|
|
|
BlueCielo Meridian Enterprise 2012 System Requirements | BlueCielo ECM Solutions |
By default, the EDM Server service runs under the SYSTEM account of the computer. This works well unless
This solution involves creating a dedicated account for the Meridian services to run under and granting that account the domain privileges needed. This solution is preferred by domain administrators when the privileges should be as restricted as possible:
This account needs to have full control over the \BC-Meridian Vaults folder and the registry branch HKEY_LOCAL_MACHINE\Software\Cyco on the Meridian application server.
Note In an Active Directory environment, changing the account under which the AutoManager EDM Server service runs will also require you to add the account to the Pre-Windows 2000 Compatible Access group of the domain, unless the new account is also a domain administrator account. If the account is not a domain administrator and the account is not added to the Pre-Windows 2000 Compatible Access group, strange security behavior will occur in the vault because the new account will not be granted access to query domain user accounts and group membership.
Note If Meridian users reside in multiple domains in an Active Directory forest, you must do this for every domain in which the users reside.
Related concepts
About support for Microsoft Active Directory
Understanding Active Directory security problems
Related tasks
Granting domain privileges to the server
Granting membership query access
Configuring NetBIOS name resolution
Copyright © 2000-2012 BlueCielo ECM Solutions |