Integrated Login

Post Reply
PlanningDev
Community Contributor
Posts: 349
Joined: Tue Aug 17, 2010 6:31 am
OLAP Product: Planning Analytics
Version: 2.0.5
Excel Version: 2016

Integrated Login

Post by PlanningDev »

I have been trying to get integrated login just for Architect and have had no luck.

Can someone help validate some points for me?

I have Security set as Kerberos and Login Mode as 2. The only other change I have made is to add the login id user@domain to the unique filed in the client properties cube. The TM1 admin service and server are both running on a windows domain service account (the same one).

Outside of this are there any other items I need to know? Do any other settings need to be messed with on the Active Directory side?
rmackenzie
MVP
Posts: 733
Joined: Wed May 14, 2008 11:06 pm

Re: Integrated Login

Post by rmackenzie »

Did you select the checkbox in the options screen that says something like 'Use integrated login'?

In mode 2, each user has the option of using integrated login, or not.
Robin Mackenzie
tomok
MVP
Posts: 2832
Joined: Tue Feb 16, 2010 2:39 pm
OLAP Product: TM1, Palo
Version: Beginning of time thru 10.2
Excel Version: 2003-2007-2010-2013
Location: Atlanta, GA
Contact:

Re: Integrated Login

Post by tomok »

Check that the Domain (in the @Domain) is the proper case. I have had situations where it's been case sensitive.
Tom O'Kelley - Manager Finance Systems
American Tower
http://www.onlinecourtreservations.com/
PlanningDev
Community Contributor
Posts: 349
Joined: Tue Aug 17, 2010 6:31 am
OLAP Product: Planning Analytics
Version: 2.0.5
Excel Version: 2016

Re: Integrated Login

Post by PlanningDev »

I have checked the box for integrated login and I also checked the case for the @domain portion.

Im still receving the standard "Server Principal Name (SPN) or the security context of the destination server could not be established.
rmackenzie
MVP
Posts: 733
Joined: Wed May 14, 2008 11:06 pm

Re: Integrated Login

Post by rmackenzie »

PlanningDev wrote:Im still receving the standard "Server Principal Name (SPN) or the security context of the destination server could not be established.
Try using NTLM instead of Kerberos...
Robin Mackenzie
Gregor Koch
MVP
Posts: 263
Joined: Fri Jun 27, 2008 12:15 am
OLAP Product: Cognos TM1, CX
Version: 9.0 and up
Excel Version: 2007 and up

Re: Integrated Login

Post by Gregor Koch »

Hi
Didn't have to use Kerberos in a while but from memory I think it can happen that the way you have to set the domain in the UniqueID can differ between the two security packages.

For example using NTLM it would simply be johnsmith@company
but with Kerberos it would be johnsmith@us.ad.company (or in which ever way the domain was set up)

You might find that changing to NTLM will solve your problem easily but in case you are using TM1Web with the web server being a another machine than the TM1 Server you would have to use Kerberos.
User avatar
Michel Zijlema
Site Admin
Posts: 712
Joined: Wed May 14, 2008 5:22 am
OLAP Product: TM1, PALO
Version: both 2.5 and higher
Excel Version: 2003-2007-2010
Location: Netherlands
Contact:

Re: Integrated Login

Post by Michel Zijlema »

If I recall correctly the TM1 Service needs to run on a domain account to be able to use Kerberos. Is your server running on a domain account or on a local account?

Michel
Post Reply