Forum Discussion
Test SSO with APM
Hi,
i want to test sso feature in bigip APM. is there any easy application setup for SSO? which can be tested for SSO with APM?
- Harry1Nimbostratus
i have configured a IIS server with windows authentication option. can i configure SSO here ? at present it is asking password once i click on published link under webtop link. i have configured kerberos sso but still web page is asking credential after entering with successful AD login in APM policy page..
anyone can help me out ?
- AndOsCirrostratus
Kerberos SSO can be a bit fiddly to get working.
Something that helped me out last time I worked with Kerberos SSO was chapter Kerberos Authentication with End-User Logons from the APM Authentication and SSO guide.
Verify that SPNs are configured correctly for your web servers. This Microsoft KB might have a few tips, How to use SPNs when you configure Web applications that are hosted on Internet Information Services
/Andreas
- Harry1Nimbostratus
i tried but still its asking credentials.
- kolom_265617Cirrostratus
You can use Auction Site , which is being used as a testing server for ASM Labs. Doing so you can test form based SSO.You can also setup a Lab exchange server to test NTLM + Kerberos SSO.
- Harry1Nimbostratus
Exchange setup is very lengthy procedure that is why i chose IIS server.
- kolomAltostratus
You can use Auction Site , which is being used as a testing server for ASM Labs. Doing so you can test form based SSO.You can also setup a Lab exchange server to test NTLM + Kerberos SSO.
- Harry1Nimbostratus
Exchange setup is very lengthy procedure that is why i chose IIS server.
- Nicolas_DestorCirrostratus
Check the 401 HTTP request message send by your IIS server, what is the value for WWW-authenticate attribute? Should be "Negociate" for Kerberos. For basic's authenticiation the value is "Basic", seems to be the case here for you.
If ok i advise you to activate debug mode for APM, and check if SSO profile is well invoke when you access your website in /var/log/apm.
- Harry1Nimbostratus
i tried to activate debug logs but not getting kerberos related logs here.
- Stanislas_Piro2Cumulonimbus
- Nicolas_DestorCirrostratus
You SSO profile seems not invoked in that case. Never tried Keberos sso, but for other sso method i always saw logs. For example for HTTP-form sso:
Jan 3 15:59:21 FW-xxx debug websso.1[15127]: 014d0001:7: constructor Jan 3 15:59:21 FW-xxx debug websso.1[15127]: 014d0001:7: webssoContext constructor ... Jan 3 15:59:21 FW-xxx debug websso.1[15127]: 014d0001:7: ssoMethod: form-based usernameSource:
Check your Access profile configuration, make sure your sso profile is well applied.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com