
Access Control 36
2
Set up AD domain controller addresses. Separate multiple addresses with a
comma. For example, 192.168.0.250.
3
Specify a domain user for dcm.dell.com as Power Center server’s domain
account for Kerberos SSO. This user account must be an existing and valid
domain user account. For example, "Tom" and Tom’s password.
Step 2. Set up Service Principle Name (SPN) for Power Center service in
AD Domain Controller
1
Log into the AD domain controller as an Administrator.
2
Open a command console.
3
Add two SPNs for Power Center, use server FQDN in one SPN and server
NetBIOS name for the other SPN. The user account associated with
service SPN must be the Power Center server’s domain account for
Kerberos SSO configured during Power Center installation or in the
Settings
page. For example:
setspn -a HTTP/server1.dcm.dell.com Tom
setspn -a HTTP/server1 Tom
Step 3. Configure Web browser
You must configure your Web browser to support SSO. For more information
on how to configure this, see your Web browser Help. For a list of supported
Web browsers, see "System Requirements" in the "Overview" chapter.
NOTE: To correctly set up Kerberos SSO: 1) The date and time on all involved
computers must be consistent. 2) DNS configuration must be correct.
To support SSO in Firefox, you must send Kerberos credentials to the
appropriate KDC.
To support SSO in Internet Explorer, you must add the Power Center server
as a local Intranet site.
The following is an example of configuration steps in Microsoft Internet
Explorer 8:
1
Go to
Internet Explorer 8
→
Internet Options
→
Security
→
Local
Intranet,
and click
Sites
. The Local Intranet window opens.
2
Click
Advanced
, add your Power Center site into Local Intranet. For
example, server1.dcm.dell.com.
OpenManagePowerCenter_User_Guide.book Page 36 Friday, March 2, 2012 10:33 AM
Komentarze do niniejszej Instrukcji