COGNOiSe.com - The IBM Cognos Community

IBM Cognos 10 Platform => Cognos 10 BI => Cognos Administration => Topic started by: crogers9 on 19 Nov 2013 05:27:28 AM

Title: Single Sign on AD
Post by: crogers9 on 19 Nov 2013 05:27:28 AM
I am trying to configure single sign through AD using Kerberos delegation, however the best I can get is the username populated in the login box, I have followed the instructions as per the IBM infocentre, is there something I have missed or is there something missing from the IBM instructions, I am on Cognos 10.2.1
Title: Re: Single Sign on AD
Post by: murali999 on 19 Nov 2013 07:56:28 AM
Hi,

What is the OS and IIS version,

and let us know what are the steps you have done for enabling the Single Signon
Title: Re: Single Sign on AD
Post by: crogers9 on 20 Nov 2013 04:04:10 AM
Hi thanks for asking

Its Windows Server 2008R2 with IIS7.5.

We have folowed the insturctions as per this the ibm info centre

http://pic.dhe.ibm.com/infocenter/cfpm/v10r1m0/index.jsp?topic=%2Fcom.ibm.swg.im.cognos.inst_cr_winux.10.1.0.doc%2Finst_cr_winux_id17682stp_SSO_active_drctry.html

details below

Steps for Single Signon Using Kerberos Delegation

Set up Windows integrated authentication on the IIS Web server.

Install Content Manager in a location that is part of the domain, for the active and standby Content Managers.

Set up the computers, or the user account under which Content Manager runs, to be trusted for delegation.

When setting up the computers using the Active Directory user tool, do not select the Account attribute, which is sensitive and cannot be delegated.
Title: Re: Single Sign on AD
Post by: murali999 on 25 Nov 2013 04:49:12 AM
Hi,

1.Have you enabled the Windows Authentication in IIS on cognos virtual Directory -> cgi-bin->cognosisapi.dll ?
2.Adn also you need to disable the Anonymous Authentication got the cognosisapi.dll file

Regards,
Murali.
Title: Re: Single Sign on AD
Post by: crogers9 on 25 Nov 2013 09:48:54 AM
Windows authentication has been enabled on the entire IIS website and disabled anonymous logon.
Title: Re: Single Sign on AD
Post by: SomeClown on 26 Nov 2013 06:07:10 AM
Might not apply, but on client-side, the webserver is listed in Local Intranet sites in IE? (Trusted is typically not open enough for it to work).