TD 92579EN
15 February 2012 / Ver. H
Installation and Operation Manual
IP-DECT Base Station & IP-DECT Gateway (software version 5.0.x)
66
3
Click "OK".
Kerberos Client configuration
The location of the Windows server must be configured locally on each client similarly to
the Kerberos server. The client configuration must be done on the Kerberos server as well
so that it can also join the Windows domain. To configure the clients, do the following:
1
Select General > Admin.
2
Go to the
Authentication Servers
section
3
In the
Realm/Domain
text field, enter the name of the trusted Windows domain.
4
In the
Address
text field, enter the IP address of the Windows server. The
Port
text
field is filled out automatically.
5
Click "OK".
Log in using Kerberos cross-realm authentication
1
Make sure that secure HTTPS protocol is used when logging in.
Authorization
Set user access rights from the
Windows domain
• Use domain group: Specify a
Windows group with Administrator
or Auditor rights
• Administrator: All Windows
domain users have administrator
access rights
• Auditor: All Windows domain
users have auditor access rights
Admin Group
RID
Specify the Relative Identifier (RID)
of a Windows group with
administrator rights. The RID is the
last part of the Security Identifier
(SID) of a group.
Determine the SID of a group by
entering the following in the
Windows command line:
whoami /groups
This command displays the group
information of the user logged in to
the Windows domain.
Auditor Group
RID
Specify the Relative Identifier (RID)
of a Windows group with auditor
rights. The RID is the last part of the
Security Identifier (SID) of a group.
Determine the SID of a group by
entering the following in the
Windows command line:
whoami /groups
This command displays the group
information of the user logged in to
the Windows domain.