You are viewing limited content. For full access, please sign in.

Question

Question

Pass-Through Authentication with Web Client Using LFDS SSO?

asked on February 19, 2018

When setting up SSO with LFDS, is it also possible to have it use pass-through authentication? I have not found anything specifically addressing this. I have found you can use Windows Authentication, but nothing specific to pass-through authentication. If so, I am guessing that Kerberos would still need to be configured?

1 0

Answer

SELECTED ANSWER
replied on February 20, 2018

LFDS single sign-on does not currently do pass-through authentication. The user still has to click on "Use Windows Authentication" on the LFDS login screen.

0 0

Replies

replied on February 19, 2018 Show version history

What the client is wanting is so when an end user is given a link to a document to access through the web client, it does not present them with a screen to enter credentials in or to have to click on a link to use Windows Authentication. They want it to automatically sign them in according to who they are signed into Windows as and take them directly to the document using the link.

The question comes up because I have only seen LFDS SSO present an intermediate screen where a user can enter their credentials or select to use Windows Authentication. I have never seen it pass-through the users Windows credentials and auto-login without first presenting a screen for the end user to choose from.

1 0
replied on February 19, 2018

@████████, are you able to verify if this is possible for me?

 

1 0
replied on February 19, 2018

No, I'm not aware of all of the LFDS configuration options.

0 0
SELECTED ANSWER
replied on February 20, 2018

LFDS single sign-on does not currently do pass-through authentication. The user still has to click on "Use Windows Authentication" on the LFDS login screen.

0 0
replied on February 19, 2018

One of the main advantages to using LFDS is that you no longer need to configure Kerberos.  Kerberos is required when one application (the browser) sends its Windows identity to another application (e.g. Web Access) and that application wants to delegate that identity to a third application (LFS).  With LFDS, the Windows identity is used only to authenticate to LFDS, which then uses SAML to represent the user's identity to the other web applications.

Can you be more specific about your pass-through authentication question?  That term has multiple meanings depending on the context (one, two), and I don't know which one you mean here.

0 0
replied on February 19, 2018

By default now, most browsers no longer automatically log in using windows authentication and must be configured to do so.  There are different ways to configure different browsers, so do a web search for how to configure your preferred browser.

0 0
replied on February 19, 2018 Show version history

Correct, but LFDS be configured to allow that like the Web Client configuration can?

1 0
replied on March 8, 2022 Show version history

Anyone get this working? I would also like to enable pass-through authentication for Laserfiche Forms and Laserfiche Web.

 

Update:

I just got this working, see this post: https://answers.laserfiche.com/questions/52155/Forms-LDAP-and-Pass-Through-Authentication

 

I added NTLM authentication to the list of providers in IIS under authentication - Windows Authentication.  I had to do this on both the Forms and Laserfiche virtual directories under Default Web Site.

 

After that is setup you still need to configure your browser to pass-through authentication. For IE/Edge this is done through the Internet Option Control panel. Add the domain of your laserfiche servers to the "Local intranet" sites list. You can either do this manually or through group policy.

 

You can do the same for Google Chrome and Firefox. Chrome calls it "AuthServerWhitelist" and Firefox calls it "spnego" authentication. Google those terms and you'll find instructions on how to change the settings for those browsers. I did it via the Firefox and Google Chrome group policy options.

 

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.