BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 09-20-2010, 09:34 AM   #1
svaldes
New Member
 
Join Date: Sep 2007
Model: 8700g
PIN: N/A
Carrier: Movistar Argentina
Posts: 9
Default Enbaled Single Sign-On on BES 5.0.2

Please Login to Remove!

I have folowed the BB articles about enabling SSO on out recentrly updated BES 5.0.2 and is not working, theres any particular log to check for errors on SSO?

Thanks.
Offline  
Old 12-08-2010, 03:51 PM   #2
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default Re: Enbaled Single Sign-On on BES 5.0.2

try this Configure BES 5.0.2 SSO / Auto Logon (Active Directory) « digital Jive
Offline  
Old 12-09-2010, 03:40 PM   #3
RadHaz75
Talking BlackBerry Encyclopedia
 
RadHaz75's Avatar
 
Join Date: Feb 2006
Location: Philadelphia
Model: 9650
OS: 6.0.0.524
PIN: BALL
Carrier: Verizon Wireless
Posts: 456
Default Re: Enbaled Single Sign-On on BES 5.0.2

that article finally got me set stright. i had been trying off and on for months to get it working. the part that rims documentation is not clear about is that the account needs to REPLACE the one listed in the "Microsoft Active Directory login information" section. i kept trying to add the new account to the last section where it asks for the account forrest name info.
__________________
Two months ago, I saw a provocative movie on cable TV. It was called The Net, with that girl from the bus.
Offline  
Old 12-09-2010, 03:57 PM   #4
hutchingsp
Thumbs Must Hurt
 
Join Date: Nov 2010
Model: 9300
PIN: N/A
Carrier: Vodafone
Posts: 52
Default Re: Enbaled Single Sign-On on BES 5.0.2

Hmm.. can I just confirm what the SSO extends to?

Right now if I go to File Shares via the BES/MDS I'm prompted for user credentials. That's what we want as our shares are locked down using NTFS permissions so using the besadmin account wouldn't be acceptable, but it would be useful if users weren't prompted for their credentials.
Offline  
Old 12-10-2010, 08:44 AM   #5
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default Re: Enbaled Single Sign-On on BES 5.0.2

Quote:
Originally Posted by hutchingsp View Post
Hmm.. can I just confirm what the SSO extends to?

Right now if I go to File Shares via the BES/MDS I'm prompted for user credentials. That's what we want as our shares are locked down using NTFS permissions so using the besadmin account wouldn't be acceptable, but it would be useful if users weren't prompted for their credentials.
access to internal resources , shares or intranet sites are setup using delegated account, DO NOT user BESADMIN for delegation, if you want BB users not to type password then use delegated account in permissions first and then setup MDS to use this delegated account to access the resources



"SINGLE SIGN-ON allows end users and administrators to directly and securely access BlackBerry Web Desktop Manager and BlackBerry Administration Service once they have signed in to the network without the need to re-enter their user ID and password. (This is when they are accessing from their windows machine NOT from smart phone). Smartphone users can be allowed access to the intranet, files and business systems "behind the firewall" directly from their BlackBerry smartphone without the need to enter their network password with the device already authenticated via Active Directory and BlackBerry Enterprise Server. For smart phone users, it is not a direct single sign-on like from your windows machine. It is achieved by configuring the Microsoft Active Directory account to delegate access to an intranet site.

After you configure the BlackBerry MDS Connection Service (which is used to access intranet resources) to support Integrated Windows authentication, the BlackBerry MDS Connection Service uses the Microsoft Active Directory account to verify login information for a user and access the network resources on behalf of the user. The BlackBerry Enterprise Server then sends information from the network resources to the user's device.

Here are most important prerequisites to achieve this

Prerequisites: Configuring the Microsoft Active Directory account to delegate access to an intranet site

Verify that you configured Integrated Windows® authentication for the application server that hosts the intranet site.
Verify that the application server that hosts the intranet site and the web application that runs on the application server support Kerberos™ authentication.

References

BES 5.0.2 MDS Connection Service with Integrated A... - BlackBerry Support Community Forums

Configuring Integrated Windows authentication so that users can access resources on your organization's network - Administration Guide - BlackBerry Enterprise Server for IBM Lotus Domino - 5.0.2

KB22726-Configure the delegation user account to delegate access to network resources
Offline  
Old 12-10-2010, 01:21 PM   #6
hutchingsp
Thumbs Must Hurt
 
Join Date: Nov 2010
Model: 9300
PIN: N/A
Carrier: Vodafone
Posts: 52
Default Re: Enbaled Single Sign-On on BES 5.0.2

Thanks, but I'm still unclear.

My network account is DOMAIN\Joe

On my Blackberry right now, if I go to files and try access \\server\share it prompts me for my credentials (with the "remember" option).

That's fine because Joe should only be able to access a shared folder to which his account has access.

What I'm not clear on is whether the SSO stuff means Joe doesn't need to enter his credentials but "somehow" BES knows it's Joe and connects to \\server\share as Joe?
Offline  
Old 12-10-2010, 01:37 PM   #7
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default Re: Enbaled Single Sign-On on BES 5.0.2

Quote:
Originally Posted by hutchingsp View Post
Thanks, but I'm still unclear.

My network account is DOMAIN\Joe

On my Blackberry right now, if I go to files and try access \\server\share it prompts me for my credentials (with the "remember" option).

That's fine because Joe should only be able to access a shared folder to which his account has access.

What I'm not clear on is whether the SSO stuff means Joe doesn't need to enter his credentials but "somehow" BES knows it's Joe and connects to \\server\share as Joe?
for SSO you will create a active directory account, and grant that account access to your file share, when BB user Joe will access the share via AD account

so not a good idea for shares and resources with multiple access level, since there is no way that BES MDS will recoginize a BB user as your domain\joe
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Schneider Electric Energy Server EBX510 Server For Energy Management- picture

Schneider Electric Energy Server EBX510 Server For Energy Management-

$4350.00



FANUC Server Driver A06B-6077-H111 picture

FANUC Server Driver A06B-6077-H111

$2158.86



FANUC Server Driver A06B-6117-H211 picture

FANUC Server Driver A06B-6117-H211

$3993.99



Server SE-SS 07020 Server Express Single Drop-In - NEW - COMPLETE - Genuine OEM picture

Server SE-SS 07020 Server Express Single Drop-In - NEW - COMPLETE - Genuine OEM

$180.00



Avtron SLS-10 Server Load Simulator Generator - 2 Channels - 10 kW - Tested ✔ï¸âš¡ picture

Avtron SLS-10 Server Load Simulator Generator - 2 Channels - 10 kW - Tested ✔ï¸âš¡

$859.00



Used & Tested FSP FSP300-701UJ Server Power Supply picture

Used & Tested FSP FSP300-701UJ Server Power Supply

$153.70







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.