Tuesday, 12 August 2014

Setting up LDAP Authentication in BO


When we install SAP BusinessObjects BI Platform, LDAP Authentication plug-in software is installed automatically but is disabled by default. We can configure it in few simple steps, provided the underlying Directory System is already set-up. 

By configuring LDAP Authentication, users can benefit from the centralized access provided by Directory Systems & can login to SAP BI Platform using the same credentials they use for login to other systems of the organization. Please note that this article pertains to SAP BusinessObjects BI Platform 4.1

Below are the Steps for configuring LDAP Authentication in BO:


  • Login to CMC as an Administator. Navigate to Authentication Tab & double Click on  LDAP
Authentication in BO: CMC




















  • Click on Start LDAP Configuration Wizard
Authentication in BO: Start LDAP Configuration Wizard 


  • Enter the LDAP Host Server name along with Port number and Click on Add.                             (E.g. xyz_server_host_name:1234)  
Authentication in BO: Add LDAP Host



  • In the next steps for configuring this authentication in BO, select the LDAP Server Type from the list. Select Microsoft Active Directory Application Server if you are configuring AD to LDAP. I have selected Custom in this case as I am using underlying LDAP system and so as to customize & adapt LDAP's mapping for BO users. 
Authentication in BO: LDAP Server type
























      Click Next



  • Specify the Base LDAP Distinguished Name and click on Next
Authentication in BO: Base LDAP Distinguished Name











  • Specify the Distinguished Name credentials. The user account that we specify here need not have administrative privileges but should have read access to the directory.  
Authentication in BO: LDAP Server Administration Credentials



















  • Specify SSL Authentication Type – Click Next
Authentication in BO: Select type of Secure Sockets Layer (SSL) Auth










  •  Specify the type of SSO in BO & click Next.

    • Basic (no SSO)
    • SiteMinder


  • Specify how New Aliases, Alias Update & New User should occur in BI Platform and click on Finish
Authentication in BO: New LDAP Users & Aliases























  • LDAP Authentication is now Enabled

Authentication in BO: LDAP Server Configuration Summary
















  • Type the Active Directory Groups in Add LDAP Group (by cn or dn) and click on Add. Once you Click on Update, we can see the LDAP Group under SAP Business Objects Groups. (CMC - Users and Groups)
Authentication in BO: Mapped LDAP Member Groups











  • LDAP Alias Options

Authentication in BO: LDAP Alias Option









  • How to check if LDAP Authentication in BO is working? Open an infoview page (or any Client tool), specify the user credentials and authentication as LDAP. If the user is able to login using the directory system credentials, the LDAP authentication in BO has been successfully enabled in SAP BI Platform. Refer BO Admin Guide for More Details

No comments:

Post a Comment