This solution assumes the following:
Access Manager is installed and configured. For more information see the Novell Access Manager 3.1 SP1 Installation Guide.
The Active Directory domain contains entries for both the users and their machines.
Active Directory and the Identity Server must be configured to use a Network Time Protocol server. If time is not synchronized, authentication fails.
The Access Manager prerequisites have been met for Kerberos authentication. For a list, see Prerequisites
in the Configuring Advanced Local Authentication Procedures
chapter of the Novell Access Manager 3.1 SP1 Identity Server Guide.
A properly configured DNS server is available to provide DNS names for the Identity Server, the Access Gateway, and the SAP Portal server. Access Manager uses the DNS names to handle requests so that authentication is seamless to the user.