Is there a way to configure Domino to use a desktop login with AD to allow access to a Domino Web site within the same domain?
Also is there a way to have SSO between a Domino site and a IIS server within the same domain.
I have users that do not want to authenticate to a Domino web app once the have logged into their desktop. They also do not want to have to authenticate when clicking alink to apps hosted on our IIS servers.
My Domino server uses LDAP to authenticate. The UN and PW are the same as the one used for the desktop.
Subject: SSO using desktop AD
I think that you are getting some concepts mixed.
Firstly SSO and LDAP are two different things and are not connected. Secondly, Domino uses LtpaToken for SSO, IIS can use a variety of mechanisms (but it doesn’t include LtpaToken).
The heart of your question revolves around what you want to use as the organisation authentication mechanism? Do you want Active Directory, do you want Domino LDAP, do you want some other organisation wide mechanism?
The answer to that question will determine where you go from there.
Regards
Rolf Pfotenhauer
Subject: RE: SSO using desktop AD
My Domino application is a Portal that maintains links to other applications on IIS, and some other servers.
I am sure the IIS sites are using AD.
On our Domino site we use a LDAP connection to NDS for authentication
The users ID and Password are the same on AD and NDS. If the PW is changed in AD then it is changed in NDS.
The NAB is only used for ACL groups by the Portal application.
Here is the users request/expectation…
They receive a Email with links to the PORTAL-Content. They do not want to have to authenticate to access the portal or content.
This tells me that I need some way to pass authentication from the desktop to Domino and then to IIS. I am sure it is possible between the desktop and IIS so I am not to worried about IIS content on the portal.
What I think I need is some way to have SSO using the desktop login(AD) and Domino.
If that means abandoning the NDS-LDAP connections and start using a AD-LDAP connect for Domino then OK.
I am not sure what is available and has been done by other Domino sites.
Then minimum I would like to accomplish is to be able to identify/authenticate a user coming into a Domino web application within our domain.
If they access from home they should get a login prompt. The IIS sites can use whatever is available from MS to pickup the authentication from the user’s desktop.
Thanks Mark.
Subject: RE: SSO using desktop AD
There is still a lot about your environment that I do not understand well enough to give you any advice.
For example, your NDS-LDAP connection appears to be your central authentication mechanism as I explained on my last post. However, when you say that user and password are the same on AD and NDS, how is that achieved?
Secondly, by what mechanism do you achieve IIS to AD authentication? Is it by JNDI, by C, by C++, or some other means?
Send me an email, I will try to point you in the right direction.
Regards
Rolf Pfotenhauer
email: rolfpf@yahoo.com.au