Starter: Authenticate Windchill Users with SSO

Version 11.0.1.0

Authentication of user data for Windchill can be performed with an existing Windchill server with SSO (single sign-on) setup, thus omitting the login process in GENIUS TOOLS Starter. The authentication provider Auth_Windchill_SSO.exe is provided for this purpose.

The setting for SSO authentication is made in GENIUS TOOLS Project Configurator: Menu item Configuration gts_configurator_konfiguration_blue17 > GENIUS TOOLS Starter App > Group: Standard > Area: Authentication and applies globally. Specifications in units are not possible.

The administrator who switches to an authentication provider is automatically saved as an administrator, i. e. they are added to the Administrator role as a member. The new access data is requested before the database is saved. GENIUS TOOLS Starter App is restarted automatically.

Setting up SSO authentication in GENIUS TOOLS Project Configurator

Setting up SSO authentication in GENIUS TOOLS Project Configurator

Note that it is possible to save a new authentication method even without successfully entering the credentials, namely by confirming the error message. If you want to make use of this possibility, e. g. because you access GENIUS TOOLS Project Configurator externally, make sure that you enter correct credentials and check the role assignments and function accesses.

Warning: If incorrect credentials are saved for the new authentication method, you may not be able to re-enter GENIUS TOOLS Project Configurator.

To avoid being permanently locked out of GENIUS TOOLS Project Configurator, you can manually add your alternative authentication system user name or assign "Everyone" to the Administration role.

In case you have locked yourself out of GENIUS TOOLS Project Configurator when switching to an alternative authentication system, you can use the last database sut_*.db in the caddepot under <Operatingenvironment>\configuration\database\BackupDefaultAuth to restore the working environment.

Please note: SSO authentication cannot be supported for server operating systems that allow several users to work simultaneously on one machine.