Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 
jcramirez472
Partner - Contributor III
Partner - Contributor III

Adding users to AWS Sense Server

So I finally got my qlik sense server running through AWS. I followed the documentation that I could find, and used the QDC. I can now access my server with https://ipaddress/hub/. Now I want to allow others users to access it through their own account that I create for them. Problem is I cannot create new users. I believe this has something to do with LDAP in User directory (QMC), but I am not sure. I have asked people to try to log-in hoping they would show up in my log where I can edit their credentials, but that have not. Does anyone have a good answer to adding users step by step? Where do I get the LDAP path/user/pass/etc...?


Best,


John

1 Solution

Accepted Solutions
Not applicable

Hi John,

Your question reads like you want Qlik Sense to behave like an identity management solution to provide user authentication.  Qlik Sense does not perform identity management to authenticate users.  The product relies upon identity management solutions like Active Directory (or many others) to perform the primary layer of authentication for users.  Once a user is authenticated their user id is sent to Qlik Sense and stored in the Repository database for access control and authorization purposes.

If you are looking for a way to provide identity management for this AWS server you have deployed Qlik Sense, you can use the local Windows users and groups snap-in to create your users and passwords there.  When a user attempts to connect to the hub, they will be prompted by the browser for userid and password.  After they are authenticated to Windows, a ticket will be created for the users to enter into Qlik Sense and they will be redirected to the hub.

If you do not want to use the local Windows users and groups snap-in, you will need to implement an identity management solution to facilitate authentication and then use one of the various Qlik Sense authentication methods (ticket, header, or session api) to complete the authentication and authorization.

Here is some documentation that may provide some additional insight.

Qlik Help: Authentication - http://help.qlik.com/sense/en-US/online/#../Subsystems/ServerDeploymentConfiguration/Content/Server/...

Qlik Help: User Directory Connectors - http://help.qlik.com/sense/en-US/online/#../Subsystems/ManagementConsole/Content/QMC_Resources_UserD...

Branch: Access Control Test Module for demonstrating Qlik tickets - Access Control Test Module‌ and documentation here Install Configure Access Control Test Module for Qlik Sense 1.x

Lastly, once you have users ready to access Qlik Sense you will need to establish a user access rule or login access rule to provision tokens to users.  I recommend watching this video here: Qlik Sense Platform - Token Licensing and Assigning Access Passes (video)‌ or here: Qlik Sense Platform - Qlik Management Console Token Licensing / Login Access Pass – Part 3

Lastly, here is a video on user directory connectors: Qlik Sense Platform - Qlik Management Console User Directory Connector - Part 5

I hope this helps.

jg

View solution in original post

4 Replies
Not applicable

Hi John,

Your question reads like you want Qlik Sense to behave like an identity management solution to provide user authentication.  Qlik Sense does not perform identity management to authenticate users.  The product relies upon identity management solutions like Active Directory (or many others) to perform the primary layer of authentication for users.  Once a user is authenticated their user id is sent to Qlik Sense and stored in the Repository database for access control and authorization purposes.

If you are looking for a way to provide identity management for this AWS server you have deployed Qlik Sense, you can use the local Windows users and groups snap-in to create your users and passwords there.  When a user attempts to connect to the hub, they will be prompted by the browser for userid and password.  After they are authenticated to Windows, a ticket will be created for the users to enter into Qlik Sense and they will be redirected to the hub.

If you do not want to use the local Windows users and groups snap-in, you will need to implement an identity management solution to facilitate authentication and then use one of the various Qlik Sense authentication methods (ticket, header, or session api) to complete the authentication and authorization.

Here is some documentation that may provide some additional insight.

Qlik Help: Authentication - http://help.qlik.com/sense/en-US/online/#../Subsystems/ServerDeploymentConfiguration/Content/Server/...

Qlik Help: User Directory Connectors - http://help.qlik.com/sense/en-US/online/#../Subsystems/ManagementConsole/Content/QMC_Resources_UserD...

Branch: Access Control Test Module for demonstrating Qlik tickets - Access Control Test Module‌ and documentation here Install Configure Access Control Test Module for Qlik Sense 1.x

Lastly, once you have users ready to access Qlik Sense you will need to establish a user access rule or login access rule to provision tokens to users.  I recommend watching this video here: Qlik Sense Platform - Token Licensing and Assigning Access Passes (video)‌ or here: Qlik Sense Platform - Qlik Management Console Token Licensing / Login Access Pass – Part 3

Lastly, here is a video on user directory connectors: Qlik Sense Platform - Qlik Management Console User Directory Connector - Part 5

I hope this helps.

jg

jcramirez472
Partner - Contributor III
Partner - Contributor III
Author

I wanted to add to Jeffrey here. In order to add users to my AWS account, all I had to do was add users through the EC2 Dashboard Homepage. For whatever reason I was trying to do this through my local machine rather than my cloud server. Thanks Jeffrey for the help.

Anyone know how to get a SSL thumbprint into the QMC? Do I get the SSL certificate from AWS?

Best,


John

Not applicable

John, if you are ok using the certificates created by the Qlik Sense server during install what you can do is go to the QMC and create a new server certificate with the hostname for your Amazon server.

After exporting certificates, you can import the new server certificate into the Local Machine Personal certificate store.

Once the named cert is imported, you can access the properties and copy the thumbprint.  To enter the thumbprint into Qlik Sense, go to the QMC|Proxies|Central and click on the Security item on the right side of the screen. The text box for thumbprint entry will appear and you can enter the thumbprint in this location.

jg

Not applicable

Hi John,

Can you please provide us the configuration / installation steps to run Qlik Sense server on AWS.

I installed QDC but when I click on QDC AWS plugin, its pointing out to register folder but I can't find any AWS .Zip plug in.

Appreciate if you shed some light, it will be valuable info for Qlik community.

Regards,

Rahul