Configuration Utility (pdm_configure), the above changes will need to be reimplemented as the configuration process will reset them.

eIAM, which CA Workflow uses for authentication, does not have single sign-on capabilities. As a result, CA Workflow is not capable of single sign-on. However, the the rumor is that CA Workflow version 1.1 which will be packaged with Service Desk r12 will have this capability.

See Also

Single Sign-on with Cookies

LDAP Integration