Single sign-on

 

+

Search Tips   |   Advanced Search

 

With SSO support, Web users can authenticate once when accessing both WAS resources, such as...

...and resources in multiple WAS domains.

Application servers distributed in multiple nodes and cells can securely communicate using the LTPA protocol which encrypts, digitally signs, and securely transmits authentication-related data, and later decrypts and verifies signatures.

LTPA also provides the SSO feature wherein a user is required to authenticate only once in a DNS domain and can access resources in other WAS cells without getting prompted. Web users can authenticate once to a WAS or to a Domino server. This authentication is accomplished by configuring WAS servers and the Domino servers to share authentication information.

Without logging in again, Web users can access other WAS or Domino servers in the same DNS domain that are enabled for SSO.

 

Prerequisites and conditions

To use SSO between WAS servers or between WAS and a Domino servers, applications must meet the following prerequisites...




Sub-topics


Single sign-on for HTTP requests using SPNEGO
Kerberos configuration requirements for SPNEGO TAI
Global single sign-on principal mapping

 

Related tasks

Implementing single sign-on to minimize Web user authentications
Configure single sign-on capability with Tivoli Access Manager or WebSEAL