<div dir="ltr">Thank you for the replies.  Can you tell me was it necessary to alter the auth that the workstations used to authenticate to the DC to get true SSO with the IdP?<div>The two articles for tutorials are quite different so I wasn't sure which were needed if not both:</div><div><p style="margin:10px 0px 0px;padding:0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px">To use the authn/SPNEGO login flow, it is necessary to have the Kerberos environment configured and working properly.</p><p style="margin:10px 0px 0px;padding:0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px">Some interesting tutorials that may help are:</p><p style="margin:10px 0px 0px;padding:0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px"><a class="external-link" rel="nofollow" href="http://www.grolmsnet.de/kerbtut/" style="color:rgb(50,96,186);text-decoration-line:none">http://www.grolmsnet.de/kerbtut/</a></p><p style="margin:10px 0px 0px;padding:0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px"><a href="http://msdn.microsoft.com/en-us/library/ms995329#http-sso-1_topic3" rel="nofollow" class="external-link" style="color:rgb(50,96,186);text-decoration-line:none">HTTP-Based Cross-Platform Authentication by Using the Negotiate Protocol</a>.</p></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr">On Wed, Sep 5, 2018 at 1:30 PM Volmer, John A. <<a href="mailto:volmer@anl.gov">volmer@anl.gov</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">We have used Rod's approach below at ANL.<br>
<br>
----- John Volmer, 630.252.5449, <a href="mailto:volmer@anl.gov" target="_blank">volmer@anl.gov</a> -----<br>
<br>
-----Original Message-----<br>
From: users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> On Behalf Of Rod Widdowson<br>
Sent: Wednesday, September 5, 2018 8:23 AM<br>
To: 'Shib Users' <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: RE: Shibboleth in Active Directory<br>
<br>
Does <br>
<a href="https://wiki.shibboleth.net/confluence/display/IDP30/SPNEGOAuthnConfiguration" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP30/SPNEGOAuthnConfiguration</a><br>
help?<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>