If you are unable to create a new account, please email support@bspsoftware.com

 

News:

MetaManager - Administrative Tools for IBM Cognos
Pricing starting at $2,100
Download Now    Learn More

Main Menu

Active Directory Authentication-Authorization Debate

Started by davidsoc, 18 Apr 2006 03:33:32 AM

Previous topic - Next topic

davidsoc

Hello all,

I would like to know what other people/companies have done in regard to setting up C8 (or CRN) to use Microsoft Active Directory as a single authentication source (i.e. no LDAP, S7 LDAP etc). Is it easy to achieve a single sign-on with W2003?

I'd also like to know what you all consider as best practice in terms of 'authorization' within Cognos Connection... do you use the built-in Cognos Namespace for creating the security user classes and the relavent hierarchies for securing packages, reports etc.

Also with the integration of PowerPlay into the C8 wrapper... what is the impact of using AD with Transformer 7.3? Does Transformer require a series 7 namespace? or can it use the Cognos Namespace or hook-up to AD directly?

Thanks in advance for any of your comments

Chris

davidsoc

Anybody?

I managed to get single signon working (described in a separate thread)... anyone using AD as authentication source?  :-\

Where is your day-to-day maintainance/user class management done? In AD or in the Cognos namespace?

Thanks

Chris

ibrusett

I use wingle signon, with a multi domain tree.
I find useful to create groups in AD (security universal group) and give authorization inside C8 to this groups.
The odd part is that I cannot find a way to retrieve effective permission on report or package: is there a pre build report to extract, for each report in a package, the effective AD group with a certain authorization on it??

Any suggestion about this and on improvement can be good!

angela

We use A.D. not only for single-signon authentication but also for object level (folders/reports) and data level security (using a macro in the Query Subject filter).  We don't use the Cognos namespace groups at all because they change each version (you'd be surprised that suddenly the 'everyone' group can get to things we aren't happy about).

I don't know about integration with Transformer 7.3 but I know it integrates with 8.3 - we're using our A.D. groups for data level security in Custom Views.