You hit the nail on the head when you said “…clients that enter through a proxy port on the Integration server (setup up in reverse invoke mode) are authenticated by the internal server.”
Users (clients) must be defined on the internal server, and need not be defined on the RI server. Any local user definitions, LDAP users, or pluggable authentication modules are ignored on the Reverse Inovke server (for the port(s) that are configured as reverse invoke ports).
I’m don’t understand what you mean by “Clients that we have defined in the LDAP receive a ‘Invalid credentials’ message going through the proxy port, even though they can sign in when they connect directly to the internal server.” Where is this LDAP connected? Is it connected to the Reverse Invoke server or the internal server?
Is it possible that you have the port on the Reverse Invoke server configured to “require certificates”? Or if it’s an SSL port but not requiring certificates, perhaps the server’s certificate isn’t signed by a CA recognized by the client? What happens when you use a browser to connect to the RI port? Do you get a certificate error?
Just some ideas… not clear enough what the problem is to know for sure what the solution will be!
#webMethods#webMethods-General#Integration-Server-and-ESB