Table of Contents

Search

  1. About the Security Guide
  2. Introduction to Informatica Security
  3. User Authentication
  4. LDAP Authentication
  5. Kerberos Authentication
  6. SAML Authentication for Informatica Web Applications
  7. Domain Security
  8. Security Management in Informatica Administrator
  9. Users and Groups
  10. Privileges and Roles
  11. Permissions
  12. Audit Reports
  13. Appendix A: Command Line Privileges and Permissions
  14. Appendix B: Custom Roles

Security Guide

Security Guide

Enable Full Delegation for the Kerberos Principal User Accounts in Active Directory

Enable Full Delegation for the Kerberos Principal User Accounts in Active Directory

Create the keytab files using the
ktpass
command.
To use full delegation, you must enable delegation for all of the accounts you created, except for the LDAP bind user account that you use to access and search Active Directory during LDAP synchronization.
To enable full delegation, perform the following steps for each user account:
  1. Right-click the user account and select
    Properties
    .
    The
    Properties
    dialog box appears.
  2. On the
    Delegation
    tab, select
    Trust this user for delegation to any service (Kerberos only)
    .
  3. Click
    Apply
    .
    Full delegation is enabled.

0 COMMENTS

We’d like to hear from you!