Any and all passwords specified in this scenario are for example purposes only. To prevent a compromise to your system or network security, you should never use these passwords as part of your own configuration.
Optional: On the Create Batch File page, select Yes,
specify the following information, and click Next:
- Batch file: Add the text systemb to the end of the default batch file name. For example, type C:\Documents and Settings\All Users\Documents\IBM\Client Access\NASConfigsystemb.bat.
- Select Include password. This ensures that all passwords associated with the i5/OS service principal are included in the batch file. It is important to note that passwords are displayed in clear text and can be read by anyone with read access to the batch file. Therefore,
it is recommended that you delete the batch file from the Kerberos server and from your PC immediately after use.
If you do not include the password,
you will be prompted for the password when the batch file is run.
- On the Summary page, review the network authentication service configuration details. Click Finish.
- On the Specify Domain Controller page, specify the following information,
and click Next:
- Domain controller name: systema.myco.com
- Port: 389
- On the Specify User for Connection page, specify the following information, and click Next:
Specify the LDAP administrator's DN and password that you created earlier in this scenario on System A.
- User type: Distinguished name and password
- Distinguished name: cn=administrator
- Password: mycopwd
Any and all passwords specified in this scenario are for example purposes only.
To prevent a compromise to your system or network security, you should never use these passwords as part of your own configuration.
- On the Specify Domain page, select the name of the domain that you want to join. Click Next. For example, MyCoEimDomain.
- On the Registry Information page, select Local i5/OS and deselect Kerberos registry. (The Kerberos registry was created when you created the MyCoEimDomain domain.) Click Next.
Write down the registry names. You will need these registry names when you create associations to EIM identifiers.
- Registry names must be unique to the domain.
- You can enter a specific registry definition name for the user registry if you want to use a specific registry definition naming plan. However, for this scenario you can accept the default values.
- On the Specify EIM System User page, select the user the operating system uses when performing EIM operations on behalf of operating system functions,
and click Next:
Specify the LDAP administrator's DN and password that you created earlier in this scenario on System A.
- User type: Distinguished name and password
- Distinguished name: cn=administrator
- Password: mycopwd
Any and all passwords specified in this scenario are for example purposes only.
To prevent a compromise to your system or network security, you should never use these passwords as part of your own configuration.
- On the Summary page, confirm the EIM configuration. Click Finish.
Parent topic:
Scenario: Enabling single sign-on for i5/OS