Forum Discussion
Authenticating to Sharepoint through APM
Hi Guys,
I am hoping you can help me here. I have managed to add my url for sharepoint under Portal Access Resource as an Application URI link (http://IP-Address-Of-Internal-Sharepoint-Server). I have added a resource item as well (IP address, Port 80 and Path /*)
This is for external access (over the internet) to sharepoint through the APM.
Now, when I log into my Portal using my domain username and password (note, I do not login to my portal specifying my AD Domain, just username and password) I get presented my icon for sharepoint. When I click it sharepoint starts to load (as it would if I was internally located and browsed to it directly from my domain connected machine logged on with my domain user account) but then I get a small browser pop up box asking me for credetials. If I type my username and password (same as I did to sing into my Portal page) it letS me in. How can I configure it as such, so it will be take the username and password I typed into my Portal login page to access sharepoint, rather than it ask me to login again?
Secondly, when browsing around sharepoint, the whole url changes as though its masked behind the F5 APM. If I was to want to send someone a link to a document stored in sharepoint, will this work as its a link behind the F5 rather than a direct sharepoint link?
Thirdly, there are some links that just randomly stop working and when clicked the browser reports the page isnt availbale, but other times they will work... This point isnt so important unless I have done something fundamentally wrong in setting this up.
Please feel free to ask me any questions that might help understand the question better.
Thanks Roo
20 Replies
- MichaelatF5
Employee
Verify that you have the proper host header entries in AAM (Alternate Access Mappings, Default Zone), and see if that helps.
You can have multiple entries in the Default Zone. What is happening is that SharePoint is accepting Windows Integrated and assuming you are on the LAN and redirecting you to the Default zone.
- Roo_150490
Nimbostratus
Hi Michael J,
Even though I'm not actually on the LAN would I still check the default zone...? I'll speak to our sharepoint guy.
Thanks for a such a quick response.
- MichaelatF5
Employee
Yep. AAM is generally the issue.
An example where this comes in to play is when using SSL termination at the BIG-IP, as the header contains https://sharepointsite, but sharepoint AAM is not configured with a default zone mapping for https but for http. SharePoint will constantly redirect to http because it senses Windows Integrated. Simple fix is to just have AAM entries for:
https://sharepointsite & http://sharepointsite
- Roo_150490
Nimbostratus
Okay, so is there something specific I'll need to do in AAM? The reason I ask is because I perhaps dont actually want Windows Integrated to be used when accessing through the portal... on the local LAN its perfectly fine and works when browsing direct to sharepoint, as users are logged onto domain joined machines with their domain credentials. The portal is there for remote access for our users wherever they maybe... they may not necessarily be using their corporate laptops and the usernames they have logged into their machines willl be different to their domain usernames (they could be using home computers, personal laptops etc that arent even a member of our AD).. so we dont want to pass these credentials.
The credentials we want to pass are the credentials used to authenticate against the Portal... these credentials will be the users domain username and password that I want to seamlessly pass to sharepoint.
I dont think I'm explaining very well. Regardless I will check AAM as soon as I can find someone in our sharepoint team.
- MichaelatF5
Employee
Specifically, add Host header mappings for all host headers used to access SharePoint.
Windows Integrated will be used by SharePoint regardless of where the users are accessing from. From External systems they will get a prompt. From Internal systems with the URL mapped to Local Intranet sites, they wont.
- kunjan
Nimbostratus
How can I configure it as such, so it will be take the username and password I typed into my Portal login page to access sharepoint, rather than it ask me to login again?
You can configure Single-Sign-On (SSO) fro Sharepoint to help you to login seamlessly
- Roo_150490
Nimbostratus
Ah! Kunjan, hope you're well... Thanks for your response... I will check that out! I didnt realise there was a form based authentication for Sharepoint, like we configured Exchange! - kunjan
Nimbostratus
Has the exchange SSO started working? Didn't occur to me that we had this SSO talk before :) - Roo_150490
Nimbostratus
Yah, its still in the same place... it broke other SSO apps. What would be ideal is if we can somehow get OWA to accept just username and password (which is what is keyed in to log into the portal) instead of requiring domain\username and password.
- kunjan_118660
Cumulonimbus
How can I configure it as such, so it will be take the username and password I typed into my Portal login page to access sharepoint, rather than it ask me to login again?
You can configure Single-Sign-On (SSO) fro Sharepoint to help you to login seamlessly
- Roo_150490
Nimbostratus
Ah! Kunjan, hope you're well... Thanks for your response... I will check that out! I didnt realise there was a form based authentication for Sharepoint, like we configured Exchange! - kunjan_118660
Cumulonimbus
Has the exchange SSO started working? Didn't occur to me that we had this SSO talk before :) - Roo_150490
Nimbostratus
Yah, its still in the same place... it broke other SSO apps. What would be ideal is if we can somehow get OWA to accept just username and password (which is what is keyed in to log into the portal) instead of requiring domain\username and password.
- Roo_150490
Nimbostratus
Okay, let me back to you. I'm hoping they dont even get a prompt from external systems (as thats whats happening now)... The only prompt they should get from external systems is the F5 Login Page for the Portal.
Internally, we access sharepoint direct, no need to go through APM.
- MichaelatF5
Employee
Correct. If your SSO is configured properly, then updating the AAM will solve your problem.
Just another thing some of these issues might be the rewrite technology some of it does not agree with SharePoint (especially the if SP 2010 and Silverlight). URL sometimes become a problem if you want to send them to other users or bookmark.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com