Page 182
Manual
ResistTel IP2 / IP152
ExResistTel IP2 / IP154
Figure 192: Cross Realm Authentication
1.
The browser sends user name and password of a Windows domain user to the
box, using HTTPS basic authentication.
2.
The box authenticates with the user credentials against the Windows Kerberos
server and gets back a ticket-granting ticket.
3.
The box uses the ticket-granting ticket to get a ticket for the own Kerberos
server.
4.
The box uses the cross-realm ticket to obtain a ticket on behalf of the user
from the own Kerberos server for its own web server.
If that was successful the password is valid and the user is authenticated.
4.3.2.1.2.4
HTTPS for Encryption
The box needs username and password in the clear to delegate authentication. Basic
authentication is used to send that information from the web browser to the box.
This message exchange has to be encrypted using HTTPS.
In order to protect user passwords from eavesdropping and to stay compatible with
existing configurations at the same time, the devices implement the following
behavior if Kerberos is enabled.
HTTP
No change to the normal behavior
Digest or Basic authentication is offered
Local users from the box, only
Summary of Contents for ExResistTel IP2/IP154
Page 43: ...Manual ResistTel IP2 IP152 Page 43 ExResistTel IP2 IP154 Figure 9 Set View ...
Page 386: ...Page 386 Manual ResistTel IP2 IP152 ExResistTel IP2 IP154 ...
Page 387: ...Manual ResistTel IP2 IP152 Page 387 ExResistTel IP2 IP154 ...
Page 390: ...Page 390 Manual ResistTel IP2 IP152 ExResistTel IP2 IP154 ...