TeamcenterKnowledge

System Administration > File Management System > Administering FMS > Configuring FMS

Configuring enhanced ticket authentication

FMS permits file data access only when the requester presents a valid security ticket. You can enhance this security by configuring FMS to use Teamcenter Security Services (TCSS) to authenticate tickets only when the requester presenting the valid security ticket is the user who generated the ticket. Configure enhanced ticket authentication using one of the following scenarios. Configure an FSC server to act as an edge server with which TCSS clients interact. Configure a single FSC to handle both authenticated and non-authenticated ticket access in addition to uploading and downloading files to other FSCs and FCCs. Configure an FSC server as an edge server This approach designates an FSC server with TCSS installed as an edge server with which TCSS clients interact. The FSC edge server authenticates each ticket, verifying that the requester presenting the valid security ticket is the user who generated the ticket, before passing it to a data center FSC. Non-interactive clients (for example, Visualization Server and Teamcenter Server) not using TCSS are mapped to FCS servers not configured with TCSS authentication. Active Workspace does not use TCSS, so is also mapped to FCS servers not using TCSS authentication. Example of an enhanced ticket authentication configuration: Configure enhanced ticket authentication as follows: Verify TCSS configuration Preform the following steps: Ensure TCSS and Security Services (SSO) are installed and configured. Ensure that you can log on to the rich client. Verify you logged on using SSO. Record the following values for later use. See Find Security Services settings for use in TCCS. SSO AppID SSO Identity Service URL Login Service URL Configure TCSS on the edge FSC Enable ticket authentication for all requests on the edge FSC by ensuring that the following lines are included (uncommented) in the edge FMS server configuration file (fsc.xml). (Here SOOappID, identity_service_url, and login_service_url are the values you recorded when verifying your TCSS configuration.) Copy ... ... Example: Copy ... ... By default, the session cookie on the FSC is valid for 1800 seconds (30 minutes) when SSO is configured. After this time, a new cookie is created on the next request sent to the FSC. Use the FSC_TcSSSessionCookieTimeout parameter as shown to adjust this timeout value (in seconds) if required. Configure the FMS primary For each rich client and other interactive client assigned to use the edge FSC, configure the clientmap element of the FMS primary configuration file (fmsmaster_fscid.xml) to use the edge FSC as the assigned FSC. (See Subnet/mask attributes in a client map.) Example: Copy Configure a single FSC for all ticket authentication You can configure a single FSC to handle both authenticated and non-authenticated ticket access in addition to its responsibilities of uploading and downloading files to other FSCs and FCCs. With an FSC configured for single FSC authentication, the FSC authenticates the TCSS clients requiring ticket authentication and the non-interactive clients (such as Visualization (Vis) Server and Teamcenter Server (TcServer)) not using TCSS authentication. Using this single FSC authentication simplifies your system configuration and processes requests more quickly than configurations using a secondary server for authentication. Example of a single FSC ticket authentication configuration: Configure an FSC for single FSC authentication as follows. Ensure TCSS and Security Services (SSO) are installed and configured. Ensure that you can log on to the rich client. Verify you logged on using SSO. Open Deployment Center and perform the following steps. Go to the Components task, and select the FSC component. Check Enable Enhanced Ticket Authentication?. Enable Single Authentication FSC? is displayed. Check Enable Single Authentication FSC?. Confirm that Authenticated Port is set to the value of an open port on the FSC. The default port value is 4545. For reference, FSC Authenticated Url provides the full URL to the authenticated port on the FSC. Generate and run the Deployment Center installation script.

Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/uuc1737238583853/fhe1737238587390/nxs1737238591363/xid1916883.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)