ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SSO via LDAP

    Scheduled Pinned Locked Moved IT Discussion
    11 Posts 6 Posters 571 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • brandon220B
      brandon220
      last edited by

      I have a friend who wants to expose their AD/LDAP to the internet (behind a FW) to allow single sign-on. Looking for some opinions on this. It will be to authenticate the users on an external website. Thoughts?

      JaredBuschJ ObsolesceO 2 Replies Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch @brandon220
        last edited by

        @brandon220 said in SSO via LDAP:

        I have a friend who wants to expose their AD/LDAP to the internet (behind a FW) to allow single sign-on. Looking for some opinions on this. It will be to authenticate the users on an external website. Thoughts?

        Exposing with firewall restrictions is just fine. I mean you either trust the site or you don't.

        1 Reply Last reply Reply Quote 1
        • coliverC
          coliver
          last edited by coliver

          Are they a Microsoft shop? If they are ADFS is fairly easy to setup.

          But the additional overhead may not be worth it for a single site. It can also be a bit fragile if you don't have the expertise (or time) to work on it.

          1 Reply Last reply Reply Quote 0
          • coliverC
            coliver
            last edited by

            Shibboleth and WSO2 are both viable options as well if you're looking at something open source.

            1 Reply Last reply Reply Quote 1
            • brandon220B
              brandon220
              last edited by

              They do trust the site and were given a list of IPs to allow traffic thru the FW. It is Microsoft AD.

              1 Reply Last reply Reply Quote 0
              • ObsolesceO
                Obsolesce @brandon220
                last edited by Obsolesce

                @brandon220 said in SSO via LDAP:

                I have a friend who wants to expose their AD/LDAP to the internet (behind a FW) to allow single sign-on. Looking for some opinions on this. It will be to authenticate the users on an external website. Thoughts?

                Typically SSO is done via a federation server (ADFS), or by leverageing Azure AD for authentication.

                What app or service are they wanting to use LDAP authentication for?

                1 Reply Last reply Reply Quote 0
                • brandon220B
                  brandon220
                  last edited by

                  I do not have the specifics yet. Just had a call last night asking about if is possible to do so.

                  1 Reply Last reply Reply Quote 0
                  • wrx7mW
                    wrx7m
                    last edited by

                    I am looking at doing this with another SSO provider; Okta is on the shortlist.

                    black3dynamiteB 1 Reply Last reply Reply Quote 0
                    • black3dynamiteB
                      black3dynamite @wrx7m
                      last edited by

                      @wrx7m said in SSO via LDAP:

                      I am looking at doing this with another SSO provider; Okta is on the shortlist.

                      We've been using Okta and its been great.

                      wrx7mW 1 Reply Last reply Reply Quote 1
                      • wrx7mW
                        wrx7m @black3dynamite
                        last edited by

                        @black3dynamite said in SSO via LDAP:

                        @wrx7m said in SSO via LDAP:

                        I am looking at doing this with another SSO provider; Okta is on the shortlist.

                        We've been using Okta and its been great.

                        Thanks for the mini review :grinning_face:

                        black3dynamiteB 1 Reply Last reply Reply Quote 0
                        • black3dynamiteB
                          black3dynamite @wrx7m
                          last edited by

                          @wrx7m said in SSO via LDAP:

                          @black3dynamite said in SSO via LDAP:

                          @wrx7m said in SSO via LDAP:

                          I am looking at doing this with another SSO provider; Okta is on the shortlist.

                          We've been using Okta and its been great.

                          Thanks for the mini review :grinning_face:

                          0_1530039980961_what can i say except you're welcome.gif

                          1 Reply Last reply Reply Quote 2
                          • 1 / 1
                          • First post
                            Last post