This article explains the steps to configure Kerberos with QlikSense. However it's important to note that the actual setup, implementation, and configuration of Kerberos for Qlik is the responsibility of the customer.
Note: The following will require appropriate permissions in Active Directory to add Service Principal Names on the account running Qlik Sense services.
A Service Principal Name may be registered using the following command:
setspn -A http/HOST serviceaccount
- HOST is the name of the server hosting Qlik Sense.
- serviceaccount is the account running Qlik Sense services.
1. Open a command prompt with administrative privileges and type :
Windows Server 2008 / R2 and Windows Server 2012
setspn -U -S http/QlikServer1 COMPANYX\serviceAccount
setspn -U -S http/QlikServer1.companyx.local COMPANYX\serviceAccount
2. Go to the QMC > Proxy > Edit
Check the 'Enable Kerberos' checkbox.NOTE
: An SPN must be set for both the short hostname and
FQDN for the target Qlik Sense server for Kerberos to work correctly. This is not related to URLs configured in the Web Client Whitelist under the Virtual Proxy configuration.
For more information about Service Principal Names see: http://technet.microsoft.com/en-us/library/cc961723.aspx