Forum Discussion
Martin_Robbins
Nimbostratus
Mar 28, 2014APM websso credential lost
Hello,
We have several SharePoint 2013 sites deployed behind an F5 with APM using AD with NTLMv2 websso.
There is an issue when a user tries to access something that they are not "allowed" to or ...
Martin_Robbins
Nimbostratus
Mar 28, 2014Hi,
Thanks for trying, the other situation it happens in is when a user changes their AD password on another device whilst the session is still active but obviously you want it to deny access on that.
Not sure if it is a fix but I added this iRule to the last irule on the VS and it seems to have helped but it isn't test by any stretch of the imagination .. 8-)
if { [ACCESS::session data get "session.sso.token.last.username.sso.state"] equals "1" }{
log local0. "Session \"[ACCESS::session sid]\", WebSSO is LOST."
ACCESS::session data set "session.sso.token.last.username.sso.state" 0
clientside { HTTP::respond 403 content "The page cannot be displayedError Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administrator." noserver Pragma "no-cache" Cache-Control "no-cache, must-revalidate" Content-Type "text/html" }
}Cheers for any comments/help.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects