SSO and Multiple Domino Domains

I’m having a problem with my SSO setup and hope someone can give me guidance.

I have three servers, each in a different Domino domain, but all in the same DNS domain. One is a mail server with Domino Web Mail running Domino 6.5, one is a Domino web server running Domino 6.5, and one is now a Team Workplace 6.5.1 server running Domino 6.5.1 IF1.

SSO has been configured and enabled on each one using Internet Site documents on the two Domino 6.5 servers and a Web Configuration document on the Team Workplace 6.51 server. The SSO document was created on one of the servers and copied to the other two, then the Domain field was updated accordingly (blank for the Web Config doc and named for the two Internet Site docs). The SSO documents load successfully on each server.

Now the problem:

I can log in first to the Domino web server and change to a Quickplace on the Team Workplace server or check my web mail on the mail server without having to log in again. It all works as expected.

I can log in first to check my mail and then move to a Quickplace without having to log in again. However, I can’t open the web site without having to log in again. Why does it work one way and not the other way?

It also works the same way logging into a Quickplace first. I can check my email without logging in, but I can’t open the web site without getting the login prompt.

What have I done wrong? I’ve read everything I can find and can’t seem to get this to work.

Thanks,

Mike

Subject: SSO and Multiple Domino Domains

Mike,this is most likely a time sync problem between your servers. I suppose your webserver is behind the others. Try to sync time through ntp, this should help.

Regards

Peter

Subject: RE: SSO and Multiple Domino Domains

That was it!! Thank you! The web server was behind by about 8 minutes. I’ve been working on this off and on for nearly two weeks and would have never thought to check the time syncronization between the servers. I bet I’ve completely reconfigured SSO on each of those servers 10 times. I guess it’s time to set up NTP!

Thanks again,

Mike