Skip to main content
1-Visitor
May 17, 2016
Question

Single Sign-On for Windchill with Apache, Shibboleth, and ADFS - Has Anyone Done This Before?

  • May 17, 2016
  • 4 replies
  • 13166 views

I am picking up an in-process project of configuring SSO with the software mentioned in the question, and as I dive in I wanted to put out a question to the user community here to see if anyone has implemented this within their environment, and if so, could provide any helpful details/information as I go forward.  Even if not the exact same software environment, but configuring SSO in general, that would be a significant help.

Thanks in advance!

4 replies

1-Visitor
May 20, 2016

First question: Do you have a multi-organization deployment of PDM? That answer will define if it's even a good idea for you to try what you mentioned.

Please advise,

Daryl

bsindelar1-VisitorAuthor
1-Visitor
May 20, 2016

Yes, this is a multi-organization deployment as far as organization containers are concerned, though I do believe that strategy is being used for data separation/access permission only and all user information is ultimately stored in one corporate LDAP (this is a system I am working with that has been inherited - I have not been involved from the ground up).

Have you done this before, Daryl?

1-Visitor
May 20, 2016

Not quite yet but I've been asked to explore the option of a multi-org setup and very quickly discovered a problem when it comes to accounts when you have the possibility of one user helping deal with data in multiple in-system organizations.

The key issues:

  • Every user account has to be set to an organization. If you don't the access they have to data inside the organization is quite crippled.
  • A user account in one organization has little to no access to data in the other organization pretty much no matter what you do to their Profiles, policy administrator access rules, etc...the fundamental framework forces separation.

EASIEST SOLUTION: do not have automated SSO and let users have multiple accounts, one per organization (a quick way to ID which is which is to put the organization name after their username. Everything else including the email address and even password can be the same), and then if the users set their browsers to not remember usernames and passwords when they go to login to PDM-Link they can just pick the account they need based on which Organization they need to do heavy work in. On this basis alone I have aggressively halted any conversation on getting our login LDAP linked; our engineers need to be able to help the other potential organizations do their main design work.

10-Marble
July 18, 2016

Hello Bob,

I have been tasked this week to implement SSO (Single SIgn On) with ADFS (Active Directory Federation Services) which I have never used.

PTC itself does not directly support Single Sign On which is a Problem as SAP and the other 3 Applications they integrated apparantly supply the Step by Step commands required within the ADFS interface.

All I have found at ptc.com is Help which mentions which Authentication Methods Windchill Supports.

Have you or  anyone implemented SSO with ADFS and would you be willing to provide your Installation Procedure.  (ADS side and changes to Apache/Windchill)

Brian Sullivan

Windchill 10.2 M020

We will implement SSL (Https) as IT Department requires for Integration to ADFS

11-Garnet
August 25, 2016

We have exactly this configuration working in production at my site. We have windchill 10.2 m030 with shibboleth installed in front of Apache, talking to an adfs server for authentication.

We can confirm that this works as a single sign on and the remote_user variable is what the windchill LDAP uses to identify the windchill user.

Both desktop integration and the cad work group managers work with this. So far the only solution that doesn't work is the arbortext integration but that's a back burner for us.

10-Marble
November 16, 2016

We have implemented the SSO in our Test environment using Shibboleth and ADFS.  Everything works well, except the following:

1. SSO will only works for IE 11 and Chrome.  It will not work for Firefox.

2. Command-line Bulk Upload command will no longer working.  (including any customization of bulk upload in WC UI that use the bulk loading command in the background).

3. Running Query report with Excel link will fail.

3. Creo Parameter connecting to your Windchill will also not work with SSO.

The workaround solution we have is to write a SSO Turn On and Turn Off script at Apache level, but it is not perfect!  (and it defect the original purpose).

If you can live with the above, you can use the SSO.

Sincerely,

Thomas Chao

1-Visitor
June 12, 2018

hi ,

 

We are configuring Windchill sso with PingFederate as Identity Provider.

Can anyone please describe the steps to accomplish the task.

 

ThankYou,

madhu