Kerberos Authentication
David Mansfield
shibboleth at dm.cobite.com
Fri Mar 6 14:36:35 EST 2015
Hi:
Did you find the AJP connector settings in your server.xml and change it
to make sure tomcatAuthentication="false" is specified?
Mine looks like:
<Connector port="8009" protocol="AJP/1.3" redirectPort="8443"
tomcatAuthentication="false" />
Also, here is my apache virtual host configuration:
Listen idptest.mydomain.com:443
<VirtualHost idptest.mydomain.com:443>
ServerName idptest.mydomain.com
SslEngine on
ProxyPass /idp ajp://localhost:8009/idp retry=0 flushpackets=auto
ProxyPassReverse /idp ajp://localhost:8009/idp
<Location />
AuthType Kerberos
AuthName "Enter Domain Credentials"
Krb5Keytab /etc/httpd/conf/idptest.keytab
KrbAuthRealms MYDOMAIN.COM
Require valid-user
KrbLocalUserMapping on
# allow user of passwords
KrbMethodK5Passwd on
</Location>
</VirtualHost>
- David
On 03/06/2015 11:19 AM, Arnal, Pascal wrote:
>
> “Second, use the RemoteUserAuthnConfiguration, standard. I *think*
> you need to set tomcatAuthentication=false in your server.xml
> (assuming you are running the IdP in tomcat) or else it will ignore
> the passed credential information received from apache over the ajp link.”
>
> I try to use this solution but I have one error
>
> [net.shibboleth.idp.authn.impl.ValidateExternalAuthentication:121] -
> Profile Action ValidateExternalAuthentication: External authentication
> failed, no user identity or error information returned
>
> Could you explain me how to configure Apache httpd and Tomcat together ?
>
> Thanks
>
> *De :*users-bounces at shibboleth.net
> [mailto:users-bounces at shibboleth.net] *De la part de* David Mansfield
> *Envoyé :* 3 mars 2015 12:01
> *À :* users at shibboleth.net
> *Objet :* Re: Kerberos Authentication
>
> Hi:
>
> I think I used apache with mod_auth_kerb, combined with "remote user"
> authentication.
>
> First get mod_auth_kerb working by creating some directory on your
> apache (say /secure) and get it protected. There are lots of docs on
> the internet.
>
> Basically: create a keytab on the AD server for HTTP/your.server.name,
> and export it and put it "somewhere" on your IDP with the right
> permissions and possibly the right selinux security context.
> Configure in apache .conf file. Make sure this is working.
>
> Second, use the RemoteUserAuthnConfiguration, standard. I *think* you
> need to set tomcatAuthentication=false in your server.xml (assuming
> you are running the IdP in tomcat) or else it will ignore the passed
> credential information received from apache over the ajp link.
>
> This is all from memory. My test IdP is currently unavalable.
>
> --
> Thanks,
> David Mansfield
> Cobite,
>
> On 03/03/2015 11:14 AM, Arnal, Pascal wrote:
>
> Hi,
>
> I would like to use my Windows Authentication with Shibboleth IDP
> V3 AND Shibboleth SP V2.
>
> I followed the documentation
> https://wiki.shibboleth.net/confluence/display/IDP30/KerberosAuthnConfiguration
>
> When I want to access my application, the login page of the IDP is
> displayed and after I filled my credentials, my application is
> accessible.
>
> Now I would like to use my Windows Authentication and the Kerberos
> Token for not fill again my credential.
>
> Is-it possible, and how please ?
>
> Thanks
>
> ------------------------------------------------------------------------
>
> AVIS: Ce courriel privilégié et confidentiel est destiné à la
> seule personne ou entité à laquelle il est adressé. Pour toute
> autre personne, toute action prise en rapport à ce courriel ainsi
> que toute lecture, reproduction, transmission et/ou divulgation
> d'une partie ou de l'ensemble de celui-ci est interdite. Si vous
> n'êtes pas la personne autorisée à recevoir ce courriel, S.V.P. le
> retourner à l'expéditeur et le détruire. Bien que ce courriel ait
> été traité contre les virus, il est de la responsabilité du
> destinataire de s'assurer que l'envoi en est exempt. Nos
> communications avec vous peuvent contenir des renseignements
> confidentiels ou protégés par le secret professionnel. Si vous
> désirez que nous communiquions avec vous par un autre moyen de
> transmission que le courrier électronique ordinaire non sécurisé,
> veuillez nous en aviser.
>
> NOTICE: This privileged and confidential email is intended only
> for the individual or entity to whom it is addressed. With regard
> to all others, any action related with this email as well as any
> reading, reproduction, transmission and/or dissemination in whole
> or in part of the information included in this email is
> prohibited. If you are not the addressee, immediately return the
> email to sender prior to destroying all copies. Even if this email
> is believed to be free from any virus, it is the responsibility of
> the recipient to make sure that it is virus exempt. Our
> communications to you may contain confidential information or
> information protected under solicitor-client privilege. Please
> advise if you wish us to use a mode of communication other than
> regular, unsecured e-mail in our communications with you.
>
>
>
> ------------------------------------------------------------------------
> AVIS: Ce courriel privilégié et confidentiel est destiné à la seule
> personne ou entité à laquelle il est adressé. Pour toute autre
> personne, toute action prise en rapport à ce courriel ainsi que toute
> lecture, reproduction, transmission et/ou divulgation d'une partie ou
> de l'ensemble de celui-ci est interdite. Si vous n'êtes pas la
> personne autorisée à recevoir ce courriel, S.V.P. le retourner à
> l'expéditeur et le détruire. Bien que ce courriel ait été traité
> contre les virus, il est de la responsabilité du destinataire de
> s'assurer que l'envoi en est exempt. Nos communications avec vous
> peuvent contenir des renseignements confidentiels ou protégés par le
> secret professionnel. Si vous désirez que nous communiquions avec vous
> par un autre moyen de transmission que le courrier électronique
> ordinaire non sécurisé, veuillez nous en aviser.
>
> NOTICE: This privileged and confidential email is intended only for
> the individual or entity to whom it is addressed. With regard to all
> others, any action related with this email as well as any reading,
> reproduction, transmission and/or dissemination in whole or in part of
> the information included in this email is prohibited. If you are not
> the addressee, immediately return the email to sender prior to
> destroying all copies. Even if this email is believed to be free from
> any virus, it is the responsibility of the recipient to make sure that
> it is virus exempt. Our communications to you may contain confidential
> information or information protected under solicitor-client privilege.
> Please advise if you wish us to use a mode of communication other than
> regular, unsecured e-mail in our communications with you.
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150306/73114a73/attachment.html
More information about the users
mailing list