16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 5: SharePoint Portal Server Architecture 121<br />

Enabling <strong>and</strong> Configuring Single Sign-On Service<br />

Like all services in SharePoint Portal Server, Single Sign-On installs automatically, but<br />

it is not enabled. Enabling the service requires an administrator to be physically at the<br />

server that is designated as the job server for the portal site. The administrator must<br />

specify a SQL Server in the server farm on which a credential database is created.<br />

A developer can develop Web Parts that are Single Sign-On–aware <strong>and</strong> use<br />

enterprise application definitions to pull information from enterprise applications<br />

<strong>and</strong> display it on pages within a portal site. The purpose of an enterprise-application<br />

definition is to provide the connection from the enterprise application to the<br />

Single Sign-On Web Part on a portal site page. Figure 5-2 shows the relationship<br />

between Single Sign-On Web Parts, enterprise-application definitions, the enterprise<br />

application, <strong>and</strong> the credentials database.<br />

Single Sign-On Service<br />

Enterprise<br />

Application<br />

Definition<br />

Credential<br />

database<br />

F05XR02<br />

Figure 5-2 SharePoint Portal Server connects users to enterprise applications using the Single<br />

Sign-On service <strong>and</strong> enterprise application definitions<br />

Authentication with Single Sign-On<br />

Enterprise<br />

Application<br />

Authentication with the Single Sign-On service can be set up to work with groups or<br />

with individual users. In either case, enterprise application definitions are used to<br />

map credentials used by SharePoint Portal Server to credentials used in an enterprise<br />

application.<br />

With group authentication, the individual user is associated with a managed<br />

group account. In this case, the user does not need to know an individual set of credentials.<br />

Instead, an enterprise application definition is configured by an administrator<br />

to provide the credentials needed. The enterprise-application definition maps the<br />

credentials used in SharePoint Portal Server to the enterprise application without<br />

users needing to provide alternate credentials.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!