Configuration Setup for Kerberos SPNEGO Authentication Policy
This section explains the configuration setup required to process SPNEGO Kerberos authentication requests for TIBCO API Exchange Gateway.
- Creating a User Account in the Microsoft Active Directory for TIBCO API Exchange Gateway
You must create a user account in the Microsoft Active Directory for the machine where TIBCO API Exchange Gateway is installed. - Mapping the Service Principal Name (SPN) to a Microsoft User Account
The Kerberos service principal name is defined as service name/Full_Qualified_Host_Name - Generating a Keytab File for an SPN
You can generate the Kerberos keytab file (krb5.keytab) for an SPN using the ktpass tool from the Windows Server toolkit.
Copyright © Cloud Software Group, Inc. All rights reserved.