Cloud Pak for Business Automation

 View Only
  • 1.  SSO Options in ICP4BA

    Posted Fri August 02, 2024 01:43 AM

    Greetings

    Currently we are windows servers hosting BAW with external CPE and ICN. Kerberos is the primary authentication mechanism also providing SSO capabilities on top of Microsoft AD. Now are planning for ICP4BA 23.0.2 on-prem. Can someone suggest what are the options for achieving SSO in this scenario and how configuration should be handled with IM component of Foundation Services ?

    Thanks



    ------------------------------
    Lakshya Agarwal
    ------------------------------


  • 2.  RE: SSO Options in ICP4BA

    Posted Tue August 06, 2024 03:20 AM

    Hi Lakshya,

    I strongly recommend moving to CP4BA 24.0.0 instead of 23.0.2. 24.0.0 has a much longer support lifecycle, whereas 23.0.2 already no longer receives regular updates.

    Regarding SSO, the default assumption is that you 

    1. connect CP4BA to an LDAP server for access to user and group data
    2. for passwordless login, you delegate authentication to an identity provider using SAML or OpenID connect.

    Your identity provider may in turn support SPNEGO (Kerberos for browser users).



    ------------------------------
    Jens Engelke
    ------------------------------