Forum Discussion
APM and certificate based AD authentication
- Mar 15, 2016
In other words: APM doesn't have the user's password. The normal solutions to this are:
- Use Kerberos SSO with a delegation account. This is easy an long as your web server is IIS.
- Use SAML.
Sometimes people come up with other solutions. Because APM has access to irules, you can basically implement anything that is technically possible, with the important exception of passing the client's certificate through to the backend app. We don't support doing that.
I'd recommend consulting your app vendor to get their preferred SSO delegation technique.
In other words: APM doesn't have the user's password. The normal solutions to this are:
- Use Kerberos SSO with a delegation account. This is easy an long as your web server is IIS.
- Use SAML.
Sometimes people come up with other solutions. Because APM has access to irules, you can basically implement anything that is technically possible, with the important exception of passing the client's certificate through to the backend app. We don't support doing that.
I'd recommend consulting your app vendor to get their preferred SSO delegation technique.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com