Blackberry PRD-10459-003 Administration Guide - Page 231

Configuring single sign-on authentication for the BlackBerry Administration Service and BlackBerry Web Desktop Manager, Con constrained delegation for the Microsoft Active Directory account to support single sign-on authentication

Page 231 highlights

Administration Guide Configuring single sign-on authentication for the BlackBerry Administration Service and BlackBerry Web Desktop Manager b. Click the Add icon. c. Perform this step for each global catalog server that you want the BlackBerry Administration Service to access. 10. Click Save All. The BlackBerry Administration Service validates the information for Microsoft Active Directory authentication. If the information is valid, the BlackBerry Administration Service implements the changes immediately and you do not need to restart the BlackBerry Administration Service services. If the information is invalid, the BlackBerry Administration Service prompts you to specify correct information. Configuring single sign-on authentication for the BlackBerry Administration Service and BlackBerry Web Desktop Manager If you configure the BlackBerry® Administration Service to support Microsoft® Active Directory® authentication, you can turn on single sign-on authentication. Single sign-on authentication permits you to access the BlackBerry Administration Service and BlackBerry device users to access the BlackBerry Web Desktop Manager without requiring that you or the users type a Microsoft Active Directory user name and password. By default, if you log in to the BlackBerry Administration Service or users log in to the BlackBerry Web Desktop Manager using Microsoft Active Directory authentication, the browser prompts you or the users to type a Microsoft Active Directory user name and password. If you turn on single sign-on authentication, and you log in to a computer using a Microsoft Active Directory account, you can bypass the login screen and access the BlackBerry Administration Service and BlackBerry Web Desktop Manager directly. The BlackBerry Monitoring Service does not support single sign-on authentication. Before you turn on single sign-on, you must configure constrained delegation for the Microsoft Active Directory account for the BlackBerry Administration Service. Configure constrained delegation for the Microsoft Active Directory account to support single sign-on authentication 1. Use the Windows Server® ADSI Edit tool to add the following SPNs for the BlackBerry® Administration Service pool to the Microsoft® Active Directory® account : • HTTP/ (for example, HTTP/BASconsole104.example.com) • BASPLUGIN111/ (for example, BASPLUGIN111/BASconsole104.example.com) 2. If you create separate pools of BlackBerry Administration Service instances and BlackBerry Web Desktop Manager instances in the BlackBerry Administration Service pool, add the HTTP/ SPN for each pool to the Microsoft Active Directory account. 3. Configure the Microsoft Active Directory account for constrained delegation using the following settings: • trust this user for delegation to specific services only • use Kerberos™ only 229

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

b.
Click the
Add
icon.
c.
Perform this step for each global catalog server that you want the BlackBerry Administration Service to
access.
10.
Click
Save All
.
The BlackBerry Administration Service validates the information for Microsoft Active Directory authentication. If the
information is valid, the BlackBerry Administration Service implements the changes immediately and you do not
need to restart the BlackBerry Administration Service services. If the information is invalid, the BlackBerry
Administration Service prompts you to specify correct information.
Configuring single sign-on authentication for the
BlackBerry Administration Service and BlackBerry Web
Desktop Manager
If you configure the BlackBerry® Administration Service to support Microsoft® Active Directory® authentication, you
can turn on single sign-on authentication. Single sign-on authentication permits you to access the BlackBerry
Administration Service and BlackBerry device users to access the BlackBerry Web Desktop Manager without requiring
that you or the users type a Microsoft Active Directory user name and password. By default, if you log in to the
BlackBerry Administration Service or users log in to the BlackBerry Web Desktop Manager using Microsoft Active
Directory authentication, the browser prompts you or the users to type a Microsoft Active Directory user name and
password. If you turn on single sign-on authentication, and you log in to a computer using a Microsoft Active Directory
account, you can bypass the login screen and access the BlackBerry Administration Service and BlackBerry Web
Desktop Manager directly. The BlackBerry Monitoring Service does not support single sign-on authentication.
Before you turn on single sign-on, you must configure constrained delegation for the Microsoft Active Directory
account for the BlackBerry Administration Service.
Configure constrained delegation for the Microsoft Active Directory
account to support single sign-on authentication
1.
Use the Windows Server® ADSI Edit tool to add the following SPNs for the BlackBerry® Administration Service
pool to the Microsoft® Active Directory® account :
HTTP/<
BAS_pool_FQDN
> (for example, HTTP/BASconsole104.example.com)
BASPLUGIN111/<
BAS_pool_FQDN
> (for example, BASPLUGIN111/BASconsole104.example.com)
2.
If you create separate pools of BlackBerry Administration Service instances and BlackBerry Web Desktop
Manager instances in the BlackBerry Administration Service pool, add the HTTP/<
BAS_pool_FQDN
> SPN for each
pool to the Microsoft Active Directory account.
3.
Configure the Microsoft Active Directory account for constrained delegation using the following settings:
trust this user for delegation to specific services only
use Kerberos™ only
Administration Guide
Configuring single sign-on authentication for the BlackBerry Administration Service and BlackBerry
Web Desktop Manager
229