Skip to main content
Announcements
Live today at 11 AM ET. Get your questions about Qlik Connect answered, or just listen in. SIGN UP NOW

QlikView Service Account Requirements

No ratings
cancel
Showing results for 
Search instead for 
Did you mean: 
Sonja_Bauernfeind
Digital Support
Digital Support

QlikView Service Account Requirements

Last Update:

Nov 9, 2023 7:32:46 AM

Updated By:

Chip_Matejowsky

Created date:

Sep 25, 2018 4:56:25 AM

The QlikView Services can be set up to either use the local QlikView Administrators Group, or Digital Certificates. The Service Account has specific requirements. 

The two options during installation are Use digital certificates and Use QlikView Administrators Group.

Use digital certificates: 

Authenticate communication between QlikView servers using digital certificates and SSL. This alternative is recommended in environments where not all servers have access to a common Windows Active Directory or when the security provided by certificate authentication is required. Note that digital certificates are only supported by Windows Server 2008 R2 and later.

Use QlikView Administrators Group: 

Authenticate communication between QlikView services based on membership in the local Windows group QlikViewAdministrators. This alternative can be used in environments where all servers that are part of the QlikView installation can authenticate using a common Windows Active Directory.



Regardless of the option chosen, the service account used to run the services has to be:

  • A local administrator on the host operating system
  • Be able to run as a network service
  • Have access to all the QlikView related folder structure, such as ProgramData, Program Files, and configured application data (.qvw storage, .qvd storage, log files) locations. 

 

Note:  GMSA (Standalone Managed Service Accounts) are not supported for Qlik products


Environment: 

 

Related Content:

Labels (1)
Comments
shravan
Contributor
Contributor

I am upgrading my environment from 12.2 SR5 to 12.5 SR2. 

I would like to continue the same mode of authentication that was previously used. 

As i don't have the information what was used during the initial install, Can i find out using logs or install logs this piece of information : "whether digital certificates was chosen" or "server administrators group was chosen"

Sonja_Bauernfeind
Digital Support
Digital Support

Hello @shravan

You can check what you are using in the QlikView Management Console. See Am I using Certificate Trust or Windows Groups between QlikView services? for details.

shravan
Contributor
Contributor

Hello @Sonja_Bauernfeind 

Thank you . that helps. 

ilyas393
Creator
Creator

Hi @Sonja_Bauernfeind ,

If we have digital cert trust, and say all ours servers are in domain A (with service account X from domain A) and one QVWS is on domain B, with service account Y from the domain B. Then does this service account Y need to have read access to domain A active directory and its users for authentication?

Thanks

 

Sonja_Bauernfeind
Digital Support
Digital Support

Hello @ilyas393 

These are our multi-domain requirements: 

  • Domain Trust (see Domains as Units of Trust (Microsoft.com) 
  • Correct DNS Forwarders
  • An Administrator account for each Active Directory able to look up Users and Groups

See Is it possible to set up multiple Active Directory domains within one QlikView Server?  and Users from AD DomainB can't connect to QlikView server that resides in AD DomainA.

All the best,
Sonja 

Version history
Last update:
‎2023-11-09 07:32 AM
Updated by: