IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Junction configuration using LDAP authentication

    Posted 02/12/21 12:55 PM
    Hello all,

    I'd like some help to do the configuration bellow.
    I have 1 backend application that already use LDAP authentication, and my isva instance has this federated directory.
    How i set my junction to do SSO on that application?

    Regards,


    ------------------------------
    Alexandre Gammaro
    CyberSecurity Especialist
    Triscal - agammaro@triscal.com.br
    ------------------------------


  • 2.  RE: Junction configuration using LDAP authentication

    Posted 02/12/21 03:02 PM
    Alexandre,
     
    Unfortunately further information is really required before much advice can be offered.  Most specifically, what forms of authentication does the application support?  Ideally it would support some kind of token based authentication (e.g. JWT, LTPA, etc).  WebSEAL offers support for a number of different single-sign-on methods.  There is a full section in the official documentation which talks about these different SSO methods (https://www.ibm.com/support/knowledgecenter/SSPREK_10.0.1/com.ibm.isva.doc/wrp_config/generic/am611_webseal_admin13.htm).  It might be worth taking a look at this.
     
    I hope that this helps.
     
     

    Scott A. Exton
    Senior Software Engineer
    Chief Programmer - IBM Security Verify Access

    IBM Master Inventor


    \
     
     
     





  • 3.  RE: Junction configuration using LDAP authentication

    Posted 02/12/21 05:01 PM
    Hi Scott,

    So... thats my doubt.
    The application is Citrix VDI and the forms authentication is shown bellow.
    This application has a LDAP integration for authentication. I need input domain\user or user@domain and password.
    I tried to do the SSO with quick connect federation, but i guess that is another Citrix system template.

    One question, can i use Kerberos to do the SSO? given that the application use LDAP integration with Active Directory and i authenticate in WebSeal with the AD account.

    Regards,

    ------------------------------
    Alexandre Gammaro
    CyberSecurity Especialist
    Triscal - agammaro@triscal.com.br
    ------------------------------



  • 4.  RE: Junction configuration using LDAP authentication

    Posted 02/12/21 05:14 PM
    Alexandre,

    It still comes down to the types of authentication which is supported by the application.  WebSEAL can be configured to perform forms based authentication, but this can be a little bit tricky to set up and does require the username and password to be stored somewhere (we call this GSO).  WebSEAL can also be configured to perform Kerberos authentication to the junctioned server (this is called Kerberos constrained delegation), but the application would need to support Kerberos authentication.

    Sent from my iPad





  • 5.  RE: Junction configuration using LDAP authentication

    Posted 02/12/21 07:50 PM
    Scott,

    Ok, i see... i'll ask about that to the vendor.
    I appreciate it.

    Regards,

    ------------------------------
    Alexandre Gammaro
    CyberSecurity Especialist
    Triscal - agammaro@triscal.com.br
    ------------------------------



  • 6.  RE: Junction configuration using LDAP authentication

    Posted 02/25/21 09:26 AM
    Edited by Joao Goncalves 02/25/21 09:27 AM
    Do you have the Federation Module or AAC module on your ISAM appliance?

    ------------------------------
    Joao Goncalves
    Pyxis, Lda.
    Sintra
    +351 91 721 4994
    ------------------------------



  • 7.  RE: Junction configuration using LDAP authentication

    Posted 02/25/21 02:16 PM
    Hi João,

    Yeah... i have both modules.

    Regards,

    ------------------------------
    Alexandre Gammaro
    CyberSecurity Especialist
    Triscal - agammaro@triscal.com.br
    ------------------------------