BusinessObjects Enterprise Administrator's Guide

Configuring the Windows AD plug-in for Kerberos authentication

In order to support Kerberos single sign-on, you have to configure the Windows AD security plug-in in the CMC to use Kerberos authentication. This includes:

To configure the Windows AD security plug-in
  1. Go to the Authentication management area of the CMC.
  2. Click the Windows AD tab.
  3. Ensure that the Windows Active Directory Authentication is enabled check box is selected.
  4. Select the Single sign-on is enabled check box.
  5. Note:    For related information about configuring the Windows AD plug-in, see Managing AD accounts.

  6. Set up the AD administrator account:
    1. Click AD Administrator Name.
    2. Enter the name and password for the account and the default AD Domain.
    3. Note:    The AD Administrator account requires read access to Active Directory only; it does not require any other rights.

    4. Click Update.
  7. In the "Mapped AD Member Group" area, map the AD group for the AD users who require access to BusinessObjects Enterprise via AD authentication and single sign-on. See Mapping AD accounts.
  8. Under Authentication Options select the following:
  9. Click Update.


Business Objects
http://www.businessobjects.com/
Support services
http://www.businessobjects.com/services/support/
Product Documentation on the Web
http://support.businessobjects.com/documentation/