<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html lang="en-us" xml:lang="en-us"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta name="security" content="public" /> <meta name="Robots" content="index,follow" /> <meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' /> <meta name="DC.Type" content="task" /> <meta name="DC.Title" content="Set central system to use Kerberos authentication" /> <meta name="DC.Relation" scheme="URI" content="rzakhscenmc2.htm" /> <meta name="DC.Relation" scheme="URI" content="rzakhkerberosscenario_completeplanningworksheets.htm" /> <meta name="DC.Relation" scheme="URI" content="rzakhkerberosscenario_createmyco2systemgroup.htm" /> <meta name="copyright" content="(C) Copyright IBM Corporation 1998, 2006" /> <meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 1998, 2006" /> <meta name="DC.Format" content="XHTML" /> <meta name="DC.Identifier" content="rzakhkerberosscenario_setcentralsystem" /> <meta name="DC.Language" content="en-us" /> <!-- All rights reserved. Licensed Materials Property of IBM --> <!-- US Government Users Restricted Rights --> <!-- Use, duplication or disclosure restricted by --> <!-- GSA ADP Schedule Contract with IBM Corp. --> <link rel="stylesheet" type="text/css" href="./ibmdita.css" /> <link rel="stylesheet" type="text/css" href="./ic.css" /> <title>Set central system to use Kerberos authentication</title> </head> <body id="rzakhkerberosscenario_setcentralsystem"><a name="rzakhkerberosscenario_setcentralsystem"><!-- --></a> <!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script> <h1 class="topictitle1">Set central system to use Kerberos authentication</h1> <div><div class="section">iSeries™ A is the model system and central system for the other target systems. To set Kerberos authentication on the central system, complete these tasks.</div> <ol><li class="stepexpand"><span>In iSeries Navigator, right-click <span class="uicontrol">Management Central (iSeriesA)</span> and select <span class="uicontrol">Properties</span>.</span></li> <li class="stepexpand"><span>On the <span class="uicontrol">Security</span> tab, select <span class="uicontrol">Use Kerberos authentication</span> and set the authentication level to <span class="uicontrol">Add to trusted group</span>.</span></li> <li class="stepexpand"><span>Select <span class="uicontrol">Do not use</span> in the <span class="uicontrol">Identity Mapping</span> field and click <span class="uicontrol">OK</span>. </span> This setting allows you to enable or disable the use of Enterprise Identity Mapping (EIM) by Management Central servers to enable a single signon environment for your endpoint systems. If you want to enable single signon for your endpoint systems, see <a href="../rzamz/rzamzconfigssomgtcentral.htm">Scenario: Configure the Management Central server for a single signon environment</a> for a scenario that shows this configuration. <div class="note"><span class="notetitle">Note:</span> The note at the bottom of the <span class="uicontrol">Security</span> page indicates that the settings will take effect the next time the Management Servers are started. Do not restart the servers now. This scenario indicates the appropriate time to restart the servers in a subsequent step.</div> </li> <li class="stepexpand"><span>A dialog box is displayed that indicates that the changes to these settings affect only this central system and that Kerberos must be properly configured before these settings can be used by the Management Central server jobs. Click <span class="uicontrol">OK</span>. You have enabled Kerberos authentication to be used by the central system.</span></li> </ol> </div> <div> <div class="familylinks"> <div class="parentlink"><strong>Parent topic:</strong> <a href="rzakhscenmc2.htm" title="Use the following scenario to become familiar with the prerequisites and objectives for using Kerberos authentication between Management Central servers.">Scenario: Use Kerberos authentication between Management Central servers</a></div> <div class="previouslink"><strong>Previous topic:</strong> <a href="rzakhkerberosscenario_completeplanningworksheets.htm">Complete the planning work sheets</a></div> <div class="nextlink"><strong>Next topic:</strong> <a href="rzakhkerberosscenario_createmyco2systemgroup.htm">Create MyCo2 system group</a></div> </div> </div> </body> </html>