You are viewing limited content. For full access, please sign in.

Question

Question

Is it possible to use local and external web clients with Windows Authentication?

asked on May 7

I have a LF 11 installation with the main repository and web client server hosted on a local domain-joined server (LF-Main). We use Windows Authentication to let our users browse the repositories without having to provide domain credentials.

We worked with our vendor to tweak the installation to support multiple Web Client servers (also within our local domain network) to let users login with Windows Authentication (LF-web1 and LF-web2); through a combination of a lot of SPI record work to have the remote web app pools run as a domain account.

We found that this setup worked great for the web client users authenticating to the LF-web1 and LF-web2 servers, but it made auto authentication very unreliable for users hitting LF-Main. Most users had a 50/50 chance of being prompted for credentials, and after selecting "Windows Authentication", would have to hit the sign-on button 10-15 times before it finally let them in.

We've reverted to just having users authenticate to the original LF-Main server, and now the external servers won't use Windows Authentication anymore. Is there a scenario where Windows authentication works seamlessly (without involving an LFDS server)?

0 0

Replies

replied on May 7

I think the short answer is that LFDS is meant to eliminate the complexity of getting Kerberos to work in a scenario like yours. It also allows you to return to running your application pools as untrusted local accounts.

0 0
replied on May 12

See, that's a problem in our environment because the LFDS server is in another domain that shares our network. Would I be able to configure one of the web servers to use LFDS auth, or does that setting have to come from the Laserfiche Server/repository configuration? Or am I just trying to have my cake and eat it, too? I'll settle for cake and pie if someone's configured it that way.

laugh

0 0
replied on May 12

That configuration is at the web server level. The configuration/configuration.aspx page is where you enable LFDS authentication and set the url for the STS. The repository and LF server can handle users having different authentication methods. So yes, it sounds like the cake and pie can both exist in your solution.

0 0
replied on May 13

Roger. Next problem to overcome, there are no existing STS sites on the shared LFDS server (shared by a few agencies across our County). I see I can create an STS site on the LFDS server, but since I want to be a good neighbor, is there any chance that creating an STS site for my domain users will cause problems or disruptions for the other agencies/domains with users on the LFDS server?

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.