You are viewing limited content. For full access, please sign in.

Question

Question

Unable to configure Mobile Access

asked on September 12, 2016

Hi,

I am trying to configure mobile access so that users can access LF repositories when they are on the move and can't login to office network. I can configure access on a server within the domain but not on a server which is outside of the domain. I can add repositories and Forms but Directory Server settings are not working (please see the image).

Scenario:

Laserfiche portal server is provisioned in Corporate DMZ. The server operates outside of Active Directory Domain and uses local accunts to provide Laserfiche portal services. The server has an external Domain name and is accessible form internet.

Laserfiche has internal infrastructure integrated with Active Directory sign on credentials. Repositories are published and users can access specific section of repositories based on their active directory group membership.

Specific rules have been configured to allow network traffic from Portal Server (DMZ) to internal LAN. These include specific Laserfiche ports and LDAPS to internal active directory server.

A read only AD account has been created and CA certificates provisioned on DMZ server to support LDAPS between DMZ server and AD server. LDAPS has been tested and is operational.

Laserfiche has currently been configured to allow anonymous access for Forms from internet.

 

Outcomes required:

We would like to authenticate users accessing the <domain name>/mobile URL from the internet.

Mobile users will enter their internal active directory username and password to authenticate and access the internal EDMS repository.

The portal server need to use LDAPS to communicate with internal Active directory server and authenticate users.

Hope this helps clarify our requirements.

0 0

Replies

replied on September 12, 2016

Based on the error, this is a communication issue between the Laserfiche Mobile Server (in DMZ) and the Laserfiche Directory Service (LFDS) (in LAN). The error is a WCF handshake error - most likely the security settings of the WCF endpoints on the LFDS configuration side (web.config) default to Kerberos or NTLM which you don't have configured. An incorrect SPN would also cause this WCF error. So you would have play with the LFDS endpoints security settings for your network. Note - LFMS does not have any endpoints configured on its side, it just uses the ones presented by LFDS.
I would suggest you open a support case as troubleshooting the details of this is not a good fit for the forum.

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.