<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hi all,<o:p></o:p></p>
<p class="MsoNormal">I’m after some advice on the best methods for user authentication in our environment with the changes that we’re looking to make in the near future.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The background:<o:p></o:p></p>
<p class="MsoNormal">We currently use Shibboleth IdP 2.3 on RedHat Linux with the mod_auth_kerb Apache module, this seamlessly authenticates users that hit the IdP from our internal network using Windows Integrated Authentication against our Active Directory
 database.<o:p></o:p></p>
<p class="MsoNormal">For users hitting the IdP from outside of our network we have Forefront TMG acting as a reverse proxy, and also authenticating the user, again using Kerberos.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Going forward:<o:p></o:p></p>
<p class="MsoNormal">We want to upgrade the IdP to version 3, and if possible move it away from the Kerberos authentication. The reason being is that when trying out various appliances to take over TMG’s reverse proxy roles, they were always failing on the
 Kerberos authentication relay point. We believe the reason for this is because we use a different UPN to access the service than our Active Directory domain. E.g. We would user service.cardiffmet.ac.uk for the user facing end, however our internal domain is
 internal.otherdomain.ac.uk. This, we think, is causing the Kerberos ticketing to bomb out.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Shibboleth is currently the only system we run here that is authentication with Kerberos, so if there’s another way we can successfully authenticate users internally using integrated authentication, and externally using credentials passed
 from a third party portal (we’re keen to use CAS for its single sign on possibilities, and because we can run ADFS and Shibboleth alongside each other).<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Any advice would be gratefully received.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Cheers,<br>
Andi<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-GB">-------------------------------------<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-GB">Andi Morris<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-GB">IT Security Officer<br>
Cardiff Metropolitan University<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-GB">T: 02920 205720<br>
E: <a href="mailto:amorris@cardiffmet.ac.uk"><span style="color:blue">amorris@cardiffmet.ac.uk</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-GB">--------------------------------------<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<hr>
<br>
<a href="http://www.cardiffmet.ac.uk/news/Pages/Cardiff-Met-research-recognised-in-Queens-Anniversary-Prizes-for-Higher-and-Further-Education.aspx" target="_blank"><img src="http://campaigns.cardiffmet.ac.uk/queensprize/QueensPrize.jpg" alt="Cardiff Metropolitan University - Queens Anniversary Prizes 2015" width="200" height="251" border="0"></a>
</body>
</html>