TIBCO Spotfire® Server and Environment - Installation and Administration

Enabling constrained delegation on nodes

You must enable constrained delegation for your nodes. It allows the service on the node to delegate user credentials to the Spotfire Server and access external resources.

Before you begin

You have enabled constrained delegation on Spotfire Server. See Enabling constrained delegation.

Procedure

  1. On the domain controller, go to Administrative Tools.
  2. Select Active Directory Users and Computers.
  3. Locate the machine accounts or user accounts that runs the node manager services.
    Note: Steps 4 through 11 must be performed for each account that runs a node manager service.
  4. To open the account properties, right-click the account name and then click Properties.
  5. On the Delegation tab, select Trust this user for delegation to specified services only.
    Note: The Delegation tab is visible only for accounts to which SPNs are mapped. If the node manager services are run by user accounts, you must first register SPNs for these. See Setting up Kerberos authentication on nodes.
  6. Select Use any authentication protocol, and then click Add.
  7. Click Users or Computers and select any Spotfire Server service account.
  8. Select the http service for each Spotfire Server service account, and then click OK.
  9. Click Users or Computers and select any machine account or service account for a computer running the external resource you want to delegate to.
  10. Select the applicable services for each account, and then click OK.
    For example the MSSQLSvc service for delegation to a Microsoft SQL Server or the CIFS service for delegation to a file share.
  11. Click Apply.