TD 92579EN
15 February 2012 / Ver. H
Installation and Operation Manual
IP-DECT Base Station & IP-DECT Gateway (software version 5.0.x)
65
1
In the
Delegated Authentication
section select the
Disable local authentication
check box.
2
Click "OK".
Configure cross-realm authentication
Cross-realm authentication is used to authenticate users from another trusted realm. In
this way it is possible for IP-DECT users to login to the IPBS/IPBL using their Windows user
name and password in the Active Directory (AD). The trust relationship between the two
realms is confirmed by configuring a shared password on both servers in the realms. This
password is used to encrypt communication between the realms. To configure cross-realm
authentication, do the following:
AD Server configuration for Windows 2003 servers
The trust relationship must be configured in the AD server.
1
In the Windows Start menu select Administrative Tools > Active Directory Domains
and Trusts
2
Right-click the domain name and select "Properties".
3
Select the
Trusts
tab and click "New Trust...".
4
The
New Trust Wizard
appears. Click "Next".
5
Enter the name of the Kerberos realm. Click "Next".
6
Select "Realm trust". Click "Next".
7
Select "Nontransitive". Click "Next".
8
Select "One-way incoming". Click "Next".
9
Enter a password that will be a shared secret between the AD server and the
Kerberos server. Click "Next".
10
Check the configuration and click "Next". Click "Finish".
Kerberos Server configuration
The trust relationship must also be configured in the Kerberos server.
1
Select General > Kerberos.
2
Select/Enter the following information in the
Trusted realms
section.
Field Name
Description
Name
Enter the name of the trusted
Windows domain.
Must be capital
letters.
Password
Enter the shared password specified
in the AD server
Retype
Password
Confirm password