Kerberos Authentication

Jarno Huuskonen jarno.huuskonen at uef.fi
Tue Mar 31 05:03:45 EDT 2015


Hi,

On Tue, Mar 31, Dave Perry wrote:
> Thanks Caleb.
> I did broach the idea of a modified user agent with our desktop team and they basically panicked that it would break stuff - I'm thinking more realistic an idea would be if I could get spengoscript to activate if something is in the url (e.g. &autologin=1, or a hidden variable posted from a button).
> 
> I'll come back to this when we hear more news from your end. And my new IdP sort of behaves normally..

When we tested (with idp-2.4.x) spnego authentication we activated
spnego if:
- client ip was in our network (+ vpn networks)
- client browser sent uefspnego cookie (we created a powershell script
  that would set the cookie(cookie lifetime was set to years) in IE (idea
  was to run this powershell on desktop login scripts)).

(this uefspnego cookie was also because changing IE user-agent could
break something ...).

-Jarno

-- 
Jarno Huuskonen


More information about the users mailing list