CapitalKnowledge

Administering Domains, Roles and Users

Using Secure Sign-On Modes

To enhance security when you log into the Capital applications, a token-based mechanism is available for OpenID Connect (OIDC) based login to desktop applications, and a pre‑shared key mechanism is available to enable secure Single Sign‑On (SSO) communication between server components such as Capital Integration Server (CIS), Capital Runner processes, and Capital Manager.

During the installation of the software, the default pre‑shared key is included in the Capital_Installation/config/ssosharedprops.xml file. If required, you can use the CapitalUtility.exe to generate a unique pre‑shared key.

The Windows Single Sign‑On (SSO) based login to desktop applications is enabled by default for on-premise installations. However, it is recommended to disable it because of the security risks. You enable or disable SSO using the Capital_Installation/config/managerprops.xml file. For more extensive information about SSO, see Delegated Sign On. It is disabled by default if you are using Capital X.

Procedure

  1. To use your own unique pre‑shared key:

                     Run the following command from the Capital_Installation/bin directory to
                         generate your own ssosharedprops.xml file.
                     
                         Copy`CapitalUtility.exe -generate-sso-shared-file`
                     
                     The Capital_Installation/config/ssosharedprops.xml.new
                         file is created.
                 
    
                 
                     Rename the file to replace the default
                             ssosharedprops.xml file.
                 
    
                 
                     Copy the file to the server and services running Capital Integration
                         Server (CIS), Capital Runner processes, and Capital Manager.
                 
    
             
             
                 Caution 
                     Only perform the following step if you require Windows Single Sign-On
                         (SSO) and accept the security risks.
    
  2. To enable or disable SSO:

                     Set the following parameter to "yes" or "no" within the
                             Capital_Installation/config/managerprops.xml
                         file.
                     
                         Copy`<windowsdelegatedsignon allowed="yes"/>`
                     
                 
    
                 
                     Restart Capital Manager.
    

Parent Topic:

Administering Domains, Roles and Users

Related Topics

  • Delegated Sign On

  • The managerprops.xml File Format

Capital Access Manager User Guide, 2512.2606

Unpublished work. © 2026 Siemens

Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/vbu1712233607044 · retrieved 2026-07-18