Authenticating with Kerberos

The Solution Manager Server supports Single Sign-On using the Kerberos protocol. To enable Kerberos authentication in the Solution Manager Server, you have to:

  1. Perform the postinstallation tasks described in the section Setting-up Kerberos Authentication of the Denodo Platform Installation Guide.
  2. Indicate a Kerberos realm, if it is different from the one from your domain, as explained in the section Using Kerberos Authentication in Solution Manager Without Joining a Kerberos Realm of the Solution Manager Installation Guide.
  3. Enable Kerberos in the Virtual DataPort Server, as described in the section Setting-Up the Kerberos Authentication in the Virtual DataPort Server of the Virtual DataPort Administration Guide.
  4. Configure Kerberos in your browser, if you want to access through the Solution Manager Administration Tool.

If Kerberos authentication is properly configured, the login dialog will show you a new option to connect to the Solution Manager Administration Tool using Single Sign-On.

Single Sign-On dialog in the Solution Manager Administration Tool

Single Sign-On dialog in the Solution Manager Administration Tool

Important

To access the Solution Manager Administration Tool, remember to use the Fully Qualified Domain Name of the Server Principal Name you configured in the Solution Manager Virtual DataPort Server. For example, if your Server Principal Name is HTTP/denodo-prod.subnet1.contoso.com@CONTOSO.COM, you should access the Solution Manager Administration Tool through the URL http://denodo-prod.subnet1.contoso.com:19090/solution-manager-web-tool or https://denodo-prod.subnet1.contoso.com:9443/solution-manager-web-tool.