Forum Discussion
APM SSO for a downstream forward proxy
Does anyone know a way to make APM SSO work when presented with 407 pages?
I have a requirement to put APM in front of a 3rd party forward proxy server with APM. The proxy only supports authentication via NTLM via a 407 page and NTLM. For a bunch of reasons, I'd like to be able to have users log on once to APM via a form, then when they want to access resources via this proxy have the APM respond to the 407 on their behalf. APM SSO seems to respond fine to 401 messages, but not 407.
I'm sure that if it was basic auth instead of NTLM in the 407, then I could put together an iRule that built a proxy authorisation header out of session variables. But that would involve sending credentials in the clear. So I'd much prefer to use NTLM.
All ideas warmly appreciated.
1 Reply
- Kevin_Davies_40
Nacreous
Create a virtual, attach an iRule, map 407 responses to 401 responses. Point APM at the virtual, point the virtual at the proxy.
The iRule to map responses would be something similar to this
If there are protocol/payload differences it would be up to you to manage them in the iRule. I am not suggesting this would be simple. Click your heels together and check the RFC behaviour in both cases.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com