<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication in multi-domain environment in QlikView</title>
    <link>https://community.qlik.com/t5/QlikView/Authentication-in-multi-domain-environment/m-p/743894#M1034534</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe a little complicated question, hope you understand the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client's QlikView server is in two domains. Server is pulling data from Domain#1 (because all of the db’s are in that domain), and all of the users have accounts in Domain#2 and login authentication should be provided using that domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if there is a way to set up Qlikview Server(IIS) to use Windows credentials from client's machine (not the server), where client and server are in different domains and&lt;STRONG&gt; there is &lt;SPAN style="color: #ff0000;"&gt;no&lt;/SPAN&gt; &lt;SPAN style="color: #ff0000;"&gt;trust&lt;/SPAN&gt; defined between those domains&lt;/STRONG&gt;? I want clients to be able to open QlikView documents(through a browser) without having to authenticate themself in the domain QlikView server belongs to. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Qlikview Security spec states:&lt;/P&gt;&lt;P&gt;"In a multi-domain environment: The internal company network IWA should be avoided in architectures where a multi-domain environment exists with no trust relationship between the domain of the workstation and the domain of the server, or when used across a reverse proxy. In such an environment the QlikView deployment should be configured to use either an existing external SSO service or a QlikView custom ticket exchange to expose an authenticated identity to QlikView."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I understand it right and it's not possible to have all users use QlikiView AccessPoint in multi-domain environment (with no trust)? How can this be solved? Different type of Authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any experience with such environments?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;LC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Nov 2020 18:02:30 GMT</pubDate>
    <dc:creator>lukacvetko</dc:creator>
    <dc:date>2020-11-20T18:02:30Z</dc:date>
    <item>
      <title>Authentication in multi-domain environment</title>
      <link>https://community.qlik.com/t5/QlikView/Authentication-in-multi-domain-environment/m-p/743894#M1034534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe a little complicated question, hope you understand the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client's QlikView server is in two domains. Server is pulling data from Domain#1 (because all of the db’s are in that domain), and all of the users have accounts in Domain#2 and login authentication should be provided using that domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if there is a way to set up Qlikview Server(IIS) to use Windows credentials from client's machine (not the server), where client and server are in different domains and&lt;STRONG&gt; there is &lt;SPAN style="color: #ff0000;"&gt;no&lt;/SPAN&gt; &lt;SPAN style="color: #ff0000;"&gt;trust&lt;/SPAN&gt; defined between those domains&lt;/STRONG&gt;? I want clients to be able to open QlikView documents(through a browser) without having to authenticate themself in the domain QlikView server belongs to. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Qlikview Security spec states:&lt;/P&gt;&lt;P&gt;"In a multi-domain environment: The internal company network IWA should be avoided in architectures where a multi-domain environment exists with no trust relationship between the domain of the workstation and the domain of the server, or when used across a reverse proxy. In such an environment the QlikView deployment should be configured to use either an existing external SSO service or a QlikView custom ticket exchange to expose an authenticated identity to QlikView."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I understand it right and it's not possible to have all users use QlikiView AccessPoint in multi-domain environment (with no trust)? How can this be solved? Different type of Authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any experience with such environments?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;LC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Nov 2020 18:02:30 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Authentication-in-multi-domain-environment/m-p/743894#M1034534</guid>
      <dc:creator>lukacvetko</dc:creator>
      <dc:date>2020-11-20T18:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication in multi-domain environment</title>
      <link>https://community.qlik.com/t5/QlikView/Authentication-in-multi-domain-environment/m-p/743895#M1034535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe this is helpful: &lt;A href="/t5/forums/searchpage/tab/message?q=multi domain"&gt;http://community.qlik.com/search.jspa?q=multi+domain&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Marcus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Jan 2015 20:00:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Authentication-in-multi-domain-environment/m-p/743895#M1034535</guid>
      <dc:creator>marcus_sommer</dc:creator>
      <dc:date>2015-01-21T20:00:20Z</dc:date>
    </item>
  </channel>
</rss>

