Forum Discussion
BOXI using kerberos gettig moved behind BigIP
I've been tasked with moving a running Business Objects XI server behind BigIP. The existing setup was using Kerberos login and the server hostname as the URL.
When moving to BigIP, they still want Kerberos to work, and added a second node, so the URL of the BOXI changed to the VIP name (boxi.domain.com). I've got the basic setup all dne, but am unsure how to attack the Kerberos.
Do I need to set up an APM policy and perform the Kerberos and pass it to the backend servers?
1 Reply
- TLL_91858
Cirrus
Answering my own question.
Yes, set up an APM policy and perform Kerberos just like any other SSO KPT request. The trick with Business Objects is the set up on the BO server. Follow all the best practices from SAP on setting up for Kerberos on BO XI, but then add a obscure setting in the web.xml as below: idm.allowS4U true
Turns out BO sets allowS4U to disable by default. More helpful info at: http://wiki.scn.sap.com/wiki/display/Community/Configuring+SSO+for+Business+Objects+Infoview+with+BEA+Weblogic
Tom
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com