Configuring the IBM® Content Manager server for SSO
Configure the IBM® Content Manager Enterprise Edition server for single sign-on.
Before you begin
These steps assume you have installed HCL Connections, IBM® Content Manager Enterprise Edition, IBM® FileNet® Collaboration Services, and a Lightweight Directory Access Protocol (LDAP) server. They also assume the LDAP server is shared by IBM® Content Manager, IBM® FileNet® Collaboration Services, and HCL Connections.
Procedure
- Disable the required password setting:
- Start the IBM® Content Manager system administration client.
- Click from the menu.
- Clear the Password is required for all users logging on to CM check box.
- Click OK
- Allow trusted log ons:
- In the navigation pane, click .
- Right-click Library Server Configuration and select Properties.
- Set Max user action to Allow logon without warning and select the Allow trusted logon check box.
- Click OK.
- Set up LDAP user import information:
- Create privilege set for SSO users:
- Add LDAP users:
- Log in to the IBM® Content Manager system administration client.
- Expand Authentication.
- Right-click and select .
- Set Password expiration to
Never expires
. - Click LDAP and provide the user name you want to import.
- After the names are returned, highlight the name and click OK.
- Set Maximum privilege set to
SSOPriv
, the privilege set that you created in Step 4. - In the Set Default panel, enter Default item access control list and click OK to create new SSO user.
- Restart the IBM® Content Manager server.
- Install the LDAP client to enable LDAP users to log in:
Note: If the LDAP server is an IBM® Tivoli® Directory Server (ITDS), install the ITDS client on the same machine as IBM® Content Manager.
- During the LDAP client installation, select the Java™ client and C client only.
- Add the following file path to the
PATH
environment variable:C:\IBM\LDAP\V6.1\bin;C:\IBM\LDAP\V6.1\lib;
- Copy the DLL file from the C:\Program Files\IBM\db2cmv8\ldap directory to the C:\Program Files\IBM\db2cmv8\cmgmt\ls\icmnlsdb directory.
- Restart the LDAP server.
- Verify the LDAP setup:
- Install the IBM® Content Manager Enterprise Edition Client for Windows®.
- Verify whether the LDAP user can log in to IBM® Content Manager server using the client.