1. The following information should be clarified before the spnego mechanism of Domino 8.5.1 is realized:
· A Microsoft Windows Active Directory domain server (BYSFT-DC). Bysft. Local), provides the Kerberos Key Allocation Center service and the LDAP service.
· Domino 8.5.1 Server (bysft-mail01. Bysft. Local) is running on a Windows machine, and this machine is joined to the domain of the Active Directory.
· Domino 8.5.1 Server Configuration (bysft-mail01. Bysft. Local) into a single sign-on authorization mechanism (MSSO) for a "multi-server session".
· You need a client (Windows XP or Windows7) that is in the Active Directory domain, running a Domino-enabled browser (ie6,7,8).
2. The working principle of realizing spnego mechanism
3, configuration implementation
3.1 Create a Web-logged ad user tester03 within a domain server and create a tester03 personal configuration document within the Domino server; Please refer to the screenshot
3.1.1 is created within a domain controller