Configuring Web client browsers for Windows™ single sign-on
To set up Windows™ single sign-on for Web clients, you must set up browsers to authenticate to theIBM® Domino® server using SPNEGO.
To set up Internet Explorer
Procedure
- Log in to the Windows™ Active Directory domain.
- Start the browser and click .
- Click the Security tab.
- Select Local intranet and then click Sites.
- Ensure that Include all sites that bypass the proxy server is checked.
- Click Advanced.
- Add the URL for the Domino® server,
and click OK twice. For example, if the Domino® server name is domino1.subnet2.renovations.com,
specify:
http://domino1.subnet2.renovations.com
Or use a wildcard to provide the ability to connect to more than one SPNEGO-enabled Domino® server in the domain, for example:
http://*.subnet2.renovations.com
or
*.subnet2.renovations.com
- Click Custom Level, and scroll to the User Authentication section.
- Select Automatic logon only in Intranet zone, and click OK.
- Click the Advanced tab, scroll to the Security section, verify that the option Enable Integrated Windows Authentication (requires restart) is selected.
- If your proxy server configuration is done manually rather
than via automatic configuration script, complete these steps:
- Click the Connections tab.
- Click LAN Settings.
- Click Advanced.
- Add the Domino® server URL to the list Do not use proxy server for addresses beginning with, and click OK.
- Click OK again and restart the browser.
- From the browser, enter a URL to a database on the Domino® server to which you have
access and verify that you are not prompted for a name and password.
For example,
http://domino1.subnet2.renovations.com/mydatabase.nsf
To set up Mozilla or Firefox
Procedure
- Log in to the Windows™ Active Directory domain.
- Start the browser.
- In the URL address box, type:
about:config
- In the Filter box, type:
network.n
- Double-click network.negotiate-auth.trusted-uris,
and enter the URL for the Domino® server,
for example:
http://domino1.subnet2.renovations.com
Or use a wildcard to provide the ability to connect to more than one SPNEGO-enabled Domino® server, for example:
http://subnet2.renovations.com
Separate multiple entries with commas.
- Click OK and restart the browser.
- From the browser, enter a URL to a database on the Domino® server to which you have
access, and verify that you are not prompted for a name and password.
For example,
http://domino1.subnet2.renovations.com/mydatabase.nsf