Topics

04 Documentation updates
Server
Enabling Single Sign-on for Domino and WebSphere servers

Beginning with R5.0.5, Web users can log on once to a Domino or WebSphere server, then access any other Domino or WebSphere server in the same DNS domain that are enabled for Single Sign-on (SSO) without logging on again. This is accomplished by selecting a new "Multi-server" option (in a Server document) for session-based authentication, along with creating a new domain-wide configuration document in the Domino Directory called the Web SSO Configuration document. This document, which should be replicated to all servers participating in the Single Sign-on domain, is encrypted for participating servers and contains a shared secret used by servers for authenticating user credentials.

All servers participating in Single Sign-on must be at the Domino 5.0.5 level or above. The users' Web browsers must have cookies enabled since the authentication token that is generated by the server is transported to the browser in a cookie.

Notes:


Step One: Create the Web SSO Configuration document
Step Two: Enable Single Sign-on in the server document and Basic Authentication
Step Three: Start the HTTP task on the Single Sign-on enabled servers

Setting up the Web SSO Configuration document for more than one Domino domain

Single Sign-on used with Domino/IIS servers
For more information about troubleshooting Single Sign-on, please refer to the "Troubleshooting Single Sign-on for Domino and WebSphere" Release Note (in the "Troubleshooting/Server Issues" section).