Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

External Authentication, Local Authorisation

Status
Not open for further replies.

spicysudhi

Programmer
Nov 10, 2003
575
FR
Hi,

I want to implement our corporate network login (which is LDAP) into Cognos for Authentication. However the authorisation should be local. Since there are more than 10 thousand plus employees, I dont want to take risk of setting up everyone in Access Manager. Say nearly 200+ users should be setup in the system and needs to assigned to proper user classes.

I may be confusing... coz i am not clear how it all works. In simple, i want to use corporate LDAP for authentication and the access rights will be given based on the settings (user classes )in AM.

How to do this? Do I have to set the access manager run-time to my corporate LDAP? If Yes, after doing this, does Access Manager will show all users in that LDAP or do I have to add one by one?

someone please guide on this. thanks in advance.
 
Hi,

It depends which Cognos product(s) you are using. If you are using ReportNet or Cognos 8, then you can simply point off at your LDAP as an external security provider (giving you your authentication), and then set up priviliges/restrictions based on your LDAP users and/or groups within the Cognos environment (giving you your local authorization)

If you are using Cognos 7 (PowerPlay, Impromptu, IWR etc), then you are tied in to Cognos Access Manager for your authentication. However, if your LDAP provider is LDAP 3.0 compliant, you can link Access Manager users to your real LDAP users (see the below thread)

Regards,

MF.
 
thanks.

currently we are using reportnet 1.1 and series 7.4.

our LDAP is 3.0 compliant (i guess).

what i understand is, i can connect to corporate ldap and import the users to AM, then assign them to user classes...



 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top