-
On the SharePoint Central Administration home page, click the Application Management tab on the top navigation bar.
-
On the Application Management page, in the Office SharePoint Server Shared Services section, click Create or configure this farm's shared services.
-
On the Manage this Farm's Shared Services page, click New SSP.
Important: |
|---|
| If you have not created a Web application for the SSP administration site, you need to create one before you create the SSP. If you have already created a Web application for the SSP administration site, skip to step 14. |
-
On the New Shared Services Provider page, click Create a new Web application.
-
On the Create New Web Application page, in the IIS Web Site section, click Create a new IIS web site , and do not modify the default settings in this section.
-
In the Security Configuration section, under Authentication provider, select the appropriate option for your environment, and do not modify the default settings in the remainder of this section.
Note: |
|---|
| By default, the authentication provider is set to NTLM. Use the Negotiate (Kerberos) setting only if Kerberos is supported in your environment. This option will require configuring a Service Principal Name for the domain user account, for which you must have Domain Administrator credentials. For more information about configuring Kerberos, see Microsoft Knowledge Base article KB 832769: HOW TO: Configure Windows SharePoint Services to Use Kerberos Authentication (http://support.microsoft.com/?kbid=832769). |
-
In the Load Balanced URL section, do not modify the default settings.
-
In the Application Pool section, click Create new application pool.
-
In Application pool name, enter the name of your application pool or use the default name.
-
Click Configurable, and in User name and Password, type the user name and password for the user account that you want to act as the application pool identity for your SSP Web application.
The user account must be a domain user account, but the user account does not have to be a member of any particular security group. It is recommended that you use the principle of least privilege and select a unique user account that does not have administrative rights on your front-end servers or on your back-end database servers. You can use the user account that you specified as the Microsoft Office SharePoint Server 2007 service account; however, if that user account is a member of a security group that has administrative rights on your front-end servers or your back-end database servers, you will not be following the principle of least privilege. The user name must be in the format DOMAIN\username.
-
In the Database Name and Authentication section, verify the database information and make sure that Windows Authentication (recommended) is selected.
-
In the Search Server section, do not modify the default settings.
-
Click OK.
Upon successful creation of the Web application, the New Shared Services Provider page appears.
-
In the SSP Name section, in Web Application , select the Web application that you created for the SSP, and do not modify any of the default settings in this section.
-
In the My Site Location section, do not modify any of the default settings.
-
In the SSP Service Credentials section, in User name and Password, type the user name and password for the user account under which you want the SSP to run.
The user account must be a domain user account, but the user account does not have to be a member of any particular security group. It is recommended that you use the principle of least privilege and select a unique user account that does not have administrative rights on your front-end servers or on your back-end database servers. You can use the user account that you specified as the Office SharePoint Server 2007 service account; however, if that user account is a member of a security group that has administrative rights on your front-end servers or your back-end database servers, you will not be following the principle of least privilege. The user name must be in the format DOMAIN\username.
-
In the SSP Database section, you can either accept the default settings (recommended), or specify your own settings for the database server, the database name, or the SQL authentication credentials.
-
In the Search Database section, you can either accept the default settings (recommended), or specify your own settings for the search database server, the database name, or the SQL Server authentication credentials.
-
In the Index Server section, in Index Server , click the server on which you configured the Search service.
If there is no index server listed in the Index Server section, then no server in your farm has been assigned the index server role. To assign the index server role to a server in your farm, follow the instructions in the "Configure the Search service" section earlier in this topic.
-
In the SSL for Web Services section, click No.
-
Click OK .
Upon successful creation of the SSP, the Success page appears.
-
On the Success page, click OK to return to the Manage this Farm's Core Services page.