TeamcenterKnowledge

System Administration > Administering Teamcenter client communication system (TCCS)

Configure TCCS for Kerberos

Kerberos, a network authentication protocol originally developed at MIT, provides authentication for client/server applications by using secret-key cryptography. With the Kerberos protocol, a client proves its identity to a server (and vice versa) across an insecure network connection. Kerberos allows a user to be authenticated without sending the user’s password over the network. Instead, encrypted tickets derived from the password and secret key information are sent over the network. After you install Kerberos, perform the following steps to set up an environment in TCCS so that users can log on to Teamcenter using Kerberos authentication: In TEM, navigate to the Kerberos Authentication Settings view, which is an advanced view of Client Communication System settings. You reach the view as part of initial installation of the rich client, or as modification of the Client Communication System feature configuration. Procedure Select the Support Kerberos authentication check box. Note On Windows hosts, the Kerberos configuration file is C:\Windows\krb5.ini. On Linux hosts, the Kerberos configuration file is etc/krb5.conf. To always prompt for a Kerberos user name, select the Always prompt for User ID check box. If you want to enable zero sign-on functionality on Windows hosts, clear this check box. Zero sign-on allows Windows users to launch a Teamcenter client without being prompted to log on to Teamcenter. Zero sign-on functionality requires that you configure Security Services in applet-free mode. Click the Back button until you reach the Environment Settings for Client Communication System panel. In the Environment Settings for Client Communication System panel, enter the Kerberos environment. (For applet-free mode, ensure that /tccs is appended at the end of the value in the SSO Login URL box.) Click Next until you reach the Confirmation panel and then click Start. The Kerberos environment information is saved. Results When users log on, they select an environment from the list of configured environments. When prompted for a user name, user must correctly enter the user name for the environment. For Kerberos authentication, the domain must be in all uppercase letters. (For example, username@DOMAIN).

Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/wpq1737238568862/xid721694.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)