Forum Discussion

skywalker76_332's avatar
skywalker76_332
Icon for Nimbostratus rankNimbostratus
Sep 06, 2017

KCD for external websites via F5 APM

Hello,

 

We are in the process of setting up VMWare Airwatch for our mobility platform. However, we are running into issues trying to get browsing (via per-app-vpn) to work for our external Salesforce site that requires an authentication via Kerberos on our internal ADFS.

 

I found this document that was jointly created by VMWare and yourselves: https://www.vmware.com/pdf/vidm_implementing_SSO_to_kdc-and-hb_apps.pdf

 

However, it doesn't respond to our needs...to summarize quickly, here are the steps for accessing a legacy Kerberos application:

 

  1. We declare the Salesforce link on VIDM
  2. User clicks on link via Workspace One on mobile device
  3. SAML assertion is sent to the F5 APM
  4. APM transforms it into KCD
  5. APM will send this to the device
  6. End user is logged into the application

The problem here is that the Salesforce site does a redirect to our internal ADFS server and then sends the auth request to the device which it won't know how to deal with... If the auth request was dealt with on the Salesforce end, then we wouldn't have the issue...

 

I'd appreciate any experts chiming in here who could clarify this for us and maybe suggest an alternative browsing solution for us via the F5 APM without VIDM/WorkspaceOne, maybe using a simple on-demand VPN?

 

Thanks

 

No RepliesBe the first to reply