About this task
Use this procedure to add the Avaya Aura® Web Gateway SPN to a domain user on the Windows Domain Controller or the Active Directory server. The SPN must be unique across the domain. To avoid issues with duplicated SPNs, track of any SPNs assigned to users.
Avaya Aura® Web Gateway supports IWA for multiple domains. To configure IWA for multiple domains that are in different Active Directories, repeat this procedure on each Active Directory.
Important:
Enter all commands exactly as shown in this procedure, and use the following guidelines:
The hostname used to access the Tomcat server must match the host name in the SPN exactly. Otherwise, authentication fails.
The server must be part of the local trusted intranet for the client.
The SPN must be formatted as HTTP/<host name> and must be exactly the same everywhere.
The port number must not be included in the SPN.
Only one SPN must be mapped to a domain user.
The Kerberos realm is always the uppercase equivalent of the DNS domain name. For example, EXAMPLE.COM.
Avaya Aura® Web Gateway supports IWA for parent and child domains. However, you cannot assign an SPN and generate a tomcat.keytab file for the child domain because the SPN can only be mapped to a single user in a forest. Here, you need to assign the SPN and generate a tomcat.keytab file for the parent domain.