For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Michael_61068's avatar
Michael_61068
Icon for Altocumulus rankAltocumulus
Aug 03, 2015

APM authentication against local windows accounts.

Hello,

 

My level of windows authentication knowledge is very low, some maybe this is an easy question. I have not found anything covering this in my initial search.

 

We have an application hosted on a windows server and need to authenticate access against local accounts defined on the windows server.

 

I can define the login page and set the SSO variables and SSO then works, but we need to check the authentication on the APM so that incorrect usernames and passwords are detected and blocked on the APM before hitting the windows server.

 

Is this done using a LDAP authentication between the APM and the windows server? Or an AD authentication, with the local windwos server acting as an AD for the local accounts?

 

Many thanks,

 

2 Replies

  • Does your server provide an authentication service?

     

    The only solution I see are:

     

    • Promote server as Domain controller. LDAP And AD Auth will be available.
    • create a login page on the web server and configure a HTTP Auth on APM.

    Regards,

     

    Stanislas

     

  • If I may add, the AD and LDAP auth and query agents all rely on LDAP running on the target system. It's doubtful that s single standalone server has an LDAP service running. You might be able to get an NTLM Auth agent to work on a standalone system, but it depends on the server. Otherwise, as Stanislas suggested, you could stand up a web server and ties that back to local accounts, and then just do HTTP auth (form or basic).