cancel
Showing results for 
Search instead for 
Did you mean: 

BO 3.1 Web Tier Server and Active Directory Authentication

Former Member
0 Kudos

We have a BO 3.1 SP3 environment setup and running AD SSO perfectly.

However the project people want to have an external BO server on the internet as well so I decided to do a web tier server install.

Install is up and running and I can log in with Enterprise authentication to it. However they want AD authentication as well.

How do I get the web tier server to authenticate with AD like the cluster does now? I don't want SSO so the users will be prompted for sign in which is fine.

The problem I have is that this server will be in a DMZ and not a domain member and not running with domain credentials. I was hoping the web tier server would simple pass login information to the CMS servers that would then verify it against either enterprise authentication or AD but that doesn't seem to be the case.

Does anyone know if it can be done and how?

Accepted Solutions (0)

Answers (1)

Answers (1)

julian_jimenez
Active Contributor
0 Kudos

Hi Mike,

If you need AD authentication, your Web Application server must be able to contact Kerberos servers (AD controllers) in order to create valid tickets. No username or password is passed to the CMS.

It is not possible to use AD authentication in the configuration that you have.

Regards,

Julian

0 Kudos

Hi,

a possible workaround could be that you use the LDAP Authentication at your external Web Tier Server.

Regards

-Seb.