If you are unable to create a new account, please email support@bspsoftware.com

 

[FM] C8.2 data level SECURITY with SSAS2005 Cubes [half solved]

Started by francois, 20 May 2008 08:49:10 AM

Previous topic - Next topic

francois

C8.2 data level SECURITY with SSAS2005 Cubes : pb

Hello,

Please have a look and tell me if you know anything that can help me solving this problem.


General info:

My company is running C8.2 on a Win2003 server Os, the data published with FM are sourced from a SqlServer2005 sp2 Datawarehouse with Win2003serverOs.

We produce both relational frameworks applying standard Cognos functions for the security (works well) and SSAS cubes for multidimensional content.

The user authentication is retrieved from integrating AD groups into C8 groups/roles and works well as a single sign on functionality.

Both the C8 server, Datawarehouse, AD and everything else in the company are under the same Domain.


In addition:

We’re able to access our published SSAS cubes if using Cognos service credentials and we’ve built reports with them already.

The SSAS roles/groups have been successfully tested:  While using Microsoft Reporting services directly, the data level security works fine with AD user id.


Problem description:

We’re unable to access our SSAS cubes if using Active Directory authentication.

We found no way to use the AD authentication out of Cognos portal while trying to implement a data level security by creating roles/groups under SSAS and retrieving AD user authentication out of Cognos while the user run a report based on a cube.


The Current faulty setting looks like :

under
Tools\Directory\Data Sources\ the targeted data source\Set properties\connection:

Type : Microsoft Analysis Services 2005
Use the default object gateway (grey)

Connection string detail:  

Server name: the server
Names instance: Blank
Language: don’t care but English
Sign on: An external namespace: Active Directory

Testing: succeeded while I’m providing my User ID and Password.

But we’re unable to produce usable packages on the portal.



Multiple contacts with both Ms and Cognos without any solution.

Would be great to find help here   :-\

kolonell

You have to options :

1) Create a signon for every user you have. :-(
2) Enable Kerberos SSO on the AD namespace so the SSO token can be forwarded to MS analysis services.

francois

Solved by....killing SSO  :-[

Using kerberos there was no way to get AD user authentication passed threw cognos to the ssas...  It was all of the time substituted by cognos service account which have no role on our MSssas cubes row level security.

So, final decision was to kill single sign on Cognos and...it works.
We're now able to use ssas RL security.