Forum Discussion
NTLM SSO for end-users in a AD domain
Hi, I have users which are already authenticated within the AD domain. My BIG-IP APM/LTM should do the following:
- provide SSO to the backend server: the SharePoint server should see the user credentials
- if a users is already authenticated against the AD, the user should not see any login prompt.
- I would like to use NTLM
There is a solution [http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-aaa-auth-config-11-4-0/3.htmlconceptid] but this is based on Kerberos.
Is this only possible with Kerberos or should NTLM work also?
My main concern is if with NTLM SSO to the backend is possible or not.
3 Replies
Yes, using NTLM on the front-end is possible - but because NTLM authentication cannot be proxied - meaning that APM does not get user's password during NTLM authentication - so regardless of whether you use Kerberos or NTLM to authenticate to APM, you will have to setup Kerberos Constrained Delegation on the backend for SSO.
https://devcentral.f5.com/articles/leveraging-big-ip-apm-for-seamless-client-ntlm-authentication
- EmBee_57573
Nimbostratus
thanks Michael, great article. Learned about ECA which was new to me :)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com