Forum Discussion
Seamless athentication to Webtop
Not sure when SAML was introduced to the conversation, but that shouldn't matter. You can very simply create a client side Kerberos AAA authentication (401 and Kerberos Auth) at the beginning of the access policy evaluation).
- The user contacts the APM VIP.
- The APM VIP responds with a 401 Unauthorized message and WWW-Authenticate Negotiate header.
- The domain-joined user contacts its local DC/KDC to get a ticket for this service, and then returns to the VIP with a Kerberos ticket.
- The Kerberos Auth agent validates the Kerberos ticket and allows access.
- The access policy assigns the webtop and additional resources to the user.
You can do more or less the same thing with NTLM on the client side, but again it's a little more involved. Once the user is authenticated and has a webtop, there's also a session variable stored in the access policy, session.logon.last.logonname, that contains the user's AD UPN (ie. bill.user@mydomain.com). You can use this to do server side authentication, IdP-initiates SAML, etc.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com