<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Active Directory authentication WITHOUT SSO? in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529000#M1736042</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Randall,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not understand the requirement very clearly but this can be done using Portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our landscape, portal servers have 2 URLs each, one for Kerberos authentication and the other without Kerberos.&lt;/P&gt;&lt;P&gt;The second URL which is without Kerberos, lets users authenticate themselves by entering their AD login credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this suits your scenario too, then create a URL alias in the DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ritu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Oct 2008 06:51:42 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-10-08T06:51:42Z</dc:date>
    <item>
      <title>Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaq-p/4528999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Everything I have found relating to Active Directory is based around getting SSO to work.  Isn't there a halfway point that doesn't require touching every user and deploying complex config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In simple terms I am looking to do this.  I want to be able to set up a connection between the SAP application (not the GUI) and Active Directory, and have the user authentication be pulled from AD.  We have dozens of systems and clients, and it would be really nice if we could set it up so that user SALES1234 (who also has a OFFICE\SALES1234 NT account), uses the same password in all systems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something that can be set up using the LDAP connector on the systems to either pull the passwords down to SAP, or authenticate against AD on the fly?  It's not true SSO, but having a unified password strategy is a huge leap forward without having to invest in a huge project to touch users that are spread out globally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help?  Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, I don't know much about AD, except ours uses Kerberos for authentication.  Our systems are Solaris based.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 19:21:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaq-p/4528999</guid>
      <dc:creator>randall_king2</dc:creator>
      <dc:date>2008-10-07T19:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529000#M1736042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Randall,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not understand the requirement very clearly but this can be done using Portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our landscape, portal servers have 2 URLs each, one for Kerberos authentication and the other without Kerberos.&lt;/P&gt;&lt;P&gt;The second URL which is without Kerberos, lets users authenticate themselves by entering their AD login credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this suits your scenario too, then create a URL alias in the DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ritu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 06:51:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529000#M1736042</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-10-08T06:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529001#M1736043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take portal out of the equation.  I am talking about SAPGUI users and the ABAP side of the system.  Bascially I want to see if there is a way to either sync passwords with an AD back end, or use something in the LDAP connector to perform the password authentication.  Security roles would still reside inside of SAP, I am talking only about the password authentication.  I have systems that range from an old BW3.1 system to a new CRM 7.0 system.  All of them are on at least a 6.20 kernel, and they all have the LDAP connector.  It's just not being used.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 12:08:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529001#M1736043</guid>
      <dc:creator>randall_king2</dc:creator>
      <dc:date>2008-10-08T12:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529002#M1736044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you'll find any way to do what you're asking for without SSO. And it's not hard to set up (in Windows, not sure about any other OS).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Oct 2008 17:35:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529002#M1736044</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-10-09T17:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529003#M1736045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Randall,&lt;/P&gt;&lt;P&gt;I have a similar requirement i am trying to prototype. Please let me know if you have found a soultion to authenticate against AD without using SSO. Any guidance is appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pavan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 17:01:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529003#M1736045</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T17:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529004#M1736046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Why cant you syncronize users with the help of RSLDAPSYNC_USER report from your AD to SAP including passowrds but you need to do some mapping in ldapmap tcode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kiran.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 19:33:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529004#M1736046</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-15T19:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529005#M1736047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MS AD is, if you just look at the core, an LDAP Server. The UME supports LDAP. &lt;/P&gt;&lt;P&gt;SAP Help: &lt;A href="http://help.sap.com/saphelp_nw04/helpdata/EN/eb/00954081efb90ee10000000a155106/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04/helpdata/EN/eb/00954081efb90ee10000000a155106/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For getting access to the groups and user information in the MS AD LDAP, you'll need to know the exact location inside the LDAP. It is something like cn=users,ou=company,ou=com. You'll have to get this information from your AD administrator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;br,&lt;/P&gt;&lt;P&gt;Tobias&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jan 2009 14:09:06 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529005#M1736047</guid>
      <dc:creator>hofmann</dc:creator>
      <dc:date>2009-01-16T14:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory authentication WITHOUT SSO?</title>
      <link>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529006#M1736048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Was there a resolution to the question?  is it possible to integrate AD into SAP without using SSO?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 May 2009 18:47:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/active-directory-authentication-without-sso/qaa-p/4529006#M1736048</guid>
      <dc:creator>dan_pfingsten2</dc:creator>
      <dc:date>2009-05-14T18:47:38Z</dc:date>
    </item>
  </channel>
</rss>

