cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

Identity awareness & Kerberos transparent auth ?

hello,

I need your help ^^

I just implemented Identity awareness. The client does not want to use AD query and would like to have transparent authentication.

I decided to set up the id awareness based on Kerberos authentication using the identity agent. The problem is that when I connect to the client machine with my domain name, the identity awareness asks me to retype my domain user and password to recognize me. Could you please tell me how to make this transparent? how can the identity agent recover my identity without retyping my user and password (i.e: by using the authentication data used during my first connection to my PC)?

Tags (1)
0 Kudos
11 Replies

Re: Identity awareness & Kerberos transparent auth ?

Have you looked into Identity Collector option?

Identity Collector - Technical Overview 

We have have it before it was called IDC and are very satisfied. As it says on the tin:

Identity Collector key benefits over standard AD Query

  • Reduces the load on the Security Gateway - the agent is doing the queries instead of the Security Gateway.
  • Reduces the load on the DCs - the native Windows API used consumes less resources.
  • The Identity Collector requires no administrator or administrator-like permissions. Only permission required is read-only access to the domain security logs.
  • One Identity Collector can serve multiple Security Gateways, even from different CMA.

Plus nothing to install on the client.

We are 25000+ users organization and AD query was not built for that scale. plus we wanted to avoid any installs on the client.

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

Do you use a dedicated machine for that? since the collector require java env maybe some customer could argue with that choice

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

did you set the corresponding SPN?

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

 yes I added the corresponding SPN on the AD (It is working when I enter manually my AD login and password on the Identity agent)

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

Hello,

Kaspars Zibarts‌: unfortunately we can not install anything on AD it's forbidden.

@Christian Stueckrath: yes I added the corresponding SPN on the AD (It is working when I enter manually my AD login and password on the Identity agent)

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

You don't need to install anything on actual domain controller. You add a new Windows machine that runs IDC. And it acts as a "proxy" between GW and AD. Reducing load on both. So yes - you will need at least one (or more depending on your network) windows machine (VM or physical) to install IDC.

By doing that we saw incredible reduction of CPU usage on gateway and also no more issues with actual domain controller as AD queries caused lots of headaches as it used WMI.

Re: Identity awareness & Kerberos transparent auth ?

Yes, I agree with you I will present this solution to the client but the Identity Agent solution has been validated in CAB and it will be very difficult for the client to rollback :S

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

Just part of our daily lives Smiley Happy took as nearly 2 years to get IA running as expected 

Re: Identity awareness & Kerberos transparent auth ?

Hello,

It was an SPN issue, it is working now, thank you all for your feedback.

Regards.

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

What was the SPN issue? Maybe I'm running into the same problem.

0 Kudos

Re: Identity awareness & Kerberos transparent auth ?

Hello,

To check if there is any SPN issue, make a flow capture with wireshark in your Kerberos server (Active directory) and  filter kerberos flows and you will see the error.

Regards.

0 Kudos