Re: AD Authentication in a DMZ ?



Pascal wrote:
Hi,

we have an application in our DMZ that needs to use Active Directory database for authentication.

Of course our AD domain controllers are in our LAN.

Is there a secure way to use AD Authentication for applications localized in a DMZ ?

One option is to use ADAM with userProxy objects which will forward authentication requests to Your AD in LAN.

Other option is to use ADFS, but your application will have to be tested if it will work with ADFS.

Third option is AD forest in Your DMZ which will have trust relationship with Your main AD (I don't like such solution but this is also an option)

--
Tomasz Onyszko
http://www.w2k.pl/ - (PL)
http://blogs.dirteam.com/blogs/tomek/ - (EN)
.



Relevant Pages

  • Re: AD Authentication in a DMZ (up) ?
    ... ADFS or a specific forest only for Applications ressources. ... Can we use a RADIUS proxy in the DMZ that will sned authentication request from DMZ to DCs? ... Why the third option is less secure than ADFS or ADAM? ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication in a DMZ (up) ?
    ... You'll need to open the necessary ports between DMZ and internal to allow ... database for authentication. ... Other option is to use ADFS, but your application will have to be tested ... Why the third option is less secure than ADFS or ADAM? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Exchange 2003 Front End/Back End Servers & Passwords
    ... Sort of negates the purpose of a DMZ. ... > The authentication was my concern - might be more sensible to post to ... you have to open up a LOT between the DMZ and LAN. ... > up the email server to the world any more than I have to. ...
    (microsoft.public.exchange.admin)
  • RE: AD in the DMZ . . . OK?
    ... If the only thing needed is authentication with userid/password, ... If I were to expose any AD domain to the DMZ, ... > interaction with one of our expert instructors. ... > Attend a course taught by an expert instructor with years of ...
    (Security-Basics)
  • Re: [fw-wiz] NTLM authentication from DMZ
    ... Exchange server is part of the normal company domain, ... have one authentication database to deal with. ... Place the exchange server in the DMZ, but that would require a whole ... Place it on the LAN, but that would require opening ports from the ...
    (Firewall-Wizards)