Creating identifier associations for John Day

 

You must create the appropriate associations between the EIM identifier, John Day, and the user identities that the person represented by the identifier uses. These identifier associations, when properly configured, enable the user to participate in a single signon environment.

In this scenario, you need to create one source association and two target associations for the John Day identifier:

Use the information from your planning work sheets to create the associations.

To create the source association for John Day's Kerberos principal, follow these steps:

  1. On System A, expand Network > Enterprise Identity Mapping > Domain Management > MyCoEimDomain > Identifiers.

  2. Right-click John Day and select Properties.

  3. On the Associations page, click Add.

  4. In the Add Association dialog, specify or Browse... to select the following information, and click OK.

  5. Click OK to close the Add Associations dialog.

To create a target association for John Day's System i user profile on System A, follow these steps:

  1. On the Associations page, click Add.

  2. In the Add Association dialog, specify or Browse... to select the following information, and click OK:

  3. Click OK to close the Add Associations dialog.

    To create a target association for John Day's System i user profile on System B, follow these steps:

  4. On the Associations page, click Add.

  5. In the Add Association dialog, specify or Browse... to select the following information, and click OK:

  6. Click OK to close the Add Associations dialog.

  7. Click OK to close the Properties dialog.

Now that you have created the identifier associations that map John Day's user identities to his EIM identifier, you can create similar associations for Sharon Jones.

 

Parent topic:

Scenario: Enabling single signon for i5/OS
Previous topic: Creating EIM identifiers for two administrators, John Day and Sharon Jones