Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Oussama_Kadim1
Contributor

Identity awareness & Kerberos transparent auth ?

hello,

I need your help ^^

I just implemented Identity awareness. The client does not want to use AD query and would like to have transparent authentication.

I decided to set up the id awareness based on Kerberos authentication using the identity agent. The problem is that when I connect to the client machine with my domain name, the identity awareness asks me to retype my domain user and password to recognize me. Could you please tell me how to make this transparent? how can the identity agent recover my identity without retyping my user and password (i.e: by using the authentication data used during my first connection to my PC)?

0 Kudos
11 Replies
Kaspars_Zibarts
Employee Employee
Employee

Have you looked into Identity Collector option?

Identity Collector - Technical Overview 

We have have it before it was called IDC and are very satisfied. As it says on the tin:

Identity Collector key benefits over standard AD Query

  • Reduces the load on the Security Gateway - the agent is doing the queries instead of the Security Gateway.
  • Reduces the load on the DCs - the native Windows API used consumes less resources.
  • The Identity Collector requires no administrator or administrator-like permissions. Only permission required is read-only access to the domain security logs.
  • One Identity Collector can serve multiple Security Gateways, even from different CMA.

Plus nothing to install on the client.

We are 25000+ users organization and AD query was not built for that scale. plus we wanted to avoid any installs on the client.

0 Kudos
Marco_Valenti
Advisor

Do you use a dedicated machine for that? since the collector require java env maybe some customer could argue with that choice

0 Kudos
cstueckrath
Collaborator

did you set the corresponding SPN?

0 Kudos
Oussama_Kadim1
Contributor

 yes I added the corresponding SPN on the AD (It is working when I enter manually my AD login and password on the Identity agent)

0 Kudos
Oussama_Kadim1
Contributor

Hello,

Kaspars Zibarts‌: unfortunately we can not install anything on AD it's forbidden.

@Christian Stueckrath: yes I added the corresponding SPN on the AD (It is working when I enter manually my AD login and password on the Identity agent)

0 Kudos
Kaspars_Zibarts
Employee Employee
Employee

You don't need to install anything on actual domain controller. You add a new Windows machine that runs IDC. And it acts as a "proxy" between GW and AD. Reducing load on both. So yes - you will need at least one (or more depending on your network) windows machine (VM or physical) to install IDC.

By doing that we saw incredible reduction of CPU usage on gateway and also no more issues with actual domain controller as AD queries caused lots of headaches as it used WMI.

Oussama_Kadim1
Contributor

Yes, I agree with you I will present this solution to the client but the Identity Agent solution has been validated in CAB and it will be very difficult for the client to rollback :S

0 Kudos
Kaspars_Zibarts
Employee Employee
Employee

Just part of our daily lives Smiley Happy took as nearly 2 years to get IA running as expected 

Oussama_Kadim1
Contributor

Hello,

It was an SPN issue, it is working now, thank you all for your feedback.

Regards.

0 Kudos
Piet_vd_Maas_2
Participant

What was the SPN issue? Maybe I'm running into the same problem.

0 Kudos
Oussama_Kadim1
Contributor

Hello,

To check if there is any SPN issue, make a flow capture with wireshark in your Kerberos server (Active directory) and  filter kerberos flows and you will see the error.

Regards.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events