<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forms authentication through Active Directory and getTicket in QlikView</title>
    <link>https://community.qlik.com/t5/QlikView/Forms-authentication-through-Active-Directory-and-getTicket/m-p/391640#M146085</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are many information about that in the forum but I didn't find a clear answer, so sorry for be redundant..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Our scenario:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We have a Qlikview Server configured in NTFS Mode so the autoritzation is through IWA (Integrated Windows Authentication), but we want to change that internet explorer popup to &lt;SPAN style="text-decoration: underline;"&gt;our login (asp.net) system&lt;/SPAN&gt;&amp;nbsp; using forms authentication linked to&lt;SPAN style="text-decoration: underline;"&gt; Active directory&lt;/SPAN&gt; achieaving a single-sign-on system through our login, thus when a already logged user (in our login solution) click a qvw link, automatically will be logged in qlikview system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found many examples to that getTicket system, but as I understood its (almost) compulsory to change authentication to DMS-Mode, is that true?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question 1:&amp;nbsp; There is a way to use getTicket with NTFS Mode? If its not, there is another method instead of getTicket to achieve the same behaviour? (without using html header for the insecurity/spoofing issue)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I read in the qlikview server manual, NTFS Mode is suitable for all that Active Directory authoritzation method:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"NTFS&amp;nbsp; is&amp;nbsp; the&amp;nbsp; default&amp;nbsp; document&amp;nbsp; authorization&amp;nbsp; model,&amp;nbsp; suitable&amp;nbsp; when&amp;nbsp; all&amp;nbsp; users&amp;nbsp; and&amp;nbsp; groups&amp;nbsp; are&amp;nbsp; identified&amp;nbsp; in &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Active&amp;nbsp; Directory&amp;nbsp; or&amp;nbsp; locally&amp;nbsp; on&amp;nbsp; the&amp;nbsp; QlikView&amp;nbsp; Server&amp;nbsp; host"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this definition fits in our users-structure system, so if we can 'overwrite' the login page of Qlikview through our own logging system in NTFS-Mode and its compulsory to switch to DMS-Mode, I wonder if:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question2: Can we use a active directory tree (LDAP PATH) as a source of users in DMS-mode? We have to import all users each time we add a new user in A.D or it reads the ldap path each time dinamically?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That second questions is a result of reading:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"DMS&amp;nbsp; integrates&amp;nbsp; fully&amp;nbsp; with&amp;nbsp; the existing&amp;nbsp; Directory&amp;nbsp; Service&amp;nbsp; Provider&amp;nbsp; (for&amp;nbsp; example,&amp;nbsp; Active&amp;nbsp; Directory,&amp;nbsp; other&amp;nbsp; LDAP)&amp;nbsp; where&amp;nbsp; Group&amp;nbsp; Membership&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;has&amp;nbsp; been&amp;nbsp; recorded&amp;nbsp; –&amp;nbsp; this&amp;nbsp; is&amp;nbsp; a&amp;nbsp; mechanism&amp;nbsp; by&amp;nbsp; which&amp;nbsp; QlikView&amp;nbsp; Server&amp;nbsp; can&amp;nbsp; re- use&amp;nbsp; existing&amp;nbsp; enterprise&amp;nbsp; accounts&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;and&amp;nbsp; group&amp;nbsp; structures.&amp;nbsp; &lt;SPAN style="text-decoration: underline;"&gt;The&amp;nbsp; permitted&amp;nbsp; users&amp;nbsp; or&amp;nbsp; groups &lt;STRONG&gt; are&amp;nbsp; recorded &lt;/STRONG&gt; in&amp;nbsp; a&amp;nbsp; meta&amp;nbsp; file&amp;nbsp; that&amp;nbsp; resides&lt;/SPAN&gt;&amp;nbsp; next&amp;nbsp; to&amp;nbsp; the&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;QlikView&amp;nbsp; document,&amp;nbsp; and&amp;nbsp; it&amp;nbsp; is&amp;nbsp; managed&amp;nbsp; using&amp;nbsp; QMC"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'm not sure at all if its dinamically or not...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question3: Maybe we should go for dual (ntfs-mode + dms mode) authoritzation, is that even possible/right having in mind the scenario I told you before?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Oct 2012 16:32:07 GMT</pubDate>
    <dc:creator>anguila</dc:creator>
    <dc:date>2012-10-08T16:32:07Z</dc:date>
    <item>
      <title>Forms authentication through Active Directory and getTicket</title>
      <link>https://community.qlik.com/t5/QlikView/Forms-authentication-through-Active-Directory-and-getTicket/m-p/391640#M146085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are many information about that in the forum but I didn't find a clear answer, so sorry for be redundant..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Our scenario:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We have a Qlikview Server configured in NTFS Mode so the autoritzation is through IWA (Integrated Windows Authentication), but we want to change that internet explorer popup to &lt;SPAN style="text-decoration: underline;"&gt;our login (asp.net) system&lt;/SPAN&gt;&amp;nbsp; using forms authentication linked to&lt;SPAN style="text-decoration: underline;"&gt; Active directory&lt;/SPAN&gt; achieaving a single-sign-on system through our login, thus when a already logged user (in our login solution) click a qvw link, automatically will be logged in qlikview system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found many examples to that getTicket system, but as I understood its (almost) compulsory to change authentication to DMS-Mode, is that true?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question 1:&amp;nbsp; There is a way to use getTicket with NTFS Mode? If its not, there is another method instead of getTicket to achieve the same behaviour? (without using html header for the insecurity/spoofing issue)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I read in the qlikview server manual, NTFS Mode is suitable for all that Active Directory authoritzation method:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"NTFS&amp;nbsp; is&amp;nbsp; the&amp;nbsp; default&amp;nbsp; document&amp;nbsp; authorization&amp;nbsp; model,&amp;nbsp; suitable&amp;nbsp; when&amp;nbsp; all&amp;nbsp; users&amp;nbsp; and&amp;nbsp; groups&amp;nbsp; are&amp;nbsp; identified&amp;nbsp; in &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Active&amp;nbsp; Directory&amp;nbsp; or&amp;nbsp; locally&amp;nbsp; on&amp;nbsp; the&amp;nbsp; QlikView&amp;nbsp; Server&amp;nbsp; host"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this definition fits in our users-structure system, so if we can 'overwrite' the login page of Qlikview through our own logging system in NTFS-Mode and its compulsory to switch to DMS-Mode, I wonder if:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question2: Can we use a active directory tree (LDAP PATH) as a source of users in DMS-mode? We have to import all users each time we add a new user in A.D or it reads the ldap path each time dinamically?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That second questions is a result of reading:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"DMS&amp;nbsp; integrates&amp;nbsp; fully&amp;nbsp; with&amp;nbsp; the existing&amp;nbsp; Directory&amp;nbsp; Service&amp;nbsp; Provider&amp;nbsp; (for&amp;nbsp; example,&amp;nbsp; Active&amp;nbsp; Directory,&amp;nbsp; other&amp;nbsp; LDAP)&amp;nbsp; where&amp;nbsp; Group&amp;nbsp; Membership&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;has&amp;nbsp; been&amp;nbsp; recorded&amp;nbsp; –&amp;nbsp; this&amp;nbsp; is&amp;nbsp; a&amp;nbsp; mechanism&amp;nbsp; by&amp;nbsp; which&amp;nbsp; QlikView&amp;nbsp; Server&amp;nbsp; can&amp;nbsp; re- use&amp;nbsp; existing&amp;nbsp; enterprise&amp;nbsp; accounts&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;and&amp;nbsp; group&amp;nbsp; structures.&amp;nbsp; &lt;SPAN style="text-decoration: underline;"&gt;The&amp;nbsp; permitted&amp;nbsp; users&amp;nbsp; or&amp;nbsp; groups &lt;STRONG&gt; are&amp;nbsp; recorded &lt;/STRONG&gt; in&amp;nbsp; a&amp;nbsp; meta&amp;nbsp; file&amp;nbsp; that&amp;nbsp; resides&lt;/SPAN&gt;&amp;nbsp; next&amp;nbsp; to&amp;nbsp; the&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;QlikView&amp;nbsp; document,&amp;nbsp; and&amp;nbsp; it&amp;nbsp; is&amp;nbsp; managed&amp;nbsp; using&amp;nbsp; QMC"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'm not sure at all if its dinamically or not...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question3: Maybe we should go for dual (ntfs-mode + dms mode) authoritzation, is that even possible/right having in mind the scenario I told you before?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 16:32:07 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Forms-authentication-through-Active-Directory-and-getTicket/m-p/391640#M146085</guid>
      <dc:creator>anguila</dc:creator>
      <dc:date>2012-10-08T16:32:07Z</dc:date>
    </item>
  </channel>
</rss>

