Re: Using Active Directory for Centralized Authentication



Thanks for the reply Joe. We may have several applications pointing to
LDAP and it's unlikely we'll use ASP.net or IIS. It will mostly be
JAVA with an iPlanet back end. I do not want to add an unreasonable
load to my Windows DCs for this traffic. I'd like to see some scaling
or best practice documents from MS (or someone else) showing what you
may need to use AD as your centralized authoriatative directory.

Since AD is our most reliable and accurate repository of user
information, I'd like to see it at the center of our organization for
proxy, application, security and other types of auth traffic.

I'm just concerned about using this as our centralized solution as
opposed to open LDAP or another LDAP solution.

Thanks,
Josh



Joe Kaplan (MVP - ADSI) wrote:
Yes, lots and lots of people do this. In fact, this all "just works" if you
put your web servers into the domain and use the built in authentication
features in IIS. ASP.NET makes it very easy to leverage your groups
directly in your web applications.

If you don't want to use the built-in features in IIS to get this, .NET 2.0
comes with a new membership and role provider things that plug in to AD and
allow you to do forms authentication against AD. There are tons of
documents on MSDN about this kind of stuff.

If you aren't using ASP.NET, you can still do this, but the docs will vary
based on the web platform you are using.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
<joshuahatten@xxxxxxxxx> wrote in message
news:1154038885.143693.324070@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I'd like to have our internal developers begin using Active Directory
for security within their applications. This would simplify user
management by allowing users to have the same un/pw on 20 different
applications. My thought is that we would use LDAP to directly query
AD, return authentication and group information to the web app which
will then allow or deny access and set permissions (based on what info
is returned).

A few questions:
1. Has anyone done this?
2. If so, do you have any documentation or recommendations on scaling,
design, setup?


Thank you,
J


.



Relevant Pages

  • Re: Domain registration requirement in federated web sso with fore
    ... Thanks a lot Joe for this useful information. ... We have some applications, written in non microsoft languages like Java, ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... internet, then the DNS entries for the resources will need to be ...
    (microsoft.public.windows.server.active_directory)
  • Re: Secure External LDAP Query into Our Active Directory
    ... Thank you for your response Joe. ... authenticate to our domain via LDAP over SSL when they go to Blackboard's ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.windows.server.active_directory)
  • Re: LDAP Authentication
    ... Thanks Joe for your responses. ... LDAP auth membership provider that is coded to work with Sun One. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • If you will submit Moammars parliament in accordance with accidents, it will wearily consist the pro
    ... stired the cultural channels into endless bow. ... Whoever mind substantially, unless Talal acquires applications ... Joe never circulates until Penny differs the ... then Sarah instantly emerges a quaint emergence ...
    (rec.games.roguelike.nethack)
  • Re: Domain registration requirement in federated web sso with fore
    ... Thanks a lot Joe for your hearty and prompt response. ... significant impacts in the existing applications, so no way to choose that. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... internet, then the DNS entries for the resources will need to be ...
    (microsoft.public.windows.server.active_directory)