Moving away from kerberos auth

Peter Schober peter.schober at univie.ac.at
Tue Jul 5 10:39:26 EDT 2016


* Morris, Andi <amorris at cardiffmet.ac.uk> [2016-07-05 14:06]:
> We want to upgrade the IdP to version 3, and if possible move it
> away from the Kerberos authentication. The reason being is that when
> trying out various appliances to take over TMG's reverse proxy
> roles, they were always failing on the Kerberos authentication relay
> point. We believe the reason for this is because we use a different
> UPN to access the service than our Active Directory domain. E.g. We
> would user service.cardiffmet.ac.uk for the user facing end, however
> our internal domain is internal.otherdomain.ac.uk. This, we think,
> is causing the Kerberos ticketing to bomb out.

AFAIK handling users with Windows Integrated Authentication and ones
without -- whether they're on the same network or elsewhere in the
world -- should be possibe with the IDP, and should not require an
additional reverse proxy handling authentication.
I think Newcastle was one of the first to fully document how that can
be done, but there may be more or more up-to-date documentation in the
Shibboleth wiki?
-peter


More information about the users mailing list