ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Web app authenticate against customer AD?

    IT Discussion
    5
    15
    468
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • 1
      1337 @momurda
      last edited by

      @momurda said in Web app authenticate against customer AD?:

      @pete-s said in Web app authenticate against customer AD?:

      But is it likely that an enterprise would expose ldap to the internet? Or is there something else inbetween?

      You can do this, using ldaps and some certificates.

      But likely you want to use SSO which is done over http/https. Many sites support SSO using SAML2.0 compliant implementations, like ADFS.
      For example the MS CRM system has you setup an ADFS by default, you dont have to but is recommended, and i think required if you want remote users to use it without vpn.
      This consists of the CRM, ADFS servers to provide access to people outside lan.
      CRM homepage exposed to internet on 443, ADFS server on 443 exposed as well.

      Someone on outside network, they sign into CRM homepage with AD creds. The login request gets sent to public IP of your ADFS server over https, which then connects to you AD server on the LAN, it does its checks and responds with yay or nay to CRM.

      Thanks, I'll look more into this.

      1 Reply Last reply Reply Quote 0
      • dbeatoD
        dbeato @1337
        last edited by

        @pete-s said in Web app authenticate against customer AD?:

        that an enterprise would expose ldap to the inter

        Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

        travisdh1T 1 Reply Last reply Reply Quote 1
        • travisdh1T
          travisdh1 @dbeato
          last edited by

          @dbeato said in Web app authenticate against customer AD?:

          @pete-s said in Web app authenticate against customer AD?:

          that an enterprise would expose ldap to the inter

          Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

          LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

          dbeatoD 1 Reply Last reply Reply Quote 0
          • dbeatoD
            dbeato @travisdh1
            last edited by

            @travisdh1 said in Web app authenticate against customer AD?:

            @dbeato said in Web app authenticate against customer AD?:

            @pete-s said in Web app authenticate against customer AD?:

            that an enterprise would expose ldap to the inter

            Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

            LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

            What do you mean LDAP secured? you mean LDAPS?

            travisdh1T 1 Reply Last reply Reply Quote 0
            • travisdh1T
              travisdh1 @dbeato
              last edited by

              @dbeato said in Web app authenticate against customer AD?:

              @travisdh1 said in Web app authenticate against customer AD?:

              @dbeato said in Web app authenticate against customer AD?:

              @pete-s said in Web app authenticate against customer AD?:

              that an enterprise would expose ldap to the inter

              Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

              LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

              What do you mean LDAP secured? you mean LDAPS?

              Yes.

              dbeatoD 1 Reply Last reply Reply Quote 0
              • dbeatoD
                dbeato @travisdh1
                last edited by

                @travisdh1 said in Web app authenticate against customer AD?:

                @dbeato said in Web app authenticate against customer AD?:

                @travisdh1 said in Web app authenticate against customer AD?:

                @dbeato said in Web app authenticate against customer AD?:

                @pete-s said in Web app authenticate against customer AD?:

                that an enterprise would expose ldap to the inter

                Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                What do you mean LDAP secured? you mean LDAPS?

                Yes.

                LDAPS still not the default as far as I know in AD .

                travisdh1T 1 Reply Last reply Reply Quote 0
                • travisdh1T
                  travisdh1 @dbeato
                  last edited by

                  @dbeato said in Web app authenticate against customer AD?:

                  @travisdh1 said in Web app authenticate against customer AD?:

                  @dbeato said in Web app authenticate against customer AD?:

                  @travisdh1 said in Web app authenticate against customer AD?:

                  @dbeato said in Web app authenticate against customer AD?:

                  @pete-s said in Web app authenticate against customer AD?:

                  that an enterprise would expose ldap to the inter

                  Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                  LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                  What do you mean LDAP secured? you mean LDAPS?

                  Yes.

                  LDAPS still not the default as far as I know in AD .

                  Really? That's just bad. I thought they had Kerberos by default.

                  dbeatoD 1 Reply Last reply Reply Quote 0
                  • dbeatoD
                    dbeato @travisdh1
                    last edited by

                    @travisdh1 said in Web app authenticate against customer AD?:

                    @dbeato said in Web app authenticate against customer AD?:

                    @travisdh1 said in Web app authenticate against customer AD?:

                    @dbeato said in Web app authenticate against customer AD?:

                    @travisdh1 said in Web app authenticate against customer AD?:

                    @dbeato said in Web app authenticate against customer AD?:

                    @pete-s said in Web app authenticate against customer AD?:

                    that an enterprise would expose ldap to the inter

                    Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                    LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                    What do you mean LDAP secured? you mean LDAPS?

                    Yes.

                    LDAPS still not the default as far as I know in AD .

                    Really? That's just bad. I thought they had Kerberos by default.

                    https://support.microsoft.com/en-us/help/321051/how-to-enable-ldap-over-ssl-with-a-third-party-certification-authority

                    travisdh1T 1 Reply Last reply Reply Quote 0
                    • travisdh1T
                      travisdh1 @dbeato
                      last edited by

                      @dbeato said in Web app authenticate against customer AD?:

                      @travisdh1 said in Web app authenticate against customer AD?:

                      @dbeato said in Web app authenticate against customer AD?:

                      @travisdh1 said in Web app authenticate against customer AD?:

                      @dbeato said in Web app authenticate against customer AD?:

                      @travisdh1 said in Web app authenticate against customer AD?:

                      @dbeato said in Web app authenticate against customer AD?:

                      @pete-s said in Web app authenticate against customer AD?:

                      that an enterprise would expose ldap to the inter

                      Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                      LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                      What do you mean LDAP secured? you mean LDAPS?

                      Yes.

                      LDAPS still not the default as far as I know in AD .

                      Really? That's just bad. I thought they had Kerberos by default.

                      https://support.microsoft.com/en-us/help/321051/how-to-enable-ldap-over-ssl-with-a-third-party-certification-authority

                      Wow, just, wow. Haven't they figured this out by now?
                      0_1533942863184_93df6151-c505-4067-a50a-06974023c370-image.png

                      dbeatoD 1 Reply Last reply Reply Quote 0
                      • dbeatoD
                        dbeato @travisdh1
                        last edited by

                        @travisdh1 said in Web app authenticate against customer AD?:

                        @dbeato said in Web app authenticate against customer AD?:

                        @travisdh1 said in Web app authenticate against customer AD?:

                        @dbeato said in Web app authenticate against customer AD?:

                        @travisdh1 said in Web app authenticate against customer AD?:

                        @dbeato said in Web app authenticate against customer AD?:

                        @travisdh1 said in Web app authenticate against customer AD?:

                        @dbeato said in Web app authenticate against customer AD?:

                        @pete-s said in Web app authenticate against customer AD?:

                        that an enterprise would expose ldap to the inter

                        Very unlikely, there must be a VPN or a LDAP open externally only allowed from certain IP addresses from said Cloud vendor.

                        LDAP can be secured the same way HTTP traffic can be. In fact, it's the default in Active Directory.

                        What do you mean LDAP secured? you mean LDAPS?

                        Yes.

                        LDAPS still not the default as far as I know in AD .

                        Really? That's just bad. I thought they had Kerberos by default.

                        https://support.microsoft.com/en-us/help/321051/how-to-enable-ldap-over-ssl-with-a-third-party-certification-authority

                        Wow, just, wow. Haven't they figured this out by now?
                        0_1533942863184_93df6151-c505-4067-a50a-06974023c370-image.png

                        It would be nice if it was on by default.

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post