1 2<!DOCTYPE html> 3 4 5<html lang="en" data-content_root="../" > 6 7 <head> 8 <meta charset="utf-8" /> 9 <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" /> 10 11 <title>Web_App_Authentication — FreeIPA documentation</title> 12 13 14 15
15<script data-cfasync="false"> 16 document.documentElement.dataset.mode = localStorage.getItem("mode") || ""; 17 document.documentElement.dataset.theme = localStorage.getItem("theme") || ""; 18 </script>
18 19 <!-- 20 this give us a css class that will be invisible only if js is disabled 21 --> 22 <noscript> 23 <style> 24 .pst-js-only { display: none !important; } 25 26 </style> 27 </noscript> 28 29 <!-- Loaded before other Sphinx assets --> 30 <link href="../_static/styles/theme.css?digest=90905a2f556bf617f1a9" rel="stylesheet" /> 31<link href="../_static/styles/pydata-sphinx-theme.css?digest=90905a2f556bf617f1a9" rel="stylesheet" /> 32 33 <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=8f2a1f02" /> 34 <link rel="stylesheet" type="text/css" href="../_static/styles/sphinx-book-theme.css?v=4418a689" /> 35 36 <!-- So that users can add custom icons --> 37
37<script defer src="../_static/scripts/fontawesome.js?digest=90905a2f556bf617f1a9"></script>
37 38 <!-- Pre-loaded scripts that we'll load fully later --> 39 <link rel="preload" as="script" href="../_static/scripts/bootstrap.js?digest=90905a2f556bf617f1a9" /> 40<link rel="preload" as="script" href="../_static/scripts/pydata-sphinx-theme.js?digest=90905a2f556bf617f1a9" /> 41 42
42<script src="../_static/documentation_options.js?v=9eb32ce0"></script>
42 43
43<script src="../_static/doctools.js?v=fd6eb6e6"></script>
43 44
44<script src="../_static/sphinx_highlight.js?v=6ffebe34"></script>
44 45
45<script src="../_static/scripts/sphinx-book-theme.js?v=fab101a9"></script>
45 46
46<script>DOCUMENTATION_OPTIONS.pagename = 'page/Web_App_Authentication';</script>
46 47
47<script>DOCUMENTATION_OPTIONS.search_as_you_type = false;</script>
47 48 <link rel="icon" href="../_static/favicon.png"/> 49 <link rel="index" title="Index" href="../genindex.html" /> 50 <link rel="search" title="Search" href="../search.html" /> 51 <meta name="viewport" content="width=device-width, initial-scale=1"/> 52 <meta name="docsearch:language" content="en"/> 53 <meta name="docsearch:version" content="" /> 54 55 56
56<script src="../_static/searchtools.js"></script>
56 57
57<script src="../_static/language_data.js"></script>
57 58
58<script src="../searchindex.js"></script>
58 59 60 </head> 61 <body data-default-mode=""> 62 63 64 <div id="pst-skip-link" class="skip-link d-print-none"><a href="#main-content">Skip to main content</a></div> 65 66 67 <div id="pst-scroll-pixel-helper"></div> 68 69 <button type="button" class="btn rounded-pill" id="pst-back-to-top"> 70 <i class="fa-solid fa-arrow-up"></i>Back to top</button> 71 72 73 74 75 <dialog id="pst-search-dialog"> 76 77<form class="bd-search d-flex align-items-center" 78 action="../search.html" 79 method="get"> 80 <i class="fa-solid fa-magnifying-glass"></i> 81 <input type="search" 82 class="form-control" 83 name="q" 84 placeholder="Search..." 85 aria-label="Search..." 86 autocomplete="off" 87 autocorrect="off" 88 autocapitalize="off" 89 spellcheck="false"/> 90 <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd>K</kbd></span> 91</form> 92 </dialog> 93 94 <div class="pst-async-banner-revealer d-none"> 95 <aside id="bd-header-version-warning" class="d-none d-print-none" aria-label="Version warning"></aside> 96</div> 97 98 99 <header id="pst-header" class="bd-header navbar navbar-expand-lg bd-navbar d-print-none"> 100<div class="bd-header__inner bd-page-width"> 101 <button class="pst-navbar-icon sidebar-toggle primary-toggle" aria-label="Site navigation"> 102 <span class="fa-solid fa-bars"></span> 103 </button> 104 105 106 <div class="col-lg-9 navbar-header-items"> 107 108 109 <div class="navbar-header-items__end"> 110 111 <div class="navbar-item navbar-persistent--container"> 112 113 114<button class="btn search-button-field search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip"> 115 <i class="fa-solid fa-magnifying-glass"></i> 116 <span class="search-button__default-text">Search</span> 117 <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd class="kbd-shortcut__modifier">K</kbd></span> 118</button> 119 </div> 120 121 122 </div> 123 124 </div> 125 126 127 <div class="navbar-persistent--mobile"> 128 129<button class="btn search-button-field search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip"> 130 <i class="fa-solid fa-magnifying-glass"></i> 131 <span class="search-button__default-text">Search</span> 132 <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd class="kbd-shortcut__modifier">K</kbd></span> 133</button> 134 </div> 135 136 137 138 <button class="pst-navbar-icon sidebar-toggle secondary-toggle" aria-label="On this page"> 139 <span class="fa-solid fa-outdent"></span> 140 </button> 141 142</div> 143 144 </header> 145 146 147 <div class="bd-container"> 148 <div class="bd-container__inner bd-page-width"> 149 150 151 152 <dialog id="pst-primary-sidebar-modal"></dialog> 153 <div id="pst-primary-sidebar" class="bd-sidebar-primary bd-sidebar"> 154 155 156 157 <div class="sidebar-header-items sidebar-primary__section"> 158 159 160 161 162 </div> 163 164 <div class="sidebar-primary-items__start sidebar-primary__section"> 165 <div class="sidebar-primary-item"><a class="navbar-brand logo" href="/"> 166 <img src="https://raw.githubusercontent.com/freeipa/freeipa.github.io/main/src/_static/freeipa-logo-small.png" class="logo__image" alt="Logo image" /> 167</a></div> 168 <div class="sidebar-primary-item"> 169 170<button class="btn search-button-field search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip"> 171 <i class="fa-solid fa-magnifying-glass"></i> 172 <span class="search-button__default-text">Search</span> 173 <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd class="kbd-shortcut__modifier">K</kbd></span> 174</button></div> 175 <div class="sidebar-primary-item"><div class="sidebar-primary-item"> 176 <nav class="bd-links" id="bd-docs-nav" aria-label="Main"> 177 <div class="bd-toc-item navbar-nav active"> 178 <ul class="nav bd-sidenav"> 179 <li class="toctree-l1"><a class="reference internal" href="/About.html">About</a></li> 180 <li class="toctree-l1"><a class="reference internal" href="/Contribute.html">
180Contribute</a></li> 181 <li class="toctree-l1"><a class="reference internal" href="/page/Documentation.html">Documentation</a></li> 182 <li class="toctree-l1"><a class="reference internal" href="/page/Troubleshooting.html">Troubleshooting</a></li> 183 <li class="toctree-l1"><a class="reference internal" href="/Downloads.html">Downloads</a></li> 184 </ul> 185 </div> 186 </nav> 187</div></div> 188 </div> 189 190 191 <div class="sidebar-primary-items__end sidebar-primary__section"> 192 <div class="sidebar-primary-item"> 193<div id="ethical-ad-placement" 194 class="flat" 195 data-ea-publisher="readthedocs" 196 data-ea-type="readthedocs-sidebar" 197 data-ea-manual="true"> 198</div></div> 199 </div> 200 201 202 </div> 203 204 <main id="main-content" class="bd-main" role="main"> 205 206 207 208<div class="sbt-scroll-pixel-helper"></div> 209 210 <div class="bd-content"> 211 <div class="bd-article-container"> 212 213 <div class="bd-header-article d-print-none"> 214<div class="header-article-items header-article__inner"> 215 216 <div class="header-article-items__start"> 217 218 <div class="header-article-item"><button class="sidebar-toggle primary-toggle btn btn-sm" title="Toggle primary sidebar" data-bs-placement="bottom" data-bs-toggle="tooltip"> 219 <span class="fa-solid fa-bars"></span> 220</button></div> 221 222 </div> 223 224 225 <div class="header-article-items__end"> 226 227 <div class="header-article-item"> 228 229<div class="article-header-buttons"> 230 231 232 233 234 235<div class="dropdown dropdown-download-buttons"> 236 <button class="btn dropdown-toggle" type="button" data-bs-toggle="dropdown" aria-expanded="false" aria-label="Download this page"> 237 <i class="fas fa-download"></i> 238 </button> 239 <ul class="dropdown-menu"> 240 241 242 243 <li><a href="../_sources/page/Web_App_Authentication.rst" target="_blank" 244 class="btn btn-sm btn-download-source-button dropdown-item" 245 title="Download source file" 246 data-bs-placement="left" data-bs-toggle="tooltip" 247> 248 249 250<span class="btn__icon-container"> 251 <i class="fas fa-file"></i> 252 </span> 253<span class="btn__text-container">.rst</span> 254</a> 255</li> 256 257 258 259 260 <li> 261<button onclick="window.print()" 262 class="btn btn-sm btn-download-pdf-button dropdown-item" 263 title="Print to PDF" 264 data-bs-placement="left" data-bs-toggle="tooltip" 265> 266 267 268<span class="btn__icon-container"> 269 <i class="fas fa-file-pdf"></i> 270 </span> 271<span class="btn__text-container">.pdf</span> 272</button> 273</li> 274 275 </ul> 276</div> 277 278 279 280 281<button onclick="toggleFullScreen()" 282 class="btn btn-sm btn-fullscreen-button pst-navbar-icon" 283 title="Fullscreen mode" 284 data-bs-placement="bottom" data-bs-toggle="tooltip" 285> 286 287 288<span class="btn__icon-container"> 289 <i class="fas fa-expand"></i> 290 </span> 291 292</button> 293 294 295 296<div class="theme-switch-container dropdown pst-js-only" data-bs-toggle="tooltip" data-bs-placement="bottom" title="Color mode"> 297 <button class="btn btn-sm nav-link pst-navbar-icon theme-switch-button dropdown-toggle" aria-label="Color mode" data-bs-toggle="dropdown"> 298 <i class="theme-switch fa-solid fa-sun fa-lg fa-fw" data-mode="light" title="Light"></i> 299 <i class="theme-switch fa-solid fa-moon fa-lg fa-fw" data-mode="dark" title="Dark"></i> 300 <i class="theme-switch fa-solid fa-circle-half-stroke fa-lg fa-fw" data-mode="auto" title="System Settings"></i> 301 </button> 302 <ul class="dropdown-menu dropdown-menu-end"> 303 <li><button class="dropdown-item d-flex align-items-center theme-change-button" data-mode="auto"><i class="fa-solid fa-circle-half-stroke fa-lg fa-fw me-1"></i>System Settings</button></li> 304 <li><button class="dropdown-item d-flex align-items-center theme-change-button" data-mode="light"><i class="fa-solid fa-sun fa-lg fa-fw me-1"></i>Light</button></li> 305 <li><button class="dropdown-item d-flex align-items-center theme-change-button" data-mode="dark"><i class="fa-solid fa-moon fa-lg fa-fw me-1"></i>Dark</button></li> 306 </ul> 307</div> 308 309 310<button class="btn btn-sm pst-navbar-icon search-button search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip"> 311 <i class="fa-solid fa-magnifying-glass fa-lg"></i> 312</button> 313<button class="sidebar-toggle secondary-toggle btn btn-sm pst-navbar-icon" title="Toggle secondary sidebar" data-bs-placement="bottom" data-bs-toggle="tooltip"> 314 <span class="fa-solid fa-list"></span> 315</button> 316</div></div> 317 318 </div> 319 320</div> 321</div> 322 323 324 325<div id="jb-print-docs-body" class="onlyprint"> 326 <h1>Web_App_Authentication</h1> 327 <!-- Table of contents --> 328 <div id="print-main-content"> 329 <div id="jb-print-toc"> 330 331 <div> 332 <h2> Contents </h2> 333 </div> 334 <nav aria-label="Page"> 335 <ul class="pst-show_toc_level nav section-nav flex-column"> 336<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#the-use-of-sssd">The use of sssd</a></li> 337<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#kerberos">Kerberos</a></li> 338<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#application-change-remote-user">Application change: REMOTE_USER</a></li> 339<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#other-authentication-modules">Other authentication modules</a></li> 340<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#host-and-service-based-access-control">Host and service based access control</a></li> 341<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#hbac-rules">HBAC rules</a></li> 342<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#pam-service">PAM service</a></li> 343<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#mod-authnz-pam">mod_authnz_pam</a></li> 344<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#overview">Overview</a></li> 345<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#login-form-using-freeipa">Login form using FreeIPA</a></li> 346<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#additional-user-information">Additional user information</a></li> 347<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#namespace-separation">Namespace Separation</a></li> 348<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#saml">SAML</a></li> 349<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#references">References</a></li> 350<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#openstack">OpenStack</a></li> 351<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#spacewalk">Spacewalk</a></li> 352<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite">Satellite</a></li> 353<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman">Foreman</a></li> 354<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite-6">Satellite 6</a></li> 355<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#manageiq">ManageIQ</a></li> 356<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#cloudforms">CloudForms</a></li> 357<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#opendaylight">OpenDayLight</a></li> 358<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#videos">Videos</a></li> 359<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#using-os-level-identity-authentication-and-access-control-for-web-applications">Using OS-level identity, authentication, and access control for Web applications</a></li> 360<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-in-red-hat-enterprise-linux-web-application-authentication-series">Identity management in Red Hat Enterprise Linux: Web Application Authentication Series</a></li> 361<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#django">Django</a></li> 362<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman-demo">Foreman demo</a></li> 363<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#presentations">Presentations</a></li> 364<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-and-federated-identities-on-the-web">External and Federated Identities on the Web</a></li> 365<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#id1">Using OS-level identity, authentication, and access control for Web applications</a></li> 366<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-identity-and-authentication-providers-for-apache-http-server">External Identity and Authentication Providers For Apache HTTP Server</a></li> 367<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-scaling-out-and-up">Identity Management Scaling Out and Up</a></li> 368<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-authentication-for-django-projects">External Authentication for Django Projects</a></li> 369</ul> 370 </nav> 371 </div> 372 </div> 373</div> 374 375 376 377<div id="searchbox"></div> 378 <article class="bd-article"> 379 380 <section id="web-app-authentication"> 381<h1>
381Web_App_Authentication<a class="headerlink" href="#web-app-authentication" title="Link to this heading">#</a></h1> 382<p>The typical web applications nowadays use HTTP 383<a class="reference external" href="http://en.wikipedia.org/wiki/HTTP_cookie">cookie</a>-based 384authentication sessions, usually with login-form to enter login and 385password pair which is then validated by the application against some 386internal user database. Session record is then created and cookie set, 387which the browser will send with each subsequent request to the 388application. The application can then show data related to the 389authenticated user (shopping cart content, userâs posts, stored files) 390throughout their work with the application.</p> 391<p>In large organizations and enterprise deployments, user identities are 392usually managed in some central manner. Many programming languages and 393frameworks provide libraries/modules to authenticate for example against 394<a class="reference external" href="http://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol">LDAP</a> 395sources. However, when the full complexity of enterprise setups is 396considered, including 397<a class="reference external" href="http://en.wikipedia.org/wiki/Kerberos_%28protocol%29">Kerberos</a> 398authentication, <a class="reference external" href="http://en.wikipedia.org/wiki/Failover">failovers</a>, 399use of <a class="reference external" href="http://en.wikipedia.org/wiki/Active_Directory">Active 400Directory</a>, and 401identity federation, it can be useful to offload the authentication 402support to solution independent on the application code or framework â 403<a class="reference external" href="http://en.wikipedia.org/wiki/Apache_HTTP_Server">Apache</a> modules, 404and where needed, <a class="reference external" href="https://fedorahosted.org/sssd/">System Security Services Daemon 405(sssd)</a>.</p> 406<p>With fairly minimal changes, web applications can consume the results of 407authentication performed by Apache modules, using the standard 408REMOTE_USER environment variable/attribute/method. If applications know 409how to handle the authentication result coming from the underlying 410(front end) web server, it is then just a matter of configuration of the 411web server to add access control to Kerberos authentication, federated 412authentication via SAML, or use central identity management server like 413FreeIPA to authenticate [login, password] values submitted by user to 414applicationâs native logon-form.</p> 415<p>If the application is then extended to understand <a class="reference external" href="Environment_Variables#Proposed_Additional_Variables">additional proposed 416environment 417variables</a>, it 418can receive not just the authentication and authorization result but 419also additional information about the user, for example email address or 420full name, typically needed by application to provide the full 421functionality and good user experience. With group membership 422information available to the application, the application can base its 423application-specific roles/access rights/authorization for the user 424based on the external user information, again without having to add 425support for all of them in the application or framework code directly.</p> 426<p>There is an <a class="reference external" href="Web_App_Authentication/Example_setup">example setup</a> 427accompanying this page which demonstrates the concepts described below 428on a trivial CGI application.</p> 429<p>We do not expect applications to drop their existing functionality that 430served them well, this is merely an additional possibility.</p> 431<section id="the-use-of-sssd"> 432<h2>The use of sssd<a class="headerlink" href="#the-use-of-sssd" title="Link to this heading">#</a></h2> 433<p>The <a class="reference external" href="https://fedorahosted.org/sssd/">System Security Services Daemon 434(sssd)</a> is present as a standard part 435of the latest Red Hat Enterprise Linux, Fedora, and related 436distributions. It provides access to identity and authentication 437services and is primarily aimed at the operating system level. In this 438document, we will explore ways to use it for authentication and identity 439access of web applications, while preserving the distinction of the 440operating system and web application deployed on it.</p> 441<p>We will assume that the system on which the web application is deployed 442is IPA-enrolled. Using the command</p> 443<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">ipa</span><span class="o">-</span><span class="n">client</span><span class="o">-</span><span class="n">install</span> 444</pre></div> 445</div> 446<p>the local configuration of a couple of subsystems including sssd can be 447set up to point to a FreeIPA server. It also creates a host record on 448the server, making it possible to add services and get their Kerberos 449keytab.</p> 450<p>Services are important because they make it possible to have 451fine-grained control over a userâs access to the system. We might want 452to give a network administrator ssh access to the machine, but not 453access to the accounting system running on it. We might want to allow 454employees in the finance department to be able to access the accounting 455web application, but not ssh access to the underlying host.</p> 456</section> 457<section id="kerberos"> 458<h2>Kerberos<a class="headerlink" href="#kerberos" title="Link to this heading">#</a></h2> 459<p>All contemporary web browsers support SPNEGO and Kerberos. When 460accessing <a class="reference external" href="http://server.example.com/">http://server.example.com/</a> or <a class="reference external" href="https://server.example.com/">https://server.example.com/</a>, the 461server can propose <strong>Negotiate</strong> authentication method. If the user 462currently has ticket granted ticket (obtained for example via <code class="docutils literal notranslate"><span class="pre">kinit</span></code> 463command), the brower will obtain Kerberos tickets for principal 464<a class="reference external" href="mailto:HTTP/server.example.com%40EXAMPLE.COM">HTTP/server<span>.</span>example<span>.</span>com<span>@</span>EXAMPLE<span>.</span>COM</a> (as opposed to ssh which uses 465<a class="reference external" href="mailto:host/server.example.com%40EXAMPLE.COM">host/server<span>.</span>example<span>.</span>com<span>@</span>EXAMPLE<span>.</span>COM</a>) and use related GSSAPI data to 466authenticate to the server.</p> 467<p>To enable this method on typical Apache installation, 468<strong>mod_auth_gssapi</strong> or <strong>mod_auth_kerb</strong> module needs to be <a class="reference external" href="Web_App_Authentication/Example_setup#Kerberos">installed 469and configured</a>.</p> 470</section> 471<section id="application-change-remote-user"> 472<h2>Application change: REMOTE_USER<a class="headerlink" href="#application-change-remote-user" title="Link to this heading">#</a></h2> 473<p>The application then needs to be able to retrieve the result of the 474authentication, the login (principal) of the authenticated user. The 475standard mechanism for CGI deployments is via REMOTE_USER environment 476variable, and almost every web framework has a way to get this value 477from the web server, either via environment variable, attribute, or 478dedicated method call. (Itâs the same value and mechanism used for the 479HTTP Basic Authentication.)</p> 480<p>The application not only needs to retrieve the value but its processing 481flow needs to be modified to trust this value. Note that this variable 482will not be set unless the admin deploying and setting up the 483application configured the underlying Apache correctly. For application 484developers it might be a step from having complete control over the 485internal user database to more uncertainty, having to trust that the 486external value is correct.</p> 487<p>Furthermore, many applications will need to have record for any 488authenticated user in its internal database, even for the externally 489(Kerberos) authenticated ones, for foreign keys to work. That is fine â 490the first time the application sees REMOTE_USER set to value it does not
491have in the database, it can create the user record in its internal 492database on the fly. That way, even if it uses object-relational 493mapping, the application will still work. (See below if the application 494requires that the user record has certain attributes besides login NOT 495NULL.)</p> 496</section> 497<section id="other-authentication-modules"> 498<h2>Other authentication modules<a class="headerlink" href="#other-authentication-modules" title="Link to this heading">#</a></h2> 499<p>Besides Kerberos (with mod_auth_gssapi or mod_auth_kerb), there are 500other mechanisms that can be configured in Apache to authenticate:</p> 501<div class="pst-scrollable-table-container"><table class="table"> 502<thead> 503<tr class="row-odd"><th class="head"><p>Authentication Method</p></th> 504<th class="head"><p>Apache Authentication Module</p></th> 505</tr> 506</thead> 507<tbody> 508<tr class="row-even"><td><p>Pure Application Level</p></td> 509<td><p><em>None</em></p></td> 510</tr> 511<tr class="row-odd"><td><p>Kerberos Single Sign-On (ticket)</p></td> 512<td><p>mod_auth_gssapi</p></td> 513</tr> 514<tr class="row-even"><td><p>mod_auth_kerb</p></td> 515<td></td> 516</tr> 517<tr class="row-odd"><td><p>SAML-based</p></td> 518<td><p>mod_auth_mellon</p></td> 519</tr> 520<tr class="row-even"><td><p>Certificate-based</p></td> 521<td><p>mod_nss</p></td> 522</tr> 523<tr class="row-odd"><td><p>mod_ssl</p></td> 524<td></td> 525</tr> 526<tr class="row-even"><td><p></p></td> 527<td></td> 528</tr> 529</tbody> 530</table> 531</div> 532</section> 533<section id="host-and-service-based-access-control"> 534<h2>Host and service based access control<a class="headerlink" href="#host-and-service-based-access-control" title="Link to this heading">#</a></h2> 535<p>If mod_auth_gssapi/mod_auth_kerb is configured and application extended 536to consult and trust the REMOTE_USER value, it may have a potentially 537unwanted side effect â any user who is able to get the Kerberos ticket 538for <a class="reference external" href="mailto:HTTP/server.example.com%40EXAMPLE.COM">HTTP/server<span>.</span>example<span>.</span>com<span>@</span>EXAMPLE<span>.</span>COM</a> would then be able to log into 539the application. If the application is only intended for small set of 540users and if any successful external authentication will populate user 541record in applicationâs database, that will pollute the database with 542users who have no access rights in the application yet manage to come 543across its URL and get authenticated.</p> 544<p>A possible solution is to apply access control check to the Kerberos 545authentication method on the Apache level. That way, even if the user is 546able to get the Kerberos ticket the authentication will still fail. For 547this to work, we will use Apache module <strong>mod_authnz_pam</strong>, configure 548PAM service to use pam_sss.so, hooking it via sssd to the FreeIPA 549server, and set up host-based access control (HBAC) rule in FreeIPA to 550separate service, to only give access to a particular set or group of 551users.</p> 552</section> 553<section id="hbac-rules"> 554<h2>HBAC rules<a class="headerlink" href="#hbac-rules" title="Link to this heading">#</a></h2> 555<p>We will start from the end â from the FreeIPA HBAC service. It is just 556a string which distinguishes one service from another. Running</p> 557<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">ipa</span> <span class="n">hbacsvc</span><span class="o">-</span><span class="n">find</span> 558</pre></div> 559</div> 560<p>will show pre-created services like ssh, kdm, login, or kdm. Their names 561are then used to define the respective PAM service on the client â so 562for ssh, the configuration is in /etc/pam.d/ssh. If we are adding 563service for a reporting web application in our organization, we can name 564it <strong>reporting</strong> or <strong>reporting.example.com</strong> or <strong>reporting-prod</strong> and 565<strong>reporting-qa</strong> if we have multiple environments. Please consult help 566pages</p> 567<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">ipa</span> <span class="n">help</span> <span class="n">hbacsvc</span> 568<span class="n">ipa</span> <span class="n">help</span> <span class="n">hbacrule</span> 569<span class="n">ipa</span> <span class="n">help</span> <span class="n">hbactest</span> 570</pre></div> 571</div> 572<p>for detailed description of creating HBAC services and rules in FreeIPA. 573Please also note that you will probably need to <a class="reference external" href="Howto/HBAC_and_allow_all">disable the default 574allow_all HBAC rule</a> for the mechanism to 575work properly.</p> 576</section> 577<section id="pam-service"> 578<h2>PAM service<a class="headerlink" href="#pam-service" title="Link to this heading">#</a></h2> 579<p>On the IPA-enrolled machine on which the web application is being 580configured, we need to define the PAM service to use sssd. We create 581file named the same as the HBAC service weâve created with 582<code class="docutils literal notranslate"><span class="pre">ipa</span> <span class="pre">hbacsvc-add</span></code> and configure <code class="docutils literal notranslate"><span class="pre">pam_sss.so</span></code> for both auth and 583account. For example, if the HBAC service is <strong>reporting-prod</strong>, we will 584need file <strong>/etc/pam.d/reporting-prod</strong> with content</p> 585<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">auth</span> <span class="n">required</span> <span class="n">pam_sss</span><span class="o">.</span><span class="n">so</span> 586<span class="n">account</span> <span class="n">required</span> <span class="n">pam_sss</span><span class="o">.</span><span class="n">so</span> 587</pre></div> 588</div> 589</section> 590<section id="mod-authnz-pam"> 591<h2>mod_authnz_pam<a class="headerlink" href="#mod-authnz-pam" title="Link to this heading">#</a></h2> 592<p>The module <strong>mod_authnz_pam</strong> adds access control checks to 593authentication phase of HTTP request processing in Apache. The typical 594mod_auth_gssapi/mod_auth_kerb configuration will have</p> 595<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">require</span> <span class="n">valid</span><span class="o">-</span><span class="n">user</span> 596</pre></div> 597</div> 598<p>in it, saying that any authenticated user should be allowed. When we 599change it to <code class="docutils literal notranslate"><span class="pre">require</span> <span class="pre">pam-account</span> <span class="pre">PAM-service</span></code>, the user will only be 600authenticated by Apache if it matches the <code class="docutils literal notranslate"><span class="pre">account</span></code> check in PAM, 601which in case of <code class="docutils literal notranslate"><span class="pre">pam_sss.so</span></code> and sssd being configured to consult 602FreeIPA will lead to HBAC rule check, with the PAM service name used as 603the HBAC service. For our <strong>reporting-prod</strong> example, the 604<code class="docutils literal notranslate"><span class="pre">require</span> <span class="pre">valid-user</span></code> will change to</p> 605<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">require</span> <span class="n">pam</span><span class="o">-</span><span class="n">account</span> <span class="n">reporting</span><span class="o">-</span><span class="n">prod</span> 606</pre></div> 607</div> 608<p>We can even used different PAM services for different parts of the 609application, provided they can be identified using URLs. If the 610application has a special admin section, we can define separate PAM 611service (which possibly more strict rules) for this part:</p> 612<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="o"><</span><span class="n">Location</span> <span class="o">/</span><span class="n">app</span><span class="o">></span> 613<span class="n">require</span> <span class="n">pam</span><span class="o">-</span><span class="n">account</span> <span class="n">reporting</span><span class="o">-</span><span class="n">prod</span> 614<span class="o"></</span><span class="n">Location</span><span class="o">></span> 615<span class="o"><</span><span class="n">Location</span> <span class="o">/</span><span class="n">app</span><span class="o">/</span><span class="n">admin</span><span class="o">></span> 616<span class="n">require</span> <span class="n">pam</span><span class="o">-</span><span class="n">account</span> <span class="n">reporting</span><span class="o">-</span><span class="n">prod</span><span class="o">-</span><span class="n">admin</span> 617<span class="o"></</span><span class="n">Location</span><span class="o">></span> 618</pre></div> 619</div> 620</section> 621<section id="overview"> 622<h2>Overview<a class="headerlink" href="#overview" title="Link to this heading">#</a></h2> 623<p>The <strong>mod_authnz_pam</strong> module can be configured with any other module 624which uses the <code class="docutils literal notranslate"><span class="pre">require</span></code> Apache directive. The deployment matrix then 625changes to:</p> 626<div class="pst-scrollable-table-container"><table class="table"> 627<thead> 628<tr class="row-odd"><th class="head"><p>Authentication Method</p></th> 629<th class="head"><p>Apache Modules</p></th> 630</tr> 631</thead> 632<tbody> 633<tr class="row-even"><td><p>Authentication</p></td> 634<td><p>Access Control</p></td> 635</tr> 636<tr class="row-odd"><td><p>Pure Application Level</p></td> 637<td><p><em>None</em></p></td> 638</tr> 639<tr class="row-even"><td><p>Kerberos Single Sign-On (ticket)</p></td> 640<td><p>mod_auth_gssapi</p></td> 641</tr> 642<tr class="row-odd"><td><p>mod_auth_kerb</p></td> 643<td></td> 644</tr> 645<tr class="row-even"><td><p>SAML-based</p></td> 646<td><p>mod_auth_mellon</p></td> 647</tr> 648<tr class="row-odd"><td><p>Certificate-based</p></td> 649<td><p>mod_nss</p></td> 650</tr> 651<tr class="row-even"><td><p>mod_ssl</p></td> 652<td></td> 653</tr> 654<tr class="row-odd"><td><p></p></td> 655<td></td> 656</tr> 657</tbody> 658</table> 659</div> 660<p>Please consult the <a class="reference external" href="Web_App_Authentication/Example_setup#Host_.28and_service.29_based_access_control_for_Kerberos">example setup 661page</a> 662for detailed configuration steps.</p> 663</section> 664<section id="login-form-using-freeipa"> 665<h2>Login form using FreeIPA<a class="headerlink" href="#login-form-using-freeipa" title="Link to this heading">#</a></h2> 666<p>In many situations, neither Kerberos nor any other authentication method 667which requires some additional setup on clientâs side (like 668certificates) can be used or mandated, for practical reasons. Still, if 669the organization has a central user management in the form of FreeIPA, 670it can connect its existing applications to the FreeIPA authentication 671service, while retaining the application-specific look and feel of its 672login form. All that it takes for application is to understand the 673REMOTE_USER result of Apache authentication modules.</p> 674<p>The central authentication is achieved using the HBAC and PAM service 675described above, and Apache module <strong>mod_intercept_form_submit</strong>. The
676module can be configured to look at HTTP POST request resulting from 677user submitting applicationâs login form, and if login and password are 678found in the request, it will run PAM authentication and access control 679checks, using service specified with <code class="docutils literal notranslate"><span class="pre">InterceptFormPAMService</span></code> 680directive. The module internally calls mod_authnz_pam. When the service 681is properly configured to use <code class="docutils literal notranslate"><span class="pre">pam_sss.so</span></code> and sssd is configured to 682use FreeIPA, this form submit interception will validate the 683login/password pair, plus do the access control check like in the setup 684with Kerberos, described above.</p> 685<p>The successful result of this authentication is again passed using the 686REMOTE_USER mechanism. If application consults this value and trusts it, 687it will consider the user authenticated without checking its local user 688database.</p> 689<p>The failed authentication result is signalled to the application via 690environment variable EXTERNAL_AUTH_ERROR and applications are welcome to 691use this result indication.</p> 692<p>The proposed mix of authentication setups expands to</p> 693<div class="pst-scrollable-table-container"><table class="table"> 694<thead> 695<tr class="row-odd"><th class="head"><p>Authentication Method</p></th> 696<th class="head"><p>Apache Modules</p></th> 697</tr> 698</thead> 699<tbody> 700<tr class="row-even"><td><p>Authentication</p></td> 701<td><p>Access Control</p></td> 702</tr> 703<tr class="row-odd"><td><p>Pure Application Level</p></td> 704<td><p><em>None</em></p></td> 705</tr> 706<tr class="row-even"><td><p>Kerberos Single Sign-On (ticket)</p></td> 707<td><p>mod_auth_gssapi</p></td> 708</tr> 709<tr class="row-odd"><td><p>mod_auth_kerb</p></td> 710<td></td> 711</tr> 712<tr class="row-even"><td><p>SAML-based</p></td> 713<td><p>mod_auth_mellon</p></td> 714</tr> 715<tr class="row-odd"><td><p>Certificate-based</p></td> 716<td><p>mod_nss</p></td> 717</tr> 718<tr class="row-even"><td><p>mod_ssl</p></td> 719<td></td> 720</tr> 721<tr class="row-odd"><td><p>Login form-based</p></td> 722<td><p>mod_intercept_form_submit</p></td> 723</tr> 724<tr class="row-even"><td><p></p></td> 725<td></td> 726</tr> 727</tbody> 728</table> 729</div> 730<p>The <a class="reference external" href="Web_App_Authentication/Example_setup#External_identities_for_login_form">example setup 731page</a> 732has more details about the configuration.</p> 733</section> 734<section id="additional-user-information"> 735<h2>Additional user information<a class="headerlink" href="#additional-user-information" title="Link to this heading">#</a></h2> 736<p>The FreeIPA server can not only store plain login identities and 737passwords for authentication services, it can also hold additional user 738attributes like email addresses, phone numbers, or full names of users, 739as well as group membership. The sssd is then able to access this 740information and make it available to applications via new <strong>sssd-dbus</strong> 741package.</p> 742<p>Using Apache module <strong>mod_lookup_identity</strong> which can talk to sssdâs ifp 743service over dbus, any Apache moduleâs authenticated user can have 744additional environment variables populated from the central identity 745provider like FreeIPA. This can be used if the application requires that 746additional attributes are filled before storing the user in its internal 747database, or simply if the application makes use of such data. On the 748sssd side, the list of LDAP attributes that need to be retrieved and 749cached is specified, and then in mod_lookup_identityâs configuration, 750these attributes are mapped to environment variables.</p> 751<p>One type of data that the sssd-dbus calls provides is userâs group 752membership. This can be used to populate application-specific roles of 753the externally-authenticated user. Consider a situation when a newly 754hired network administrator is added to group <strong>netadmin</strong> in 755organizationâs FreeIPA server. Module mod_lookup_identity is able to 756retrieve this group name and populate environment variable like 757REMOTE_USER_GROUP_N, REMOTE_USER_GROUP_1, â¦, or REMOTE_USER_GROUPS as 758colon-separated list. System management and provisioning application can 759hold internal mapping of the external group <strong>netadmin</strong> to its internal 760role and access control handling, making such a user automatically have 761appropriate privileges.</p> 762<p>When using the attributes to populate the database with 763externally-authenticated users, it is good to consider the case when 764userâs details or group membership in the central identity provider 765change. It might be useful to not only populate the user record when it
766is not found in applicationâs database the first time the user 767authenticates, but also compare and update the information every time 768the user authenticates, if needed. This is especially important if group 769membership is linked to applicationâs role handling.</p> 770<p>Populating of additional attributes, mapping of groups to roles, and 771update of this information in applicationâs database are therefore 772additional changes that the web application developers might consider 773adding to their application to make deployment of their application 774easier in large enterprise environment, without getting necessarily deep 775into the details of each possible identity provider which the 776organizations might use. The applications only need to assume that the 777environment variables (or whatever is the method of handling this 778information in its programming language or framework) might be populated 779by the HTTP daemon setup and its modules.</p> 780<p>It is also our hope that other modules that might have the additional 781user attributes available (like SAML) might populate the <a class="reference external" href="Environment_Variables#Proposed_Additional_Variables">proposed 782environment 783variables</a> 784directly, so even if the web application deployment does not use neither 785FreeIPA, sssd, nor any of the Apache modules mentioned on this page, 786effort that went into modifications of web applications can still be 787used.</p> 788<p>The <a class="reference external" href="Web_App_Authentication/Example_setup#Storing_external_users_in_internal_databases">example setup 789page</a> 790describes the sssd-dbus and mod_lookup_identity setup in more detail.</p> 791<p>The whole proposed solution for web application authentication using 792sssd:</p> 793<div class="pst-scrollable-table-container"><table class="table"> 794<thead> 795<tr class="row-odd"><th class="head"><p>Authentication Method</p></th> 796<th class="head"><p>Apache Modules</p></th> 797</tr> 798</thead> 799<tbody> 800<tr class="row-even"><td><p>Authentication</p></td> 801<td><p>Access Control</p></td> 802</tr> 803<tr class="row-odd"><td><p>Pure Application Level</p></td> 804<td><p><em>None</em></p></td> 805</tr> 806<tr class="row-even"><td><p>Kerberos Single Sign-On (ticket)</p></td> 807<td><p>mod_auth_gssapi</p></td> 808</tr> 809<tr class="row-odd"><td><p>mod_auth_kerb</p></td> 810<td></td> 811</tr> 812<tr class="row-even"><td><p>SAML-based</p></td> 813<td><p>mod_auth_mellon</p></td> 814</tr> 815<tr class="row-odd"><td><p>Certificate-based</p></td> 816<td><p>mod_nss</p></td> 817</tr> 818<tr class="row-even"><td><p>mod_ssl</p></td> 819<td></td> 820</tr> 821<tr class="row-odd"><td><p>Login form-based</p></td> 822<td><p>mod_intercept_form_submit</p></td> 823</tr> 824<tr class="row-even"><td><p></p></td> 825<td></td> 826</tr> 827</tbody> 828</table> 829</div> 830<p>Note: sssd call also be configured to use different identity providers 831than FreeIPA but such setup is beyond the scope of this overview.</p> 832</section> 833<section id="namespace-separation"> 834<h2>Namespace Separation<a class="headerlink" href="#namespace-separation" title="Link to this heading">#</a></h2> 835<p>In the above description we have assumed that the admin wants to handle 836all their application users with external authentication and that the 837set of user identities (locally created/managed and the 838externally-authenticated) overlap. Depending on the use case this might 839or might not be desirable. Consult <a class="reference external" href="Web_App_Authentication/Namespace_separation">Namespace 840separation</a> for possible 841setups with externally-authenticated users marked with @REALM and 842multiple IPA server setups.</p> 843</section> 844<section id="saml"> 845<h2>SAML<a class="headerlink" href="#saml" title="Link to this heading">#</a></h2> 846<p>As mentioned above, when the Web application / framework is amended to 847be able to process REMOTE_USER and REMOTE_USER_GROUP_* environment 848variables, itâs then just a matter of configuration of the front-end 849server to enable a particular mechanism of external authentication. For 850example, for SAML (Security Assertion Markup Language), 851<a class="reference external" href="https://github.com/UNINETT/mod_auth_mellon">mod_auth_mellon</a> can be
852used and starting with version 0.11.0, it can be configured to populate 853environment variables exactly like mod_lookup_identity does:</p> 854<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_GROUP"</span> <span class="s2">"groups"</span> 855<span class="n">MellonEnvVarsIndexStart</span> <span class="mi">1</span> 856<span class="n">MellonEnvVarsSetCount</span> <span class="n">On</span> 857</pre></div> 858</div> 859<p>and we can pass other attributes as well:</p> 860<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_LASTNAME"</span> <span class="s2">"surname"</span> 861<span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_FIRSTNAME"</span> <span class="s2">"givenname"</span> 862<span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_EMAIL"</span> <span class="s2">"email"</span> 863</pre></div> 864</div> 865</section> 866<section id="references"> 867<h2>References<a class="headerlink" href="#references" title="Link to this heading">#</a></h2> 868</section> 869<section id="openstack"> 870<h2>OpenStack<a class="headerlink" href="#openstack" title="Link to this heading">#</a></h2> 871<ul class="simple"> 872<li><p>Nathan Kinderâs <a class="reference external" href="https://blog-nkinder.rhcloud.com/?p=130">https://blog-nkinder.rhcloud.com/?p=130</a></p></li> 873<li><p>Adam Youngâs <a class="reference external" href="http://adam.younglogic.com/2015/03/key-fed-lookup-redux/">http://adam.younglogic.com/2015/03/key-fed-lookup-redux/</a></p></li> 874</ul> 875</section> 876<section id="spacewalk"> 877<h2>Spacewalk<a class="headerlink" href="#spacewalk" title="Link to this heading">#</a></h2> 878<p>In Spacewalk 2.1, it is possible to use both the Kerberos 879authentication, and the form-based PAM authentication, including the 880HBAC management from FreeIPA and mapping of group membership from the 881identity provider to Spacewalk roles (access rights) â see 882<a class="reference external" href="https://fedorahosted.org/spacewalk/wiki/SpacewalkAndIPA">https://fedorahosted.org/spacewalk/wiki/SpacewalkAndIPA</a> for full 883documentation of the feature.</p> 884</section> 885<section id="satellite"> 886<h2>Satellite<a class="headerlink" href="#satellite" title="Link to this heading">#</a></h2> 887<p>Based on Spacewalk upstream, the capability is now also available in 888Satellite 5.7 and documented in the <a class="reference external" href="https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/5.7/html/Installation_Guide/ch06s02.html">Using Identity Management for 889Authentication</a> 890chapter of the Installation Guide.</p> 891</section> 892<section id="foreman"> 893<h2>Foreman<a class="headerlink" href="#foreman" title="Link to this heading">#</a></h2> 894<p>In Foreman 1.5, the external authentication is fully implemented as 895described on this page â see the <a class="reference external" href="http://projects.theforeman.org/issues/5031">tracking 896issue</a> with links to 897individual issues and pull requests that introduced the feature. It is 898now documented in <a class="reference external" href="http://theforeman.org/manuals/1.6/index.html#5.7ExternalAuthentication">Foreman 899manual</a>.</p> 900</section> 901<section id="satellite-6"> 902<h2>Satellite 6<a class="headerlink" href="#satellite-6" title="Link to this heading">#</a></h2> 903<p>Based on Foreman upstream, the capability is now also available in 904Satellite 6.0: 905<a class="reference external" href="https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.1/html/User_Guide/sect-Using-I
905dM-for-Authentication.html">https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.1/html/User_Guide/sect-Using-IdM-for-Authentication.html</a></p> 906</section> 907<section id="manageiq"> 908<h2>ManageIQ<a class="headerlink" href="#manageiq" title="Link to this heading">#</a></h2> 909<p>The support for external authentication is now in manageiq master: 910<a class="github reference external" href="https://github.com/ManageIQ/manageiq/commit/e0423c18d48380ff8d490ccb08291d2098fde69f">ManageIQ/manageiq</a>. 911The feature is configured by the console: 912<a class="github reference external" href="https://github.com/ManageIQ/manageiq/commit/cc6ea8b103a23bee5af8f9d88eac3024fc26cf18">ManageIQ/manageiq</a>, 913or manually: 914<a class="github reference external" href="https://github.com/ManageIQ/guides/blob/master/external_auth.md">ManageIQ/guides</a> and 915<a class="github reference external" href="https://github.com/ManageIQ/guides/blob/master/external_auth/configuration.md">ManageIQ/guides</a>.</p> 916</section> 917<section id="cloudforms"> 918<h2>CloudForms<a class="headerlink" href="#cloudforms" title="Link to this heading">#</a></h2> 919<p>Based on the ManageIQ upstream, the capability is now also available in 920CFME 5.3 and documented in the 921<a class="reference external" href="https://access.redhat.com/documentation/en-US/Red_Hat_CloudForms/3.1/html/Management_Engine_5.3_Settings_and_Operations_Guide/chap-Configuration.html">Configuration</a> 922chapter of the Settings and Operations Guide.</p> 923</section> 924<section id="opendaylight"> 925<h2>OpenDayLight<a class="headerlink" href="#opendaylight" title="Link to this heading">#</a></h2> 926<p><a class="reference external" href="https://jdennis.fedorapeople.org/doc/sssd_configuration.pdf">Federated Authentication Utilizing Apache & 927SSSD</a> by 928John Dennis.</p> 929</section> 930<section id="videos"> 931<h2>Videos<a class="headerlink" href="#videos" title="Link to this heading">#</a></h2> 932</section> 933<section id="using-os-level-identity-authentication-and-access-control-for-web-applications"> 934<h2>Using OS-level identity, authentication, and access control for Web applications<a class="headerlink" href="#using-os-level-identity-authentication-and-access-control-for-web-applications" title="Link to this heading">#</a></h2> 935<ul class="simple"> 936<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/os-auth-stack-for-web-applications">Presentation at DevConf 9372015</a> 938<a class="reference external" href="https://www.youtube.com/watch?v=Hhy5__C-XFc">https://www.youtube.com/watch?v=Hhy5__C-XFc</a> 939{{#ev:youtube|Hhy5__C-XFc}} 940Sadly, the first five minutes of the video are without sound.</p></li> 941</ul> 942</section> 943<section id="identity-management-in-red-hat-enterprise-linux-web-application-authentication-series"> 944<h2>Identity management in Red Hat Enterprise Linux: Web Application Authentication Series<a class="headerlink" href="#identity-management-in-red-hat-enterprise-linux-web-application-authentication-series" title="Link to this heading">#</a></h2> 945<ul class="simple"> 946<li><p>Part I: Current standard: logon forms and cookie-based sessions 947<a class="reference external" href="https://www.youtube.com/watch?v=Qdv8waOk6UE">https://www.youtube.com/watch?v=Qdv8waOk6UE</a> 948{{#ev:youtube|Qdv8waOk6UE}}</p></li> 949<li><p>Part II: Kerberos single sign-on 950<a class="reference external" href="https://www.youtube.com/watch?v=_We4O8OuJAY">https://www.youtube.com/watch?v=_We4O8OuJAY</a> 951{{#ev:youtube|_We4O8OuJAY}}</p></li> 952<li><p>Part III: Additional services of central identity provider 953<a class="reference external" href="https://www.youtube.com/watch?v=uG1rxZ4ydUE">
953https://www.youtube.com/watch?v=uG1rxZ4ydUE</a> 954{{#ev:youtube|uG1rxZ4ydUE}}</p></li> 955</ul> 956</section> 957<section id="django"> 958<h2>Django<a class="headerlink" href="#django" title="Link to this heading">#</a></h2> 959<ul class="simple"> 960<li><p>External Authentication for Django Projects 961<a class="reference external" href="https://www.youtube.com/watch?v=62_jD-8zV4M">https://www.youtube.com/watch?v=62_jD-8zV4M</a> 962{{#ev:youtube|62_jD-8zV4M}}</p></li> 963</ul> 964</section> 965<section id="foreman-demo"> 966<h2>Foreman demo<a class="headerlink" href="#foreman-demo" title="Link to this heading">#</a></h2> 967<ul class="simple"> 968<li><p>External authentication with and installer improvements, presented by 969Marek Hulán 970<a class="reference external" href="https://www.youtube.com/watch?v=S-8PESGbOUk#t=475">https://www.youtube.com/watch?v=S-8PESGbOUk#t=475</a> 971{{#ev:youtube|S-8PESGbOUk|||||#t=475}}</p></li> 972</ul> 973</section> 974<section id="presentations"> 975<h2>Presentations<a class="headerlink" href="#presentations" title="Link to this heading">#</a></h2> 976</section> 977<section id="external-and-federated-identities-on-the-web"> 978<h2>External and Federated Identities on the Web<a class="headerlink" href="#external-and-federated-identities-on-the-web" title="Link to this heading">#</a></h2> 979<ul class="simple"> 980<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/external-and-federated-identities">ApacheCon Core Europe 2015 981presentation</a> 982(also as <a class="reference external" href="http://www.adelton.com/docs/idm/external-and-federated-identities.pdf">PDF 983slides</a>)</p></li> 984</ul> 985</section> 986<section id="id1"> 987<h2>Using OS-level identity, authentication, and access control for Web applications<a class="headerlink" href="#id1" title="Link to this heading">#</a></h2> 988<ul class="simple"> 989<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/os-auth-stack-for-web-applications">Developer Conference 2015 990presentation</a> 991(also as <a class="reference external" href="http://www.adelton.com/docs/idm/os-auth-stack-for-web-applications.pdf">PDF 992slides</a>)</p></li> 993</ul> 994</section> 995<section id="external-identity-and-authentication-providers-for-apache-http-server"> 996<h2>External Identity and Authentication Providers For Apache HTTP Server<a class="headerlink" href="#external-identity-and-authentication-providers-for-apache-http-server" title="Link to this heading">#</a></h2> 997<ul class="simple"> 998<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/apache-external-idm-auth">ApacheCon Europe 2014 999presentation</a> 1000(also as <a class="reference external" href="http://www.adelton.com/docs/idm/apache-external-idm-auth.pdf">PDF 1001slides</a>)</p></li> 1002</ul> 1003</section> 1004<section id="identity-management-scaling-out-and-up"> 1005<h2>Identity Management Scaling Out and Up<a class="headerlink" href="#identity-management-scaling-out-and-up" title="Link to this heading">#</a></h2> 1006<ul class="simple"> 1007<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/idm-scaling-out-and-up">LinuxCon Europe 2014 1008presentation</a> 1009(also as <a class="reference external" href="http://www.adelton.com/docs/idm/idm-scaling-out-and-up.pdf">PDF 1010slides</a>)</p></li> 1011</ul> 1012</section> 1013<section id="external-authentication-for-django-projects"> 1014<h2>External Authentication for Django Projects<a class="headerlink" href="#external-authentication-for-django-projects" title="Link to this heading">#</a></h2> 1015<ul class="simple"> 1016<li><p><a class="reference external" href="http://www.adelton.com/django/external-authentication-for-django-projects">EuroPython 2015 1017presetnation</a> 1018(also as <a class="reference external" href="http://www.adelton.com/django/external-authentication-for-django-projects.pdf">PDF 1019slides</a>)</p></li> 1020</ul> 1021</section> 1022</section> 1023 1024 1025 </article> 1026 1027 1028 1029 1030 1031 1032 <footer class="prev-next-footer d-print-none"> 1033 1034<div class="prev-next-area"> 1035</div> 1036 </footer> 1037 1038 </div> 1039 1040 1041 1042 <dialog id="pst-secondary-sidebar-modal"></dialog> 1043 <div id="pst-secondary-sidebar" class="bd-sidebar-secondary bd-toc"><div class="sidebar-secondary-items sidebar-secondary__inner"> 1044 1045 1046 <div class="sidebar-secondary-item"><div 1047 id="pst-page-navigation-heading-2" 1048 class="page-toc tocsection onthispage"> 1049 <i class="fa-solid fa-list"></i> Contents 1050 </div> 1051 <nav id="pst-page-toc-nav" class="page-toc" aria-labelledby="pst-page-navigation-heading-2"> 1052 <ul class="pst-show_toc_level nav section-nav flex-column"> 1053<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#the-use-of-sssd">The use of sssd</a></li> 1054<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#kerberos">Kerberos</a></li> 1055<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#application-change-remote-user">Application change: REMOTE_USER</a></li> 1056<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#other-authentication-modules">Other authentication modules</a></li> 1057<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#host-and-service-based-access-control">Host and service based access control</a></li> 1058<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#hbac-rules">HBAC rules</a></li> 1059<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#pam-service">PAM service</a></li> 1060<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#mod-authnz-pam">mod_authnz_pam</a></li> 1061<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#overview">Overview</a></li> 1062<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#login-form-using-freeipa">Login form using FreeIPA</a></li> 1063<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#additional-user-information">Additional user information</a></li> 1064<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#namespace-separation">Namespace Separation</a></li> 1065<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#saml">SAML</a></li> 1066<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#references">References</a></li> 1067<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#openstack">OpenStack</a></li> 1068<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#spacewalk">Spacewalk</a></li> 1069<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite">Satellite</a></li> 1070<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman">Foreman</a></li> 1071<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite-6">Satellite 6</a></li> 1072<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#manageiq">ManageIQ</a></li> 1073<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#cloudforms">CloudForms</a></li> 1074<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#opendaylight">OpenDayLight</a></li> 1075<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#videos">Videos</a></li> 1076<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#using-os-level-identity-authentication-and-access-control-for-web-applications">Using OS-level identity, authentication, and access control for Web applications</a></li> 1077<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-in-red-hat-enterprise-linux-web-application-authentication-series">Identity management in Red Hat Enterprise Linux: Web Application Authentication Series</a></li> 1078<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#django">Django</a></li> 1079<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman-demo">Foreman demo</a></li> 1080<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#presentations">Presentations</a></li> 1081<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-and-federated-identities-on-the-web">External and Federated Identities on the Web</a></li> 1082<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#id1">Using OS-level identity, authentication, and access control for Web applications</a></li> 1083<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-identity-and-authentication-providers-for-apache-http-server">External Identity and Authentication Providers For Apache HTTP Server</a></li> 1084<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-scaling-out-and-up">Identity Management Scaling Out and Up</a></li> 1085<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-authentication-for-django-projects">External Authentication for Django Projects</a></li> 1086</ul> 1087 </nav></div> 1088 1089</div></div> 1090 1091 1092 </div> 1093 <footer class="bd-footer-content"> 1094 1095<div class="bd-footer-content__inner container"> 1096 1097 <div class="footer-item"> 1098 1099<p class="component-author"> 1100By FreeIPA Team 1101</p> 1102 1103 </div> 1104 1105 <div class="footer-item"> 1106 1107 1108 <p class="copyright"> 1109 1110 © Copyright 2023, FreeIPA Team. 1111 <br/> 1112 1113 </p> 1114 1115 </div> 1116 1117 <div class="footer-item"> 1118 1119 </div> 1120 1121 <div class="footer-item"> 1122 1123 </div> 1124 1125</div> 1126 </footer> 1127 1128 1129 </main> 1130 </div> 1131 </div> 1132 1133 <!-- Scripts loaded after <body> so the DOM is not blocked --> 1134
1134<script defer src="../_static/scripts/bootstrap.js?digest=90905a2f556bf617f1a9"></script>
vendor: 1 bytes, line 1134
1134
1135<script defer src="../_static/scripts/pydata-sphinx-theme.js?digest=90905a2f556bf617f1a9"></script>
1135 1136 1137 <footer class="bd-footer"> 1138 </footer> 1139 </body> 1140</html>
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.