16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 26: Single Sign-On in SharePoint Portal Server 2003 707<br />

Step 6: Enable the Single Sign-On Service on the Front-End<br />

Web Servers<br />

After you have configured the single sign-on settings on the job server, you need to<br />

enable the single sign-on service of the front-end Web servers. To enable the single<br />

sign-on service on each front-end Web server, follow the instructions given earlier in<br />

step 2, “Enable the Single Sign-On Service on the Job Server.”<br />

Managing Single Sign-On<br />

After you have configured the single sign-on for the first time, you are likely to need<br />

to perform administration tasks at a later stage, including the following:<br />

■ Creating <strong>and</strong> deleting the application definitions<br />

■ Managing account credentials mapped within the application definitions<br />

■ Regenerating, backing up, <strong>and</strong> restoring the encryption key<br />

■ Enabling auditing of the encryption key<br />

■ Disabling the SSOSrv service<br />

In this section, we will discuss the single sign-on administration tasks. If you<br />

need to change your single sign-on configuration, make sure you consider the<br />

following:<br />

■ The single sign-on configuration <strong>and</strong> encryption key management tasks cannot<br />

be done remotely. To configure single sign-on or manage the encryption key,<br />

go to the computer running as the job server <strong>and</strong> specify the settings locally.<br />

■ If you change the job server to another server, you must reconfigure single<br />

sign-on. After changing the job server, you must delete the entire registry key<br />

HKEY_LOCAL_MACHINE\SOFTWARE\<strong>Microsoft</strong>\ssosrv\Config on the old job<br />

server.<br />

■ If you reconfigure single sign-on <strong>and</strong> you want to change the account that you<br />

specified for managing the single sign-on service (the single sign-on administrator<br />

account), the user who reconfigures the single sign-on <strong>and</strong> the single<br />

sign-on service account must be a member of both the current single sign-on<br />

administrator account that manages the service <strong>and</strong> the new account that you<br />

want to specify.<br />

Editing an Application Definition<br />

You can edit the display name, the e-mail contact, <strong>and</strong> the logon fields for an enterprise<br />

application definition. You cannot edit the application definition name or<br />

change the account type.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!