60 ECLYPSE Connected Thermostat (ECY-STAT)
Single Sign On (SSO) Settings
The
Single Sign On (SSO)
service allows a user to use one set of login credentials (e.g.username and
password) to access multiple ECLYPSE devices that are on the same network. This provides a secure
centralized login method to authenticate users.
The basic functionality behind an SSO service with the ECY-STAT is the Client-Server architecture
where one controller is defined as the Server dedicated to authentication/authorization purposes to ac-
cess the Client controllers.
The SSO authenticates the user for all the controllers the user has been given rights to and eliminates
further login prompts when the user accesses other controllers within the same session.
The session ends if you close the web browser or you log out. It is recommended that you close your
web browser after logging out.
Figure44: SSO Architecture
With the SSO service, you will be automatically redirected to the SSO server login page when you
navigate to a SSO client web page. Once you are authenticated by the server, you will be redirected to
the web page you requested on the client. If you requested the default page, you will be redirected to
your Welcome page instead.
Enter the Client IP
address
(e.g.,192.168.0.22)
Redirected to the
login page of the
server IP address
Login page
(Server IP address)
(e.g.,192.168.0.10)
Client IP
Welcome page
or specific URL
(e.g.,192.168.0.22)
Figure45: SSO Authentication Sequence
The Xpress
Network
Utility allows you to perform a range of operations on many controllers at once, so
we highly recommend that you use Xpress
Network
Utility when configuring the SSO parameters for
your controllers.
The SSO requires HTTPS to function properly. HTTP cannot be enabled and will automatically be disabled when
SSO is activated.
See also Setting Up the SSO Functionality.
ECLYPSE Web Interface