Microsoft KB Archive/299729

= How To Configure a Host Security Domain for Single Sign-On When Using COMTI in TCP/IP =

Article ID: 299729

Article Last Modified on 2/22/2007

-

APPLIES TO


 * Microsoft SNA Server 4.0 Service Pack 2
 * Microsoft SNA Server 4.0 Service Pack 3
 * Microsoft SNA Server 4.0 Service Pack 4
 * Microsoft Host Integration Server 2000 Standard Edition

-



This article was previously published under Q299729



SUMMARY
This article describes how to configure a Host Security Domain (HSD) for Single Sign-on (SSO) when using COM Transaction Integrator (COMTI) in a TCP/IP-only environment.

This article assumes that the following steps have been completed:
 * SNA Server or Host Integration Server, COMTI and the Host Security components are installed.
 * A COMTI remote environment (RE) has been configured.
 * The COMTI CedarBank sample program that is included with SNA Server or Host Integration Server works going to your mainframe.

NOTE: Although any COM-aware language program that uses COMTI can take advantage of the host account cache (HAC) for SSO look-ups, the CedarBank sample might provide a better test because the correct files are already included. For more information about how to set up the CedarBank sample program, see the application's Help documentation.



MORE INFORMATION
This section describes the four steps that must be completed to configure a Host Security Domain for COMTI:
 * 1) Create a &quot;dummy&quot; connection in SNA Manager.
 * 2) Create a host security domain.
 * 3) Enable security on the remote environment.
 * 4) Populate the host account cache.

Before COMTI can perform a look-up using the host account cache, a &quot;dummy&quot; connection must first be configured in SNA Manager. Although the dummy connection is not used, you must have it to configure a Host Security Domain.

Step 1: Create a Dummy Connection

 * 1) Open SNA Manager.
 * 2) Add a Demo SDLC Link Service: right-click the Link Service folder, and then click New/Link Service.
 * 3) Create a connection: right-click the Connections folder, and then click New/SDLC.
 * 4) On the Connection Properties page, name the connection (COMTI), select the link service that you created in step 2 (SnaDemo1), and leave all other default settings.

Step 2: Create a Host Security Domain

 * 1) To start the Host Security Domain Wizard, right-click the Host Security Domain folder, and then click New/Host Security Domain.
 * 2) When prompted, name your Host Security Domain as COMTIHSD.
 * 3) Select the SNA Connection using the drop-down menu. For this example, it looks similar to COMTI on  .

Accept all the other default settings while you continue through the wizard.

Step 3: Enable Security on the Remote Environment

 * 1) Open COMTI Manager.
 * 2) Right-click the CedarBank remote environment, click Properties, and then click the Security tab.
 * 3) To enable security, click the Set security on check box and then select the appropriate authentication (package or user credentials).

NOTE: Enabling Allow application to override selected authentication (also known as Explicit Security) prevents look-ups to the host account cache. Using Explicit Security means the program that calls the COMTI method supplies the userid and password that is sent to the host.
 * 1) In the Host Security Domain list, type the Host Security Domain name that you created earlier (that is, COMTIHSD) because it does not appear in the list.

Step 3: Populate the Host Account Cache
To take advantage of SSO, the user account that you will be using must be populated in the HAC. To populate the HAC, use one of the following methods:
 * For an existing user account, force a password change on the user account in question. The next time the user changes his/her password, the HAC will be populated.
 * For an existing user account, use Host Account Manager (UDCONFIG), select the user account in question, type the user's password, and then select Update Cache.
 * If you are setting up a new user account for the first time, after you create a UserID and password, this user is automatically entered into the HAC.

To verify a user in the HAC database, you can type the following command from either the SNA Server or the Host Integrations Server command prompt:

snacfg hsmapping *\* /print

Additional query words: HIS 2000

Keywords: kbhowto KB299729

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.