Configure network authentication service and EIM on the V5R2 or later system, iSeries D

iSeries™ D is running OS/400® V5R2 and this release does not support the Synchronize Functions wizard. Therefore, the configurations on iSeries A cannot be propagated to iSeries D. Instead, you need to use the EIM Configuration wizard and the Network Authentication Service wizard to manually configure this system, and you need to perform the additional steps required to allow iSeries D to participate in the single signon environment.

These are the tasks you need to perform, depending on how you configured single signon on iSeries A:

  1. Configure iSeries D to participate in the EIM domain and configure iSeries D for network authentication service using the EIM Configuration wizard and Network Authentication Service wizard.
  2. Add i5/OS™ service principals to the Kerberos server.
  3. Create a home directory for each of your users.
  4. Test network authentication service.
  5. Create EIM identifiers for your users.
  6. Create source associations and target associations for the EIM identifiers.
  7. (Optional) Create policy associations.
  8. (Optional) Enable the registries to participate in lookup operations and to use the policy associations.
  9. Test the EIM mappings.
  10. (Optional) Configure iSeries Access for Windows® applications to use Kerberos.
  11. Verify network authentication service and EIM configurations.

You can use the Enable single signon for i5/OS scenario as a guide as you configure iSeries D to match the single signon configuration on iSeries A. This scenario provides step-by-step instructions for completing all the tasks required for single signon. Within the Enable single signon for i5/OS scenario, you should follow the instructions for the system identified asiSeries B because that system joins an existing EIM domain just as iSeries D should join the existing EIM domain in this scenario.

You have completed the propagation of the network authentication service and EIM configurations to multiple systems. To configure the Management Central server to take advantage of a single signon environment, you need to perform some additional tasks. See Scenario: Configure the Management Central server for a single signon environment for details.