TeamcenterKnowledge

System Administration > Administering Teamcenter client communication system (TCCS)

Configure TCCS for reverse proxy form-based authentication

If Teamcenter client applications must connect to the Teamcenter web tier via a reverse proxy server that requires form-based authentication, and if the reverse proxy server is other than WebSEAL, then you must either configure TCCS with advanced reverse proxy criteria to recognize the form-based challenge, or disable reverse proxy criteria checking. Failure to do this may lead to errors about invalid SOA responses. This procedure describes how to use Teamcenter Environment Manager (TEM) and Deployment Center to configure TCCS reverse proxy settings. Depending on your environment, you can configure TCCS using other tools such as the TCCS installer, the Client for Office installer, and web tier context parameters. The TCCS configuration options in these tools are similar. Procedure If you are using TEM, navigate to the Reverse Proxy Settings view, which is an advanced view of Client Communication System settings. If you are using Deployment Center, add the Teamcenter Client Communication System component to your system. Select the Teamcenter Client Communication System component, and navigate to its Reverse Proxy Settings section. You reach the view as part of initial installation of the rich client, or as modification of the Client Communication System feature configuration. Depending on your situation, either configure TCCS with criteria to recognize the form-based challenge, or disable reverse proxy criteria checking. In this situation Do this Your reverse proxy performs form-based authentication using SiteMinder or another server type that does not send specific header information in the type 200 form-based challenge. You are troubleshooting communication errors, your reverse proxy requires form-based authentication, and you suspect invalid criteria settings. Select the Skip reverse proxy criteria check checkbox. If checking is disabled, then TCCS treats all reverse proxy text/html packages with HTTP status of 200 as form-based challenges that pass criteria checking. Your reverse proxy is not configured for form-based authentication challenges, thus there is no occasion for TCCS to perform checking. At your discretion, delete any existing criteria and form actions. Criteria are not needed. Ensure that the Skip reverse proxy criteria check checkbox is not selected. Your reverse proxy server performs form-based authentication using WebSEAL, or using another server type that does send specific header information in the type 200 form-based challenge. Ensure that the Skip reverse proxy criteria check checkbox is not selected. Add appropriate criteria for identifying the challenge. The Reverse Proxy Settings view includes two groups: Private Reverse Proxy Settings Lists the reverse proxy criteria currently defined. Each row is a criteria XML element defined in the specified format. By default, the table is blank and no criteria are defined. A criterion string is of the following form: Header_Name1, Header_Value1, Header_Name2, Header_Value2,…:Form_Action Criteria Details Lists the details of a criterion selected in the Private Reverse Proxy Settings group. Each criterion must contain at least one header name/header value pair or at least a single form action. To satisfy a criterion, a reverse proxy form-based challenge package must match every criteria element listed within a given criterion. Next to the Private Reverse Proxy Settings group, click Add. Next to the Criteria Details group, use the Add and Remove buttons to add or remove HTTP header names and values for the selected criterion. In the Form Action box, specify a form action. Click Apply. The criterion is added to the criteria table. Note If you have reached the Reverse Proxy Settings view in TEM, and you do deploy the advanced TCCS configuration, TEM saves the configuration to the reverseproxy_cfg.xml file, which overrides the default WebSEAL configuration. To ensure that TCCS correctly performs checking if you use WebSEAL, add the following criterion: Header name Header value Form action server webseal /pkmslogin.form When you are through configuring criteria, click Next until you reach the Confirmation panel and click Start. The reverse proxy information is saved in the reverseproxy_config.xml file.

Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/wpq1737238568862/xid721696.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)