F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

Nath's avatar
Nath
Icon for Cirrostratus rankCirrostratus
Mar 10, 2016

Setting up CAS server with certificate based authentication

Hi All,

 

Does anyone tried to use this or tried to done this kind of setup.

 

When I use the client and server ssl profile it always fail, but when I removed both client and server ssl profile my testing works.

 

As per client. The certificate on the client side includes UPN User private name I'm not sure. Then the certificate needed to verified by their AD and the UPN is the reference of the AD. Once it is verified any server mail that will access by the client should be SSO due to its already verified by the client.

 

Thank you all.

 

11 Replies

  • Hello,

     

    This is a common scenario where you configure client cert authentication on the F5 VIP protecting the pool of CAS servers.

     

    The client cert auth is feasible using LTM only by correctly setting up a client ssl profile.

     

    But the Web SSO feature require APM module. If you ask only client certificate, so you must configure Kerberos Delegation on the BIG-IP and activate Kerberos authentication on the CAS servers.

     

    I suggest you to add the UPN or the e-mail address of the user within the certificate so that by doing an AD query, you can retrieve all required attributes.

     

    • Nath's avatar
      Nath
      Icon for Cirrostratus rankCirrostratus
      Thanks I'm glad someone understand me. The UPN was included on the certificate that AD needed to vertfy. My problem is the clientSSL profile. I'm not really familiar the certificates and keys.
    • Nath's avatar
      Nath
      Icon for Cirrostratus rankCirrostratus
      Yann Hi, May I know if can do this using LTM only? As you said I just need to configure client SSL correctly.
    • Yann_Desmarest_'s avatar
      Yann_Desmarest_
      Icon for Nacreous rankNacreous
      Hello, The kerberos delegation require APM to works. The SSL part can be achieved by LTM only
  • Hello,

     

    This is a common scenario where you configure client cert authentication on the F5 VIP protecting the pool of CAS servers.

     

    The client cert auth is feasible using LTM only by correctly setting up a client ssl profile.

     

    But the Web SSO feature require APM module. If you ask only client certificate, so you must configure Kerberos Delegation on the BIG-IP and activate Kerberos authentication on the CAS servers.

     

    I suggest you to add the UPN or the e-mail address of the user within the certificate so that by doing an AD query, you can retrieve all required attributes.

     

    • Nath's avatar
      Nath
      Icon for Cirrostratus rankCirrostratus
      Thanks I'm glad someone understand me. The UPN was included on the certificate that AD needed to vertfy. My problem is the clientSSL profile. I'm not really familiar the certificates and keys.
    • Nath's avatar
      Nath
      Icon for Cirrostratus rankCirrostratus
      Yann Hi, May I know if can do this using LTM only? As you said I just need to configure client SSL correctly.
    • Yann_Desmarest's avatar
      Yann_Desmarest
      Icon for Cirrus rankCirrus
      Hello, The kerberos delegation require APM to works. The SSL part can be achieved by LTM only