Everything client-side is set up and working for Kerberos. There's server-side config required for IBM Navigator for i. It's in the linked documentation. I just overlooked it among the generic EIM/SSO config instructions.
Thanks
-----Original Message-----
From: Hiebert, Chris [mailto:chris.hiebert@xxxxxxxxxxxxxx]
Sent: Tuesday, October 17, 2017 9:26 AM
To: Midrange Systems Technical Discussion <midrange-l@xxxxxxxxxxxx>
Subject: RE: Single sign-on for IBM Navigator for i?
Are you using the web I nav?
Are you using Windows?
What browser are you using?
IE does the Kerberos tickets natively.
I'm not sure about chrome.
In Firefox you may need to modify some about:config settings like:
network.negotiate-auth.trusted-uris .example.com network.auth.use-sspi false network.negotiate-auth.delegation-uris .example.com network.automatic-ntlm-auth.allow-non-fqdn;true
network.automatic-ntlm-auth.trusted-uris;.example.com
If your web I nav isn't using ssl certs you may need to toggle this one:
network.negotiate-auth.allow-insecure-ntlm-v1
Are you using the java navigator iAccess Client?
Then you need to configure the connection to use Kerberos.
Chris Hiebert
Senior Programmer/Analyst
Disclaimer: Any views or opinions presented are solely those of the author and do not necessarily represent those of the company.
This mailing list archive is Copyright 1997-2026 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact
[javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.