Forum Discussion
Yann_Desmarest_
May 06, 2016Nacreous
Hello,
You are right, when choosing Kerberos, client certificate or ntlm authentication, you retrict your capabilities on the authentication mecanism supported on the backend for SSO.
When using authentication mecanism not prompting for password, you can only use kerberos delegation, saml or header based SSO.
- tminfw2May 06, 2016NimbostratusIn this case, server side SSO is ntlmv2. If I understand well, does this mean that I am limited to also using ntlm on the client side?
- Yann_Desmarest_May 06, 2016NacreousIf sso is ntlmv2, you have the options to use basic or forms based client auth because we need the password. Ntlmv2 client auth with ntlmv2 sso doesn't make sense and asaik is not supported through apm.
- tminfw2May 06, 2016NimbostratusJust checked the ntlmv2 SSO config and indeed you need a password source for the SSO profile. I will take this up with my team next week.