BusinessObjects Enterprise Administrator's Guide
Configuring the Windows AD plug-in for Kerberos authentication
In order to support Kerberos single sign-on, you have to configure the Windows AD security plug-in in the CMC to use Kerberos authentication. This includes:
- Ensuring Windows AD authentication is enabled.
- Setting up an AD Administrator account. This account requires read access to Active Directory only; it does not require any other rights.
- Enabling Kerberos single sign-on and setting the service principal name (SPN) to use a service account.
To configure the Windows AD security plug-in
- Go to the Authentication management area of the CMC.
- Click the Windows AD tab.
- Ensure that the Windows Active Directory Authentication is enabled check box is selected.
- Select the Single sign-on is enabled check box.
Note: For related information about configuring the Windows AD plug-in, see Managing AD accounts.
- Set up the AD administrator account:
- Click AD Administrator Name.
- Enter the name and password for the account and the default AD Domain.
Note: The AD Administrator account requires read access to Active Directory only; it does not require any other rights.
- Click Update.
- In the "Mapped AD Member Group" area, map the AD group for the AD users who require access to BusinessObjects Enterprise via AD authentication and single sign-on. See Mapping AD accounts.
- Under Authentication Options select the following:
- Click Update.