1.4.5.8.1.4. Tabbed page "Login"

On the Login Tabbed page, you can restrict the login, once under Allowed web login methods and once under Allowed client login methods.

Tabbed page "Login [Login]"

Tabbed page "Login [Login]"

Allowed web login methods:

  1. Create new lines by clicking on the plus button.

  2. Enter a computer or domain name in the Hostname [Host name] column.

  3. Click in a field in the Methods column, open the list field with the options basis, ntlm and openid and activate the desired one.

Example:

Windows only (ntlm) Authentication

Windows only (ntlm) Authentication

Username/password (basic) and Windows authentication (ntlm)

Username/password (basic) and Windows authentication (ntlm)

Allowed client login methods:

  1. Create new lines by clicking on the plus button.

  2. Enter a domain (e.g. "CNS") or a host name (e.g. DE-AGB-NAME-01) in the Rule column.

  3. Click in a field in the Databases column, open the list field with the options WINDOWS, ERP, OPENIDC, SQL,FILE andLDAP and activate the desired ones.

    The options listed here are configured under the Rights management [Rights administration] category.

1.4.5.8.1.4.1. Requirements for Windows authentication

  1. Service runs as a local system and does not require access to network shares (requires access to network shares via UNC path)

    Standard configuration from Microsoft for Windows authentication (Kerberos) works. Only the computer name must be added to the Local Intranet Zone in the browser settings of the clients.

  2. Service requires access to external network shares. It must then run as a service user and the SPN entry (Service Principal Name) must be set correctly in the AD. And the computer name must be included in the Local Intranet Zone in the browser settings of the clients.

    Examples:

    setspn -S HTTP/servername.domain.name DOMAIN\serviceuser