ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Web app authenticate against customer AD?

    IT Discussion
    5
    15
    468
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • momurdaM
      momurda
      last edited by

      @pete-s said in Web app authenticate against customer AD?:

      But is it likely that an enterprise would expose ldap to the internet? Or is there something else inbetween?

      You can do this, using ldaps and some certificates.

      But likely you want to use SSO which is done over http/https. Many sites support SSO using SAML2.0 compliant implementations, like ADFS.
      For example the MS CRM system has you setup an ADFS by default, you dont have to but is recommended, and i think required if you want remote users to use it without vpn.
      This consists of the CRM, ADFS servers to provide access to people outside lan.
      CRM homepage exposed to internet on 443, ADFS server on 443 exposed as well.

      Someone on outside network, they sign into CRM homepage with AD creds. The login request gets sent to public IP of your ADFS server over https, which then connects to you AD server on the LAN, it does its checks and responds with yay or nay to CRM.

      1 1 Reply Last reply Reply Quote 2
      • 1
        1337 @momurda
        last edited by

        @momurda said in Web app authenticate against customer AD?:

        @pete-s said in Web app authenticate against customer AD?:

        But is it likely that an enterprise would expose ldap to the internet? Or is there something else inbetween?

        You can do this, using ldaps and some certificates.

        But likely you want to use SSO which is done over http/https. Many sites support SSO using SAML2.0 compliant implementations, like ADFS.
        For example the MS CRM system has you setup an ADFS by default, you dont have to but is recommended, and i think required if you want remote users to use it without vpn.
        This consists of the CRM, ADFS servers to provide access to people outside lan.
        CRM homepage exposed to internet on 443, ADFS server on 443 exposed as well.

        Someone on outside network, they sign into CRM homepage with AD creds. The login request gets sent to public IP of your ADFS server over https, which then connects to you AD server on the LAN, it does its checks and responds with yay or nay to CRM.

        Thanks, I'll look more into this.

        1 Reply Last reply Reply Quote 0
        • dbeatoD
          dbeato @1337
          last edited by

          @pete-s said in Web app authenticate against customer AD?:

          that an enterprise would expose ldap to the inter

          Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

          travisdh1T 1 Reply Last reply Reply Quote 1
          • travisdh1T
            travisdh1 @dbeato
            last edited by

            @dbeato said in Web app authenticate against customer AD?:

            @pete-s said in Web app authenticate against customer AD?:

            that an enterprise would expose ldap to the inter

            Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

            LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

            dbeatoD 1 Reply Last reply Reply Quote 0
            • dbeatoD
              dbeato @travisdh1
              last edited by

              @travisdh1 said in Web app authenticate against customer AD?:

              @dbeato said in Web app authenticate against customer AD?:

              @pete-s said in Web app authenticate against customer AD?:

              that an enterprise would expose ldap to the inter

              Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

              LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

              What do you mean LDAP secured? you mean LDAPS?

              travisdh1T 1 Reply Last reply Reply Quote 0
              • travisdh1T
                travisdh1 @dbeato
                last edited by

                @dbeato said in Web app authenticate against customer AD?:

                @travisdh1 said in Web app authenticate against customer AD?:

                @dbeato said in Web app authenticate against customer AD?:

                @pete-s said in Web app authenticate against customer AD?:

                that an enterprise would expose ldap to the inter

                Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                What do you mean LDAP secured? you mean LDAPS?

                Yes.

                dbeatoD 1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato @travisdh1
                  last edited by

                  @travisdh1 said in Web app authenticate against customer AD?:

                  @dbeato said in Web app authenticate against customer AD?:

                  @travisdh1 said in Web app authenticate against customer AD?:

                  @dbeato said in Web app authenticate against customer AD?:

                  @pete-s said in Web app authenticate against customer AD?:

                  that an enterprise would expose ldap to the inter

                  Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                  LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                  What do you mean LDAP secured? you mean LDAPS?

                  Yes.

                  LDAPS still not the default as far as I know in AD .

                  travisdh1T 1 Reply Last reply Reply Quote 0
                  • travisdh1T
                    travisdh1 @dbeato
                    last edited by

                    @dbeato said in Web app authenticate against customer AD?:

                    @travisdh1 said in Web app authenticate against customer AD?:

                    @dbeato said in Web app authenticate against customer AD?:

                    @travisdh1 said in Web app authenticate against customer AD?:

                    @dbeato said in Web app authenticate against customer AD?:

                    @pete-s said in Web app authenticate against customer AD?:

                    that an enterprise would expose ldap to the inter

                    Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                    LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                    What do you mean LDAP secured? you mean LDAPS?

                    Yes.

                    LDAPS still not the default as far as I know in AD .

                    Really? That's just bad. I thought they had Kerberos by default.

                    dbeatoD 1 Reply Last reply Reply Quote 0
                    • dbeatoD
                      dbeato @travisdh1
                      last edited by

                      @travisdh1 said in Web app authenticate against customer AD?:

                      @dbeato said in Web app authenticate against customer AD?:

                      @travisdh1 said in Web app authenticate against customer AD?:

                      @dbeato said in Web app authenticate against customer AD?:

                      @travisdh1 said in Web app authenticate against customer AD?:

                      @dbeato said in Web app authenticate against customer AD?:

                      @pete-s said in Web app authenticate against customer AD?:

                      that an enterprise would expose ldap to the inter

                      Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                      LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                      What do you mean LDAP secured? you mean LDAPS?

                      Yes.

                      LDAPS still not the default as far as I know in AD .

                      Really? That's just bad. I thought they had Kerberos by default.

                      https://support.microsoft.com/en-us/help/321051/how-to-enable-ldap-over-ssl-with-a-third-party-certification-authority

                      travisdh1T 1 Reply Last reply Reply Quote 0
                      • travisdh1T
                        travisdh1 @dbeato
                        last edited by

                        @dbeato said in Web app authenticate against customer AD?:

                        @travisdh1 said in Web app authenticate against customer AD?:

                        @dbeato said in Web app authenticate against customer AD?:

                        @travisdh1 said in Web app authenticate against customer AD?:

                        @dbeato said in Web app authenticate against customer AD?:

                        @travisdh1 said in Web app authenticate against customer AD?:

                        @dbeato said in Web app authenticate against customer AD?:

                        @pete-s said in Web app authenticate against customer AD?:

                        that an enterprise would expose ldap to the inter

                        Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                        LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                        What do you mean LDAP secured? you mean LDAPS?

                        Yes.

                        LDAPS still not the default as far as I know in AD .

                        Really? That's just bad. I thought they had Kerberos by default.

                        https://support.microsoft.com/en-us/help/321051/how-to-enable-ldap-over-ssl-with-a-third-party-certification-authority

                        Wow, just, wow. Haven't they figured this out by now?
                        0_1533942863184_93df6151-c505-4067-a50a-06974023c370-image.png

                        dbeatoD 1 Reply Last reply Reply Quote 0
                        • dbeatoD
                          dbeato @travisdh1
                          last edited by

                          @travisdh1 said in Web app authenticate against customer AD?:

                          @dbeato said in Web app authenticate against customer AD?:

                          @travisdh1 said in Web app authenticate against customer AD?:

                          @dbeato said in Web app authenticate against customer AD?:

                          @travisdh1 said in Web app authenticate against customer AD?:

                          @dbeato said in Web app authenticate against customer AD?:

                          @travisdh1 said in Web app authenticate against customer AD?:

                          @dbeato said in Web app authenticate against customer AD?:

                          @pete-s said in Web app authenticate against customer AD?:

                          that an enterprise would expose ldap to the inter

                          Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                          LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                          What do you mean LDAP secured? you mean LDAPS?

                          Yes.

                          LDAPS still not the default as far as I know in AD .

                          Really? That's just bad. I thought they had Kerberos by default.

                          https://support.microsoft.com/en-us/help/321051/how-to-enable-ldap-over-ssl-with-a-third-party-certification-authority

                          Wow, just, wow. Haven't they figured this out by now?
                          0_1533942863184_93df6151-c505-4067-a50a-06974023c370-image.png

                          It would be nice if it was on by default.

                          1 Reply Last reply Reply Quote 0
                          • 1 / 1
                          • First post
                            Last post