Forum Discussion
mixing SSO methods, i.e. ntlm, basic http and kerberos
HEllo, is it possible to share how policy should look like for both aaa (client side) and sso (server side) authentication?
I am struggling with implementing such a flow:
User ------ any page except sso-login.htm ----> Big Ip ------ any page ---> server
User <----- response ----------------------------- BigIP <------- response ---- server
User ----- sso-login.html ------> BigIp User <----- 401 Negotiate-------- BigIp (if no valid previous kerb-Auth-ok cookie found)
User ----- TGT ---------------------> BigIP -------- request sso-login.htm ----> server
BigIP <-------- 401 Negotiate ----> server
BigIP -------- TGT as user ----> server User <---- response with kerb-Auth-Cookie -- BigIp <------- response --- server (if kerb auth OK
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com