PageSourceSearch

https://www.freeipa.org/page/Web_App_Authentication

html freeipa.org collected 2026-09-24 08:28:05 UTC 61,934 bytes, 1,140 lines download raw bytes

1
2<!DOCTYPE html>
3
4
5<html lang="en" data-content_root="../" >
6
7  <head>
8    <meta charset="utf-8" />
9    <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
10
11    <title>Web_App_Authentication &#8212; FreeIPA  documentation</title>
12  
13  
14  
15  
15<script data-cfasync="false">
16    document.documentElement.dataset.mode = localStorage.getItem("mode") || "";
17    document.documentElement.dataset.theme = localStorage.getItem("theme") || "";
18  </script>
18
19  <!--
20    this give us a css class that will be invisible only if js is disabled
21  -->
22  <noscript>
23    <style>
24      .pst-js-only { display: none !important; }
25
26    </style>
27  </noscript>
28  
29  <!-- Loaded before other Sphinx assets -->
30  <link href="../_static/styles/theme.css?digest=90905a2f556bf617f1a9" rel="stylesheet" />
31<link href="../_static/styles/pydata-sphinx-theme.css?digest=90905a2f556bf617f1a9" rel="stylesheet" />
32
33    <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=8f2a1f02" />
34    <link rel="stylesheet" type="text/css" href="../_static/styles/sphinx-book-theme.css?v=4418a689" />
35  
36  <!-- So that users can add custom icons -->
37  
37<script defer src="../_static/scripts/fontawesome.js?digest=90905a2f556bf617f1a9"></script>
37
38  <!-- Pre-loaded scripts that we'll load fully later -->
39  <link rel="preload" as="script" href="../_static/scripts/bootstrap.js?digest=90905a2f556bf617f1a9" />
40<link rel="preload" as="script" href="../_static/scripts/pydata-sphinx-theme.js?digest=90905a2f556bf617f1a9" />
41
42    
42<script src="../_static/documentation_options.js?v=9eb32ce0"></script>
42
43    
43<script src="../_static/doctools.js?v=fd6eb6e6"></script>
43
44    
44<script src="../_static/sphinx_highlight.js?v=6ffebe34"></script>
44
45    
45<script src="../_static/scripts/sphinx-book-theme.js?v=fab101a9"></script>
45
46    
46<script>DOCUMENTATION_OPTIONS.pagename = 'page/Web_App_Authentication';</script>
46
47    
47<script>DOCUMENTATION_OPTIONS.search_as_you_type = false;</script>
47
48    <link rel="icon" href="../_static/favicon.png"/>
49    <link rel="index" title="Index" href="../genindex.html" />
50    <link rel="search" title="Search" href="../search.html" />
51  <meta name="viewport" content="width=device-width, initial-scale=1"/>
52  <meta name="docsearch:language" content="en"/>
53  <meta name="docsearch:version" content="" />
54  
55    
56    
56<script src="../_static/searchtools.js"></script>
56
57    
57<script src="../_static/language_data.js"></script>
57
58    
58<script src="../searchindex.js"></script>
58
59  
60  </head>
61  <body data-default-mode="">
62  
63  
64  <div id="pst-skip-link" class="skip-link d-print-none"><a href="#main-content">Skip to main content</a></div>
65
66  
67  <div id="pst-scroll-pixel-helper"></div>
68  
69  <button type="button" class="btn rounded-pill" id="pst-back-to-top">
70    <i class="fa-solid fa-arrow-up"></i>Back to top</button>
71  
72  
73  
74  
75  <dialog id="pst-search-dialog">
76    
77<form class="bd-search d-flex align-items-center"
78      action="../search.html"
79      method="get">
80  <i class="fa-solid fa-magnifying-glass"></i>
81  <input type="search"
82         class="form-control"
83         name="q"
84         placeholder="Search..."
85         aria-label="Search..."
86         autocomplete="off"
87         autocorrect="off"
88         autocapitalize="off"
89         spellcheck="false"/>
90  <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd>K</kbd></span>
91</form>
92  </dialog>
93
94  <div class="pst-async-banner-revealer d-none">
95  <aside id="bd-header-version-warning" class="d-none d-print-none" aria-label="Version warning"></aside>
96</div>
97
98  
99    <header id="pst-header" class="bd-header navbar navbar-expand-lg bd-navbar d-print-none">
100<div class="bd-header__inner bd-page-width">
101  <button class="pst-navbar-icon sidebar-toggle primary-toggle" aria-label="Site navigation">
102    <span class="fa-solid fa-bars"></span>
103  </button>
104  
105  
106  <div class="col-lg-9 navbar-header-items">
107    
108    
109    <div class="navbar-header-items__end">
110      
111        <div class="navbar-item navbar-persistent--container">
112          
113
114<button class="btn search-button-field search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip">
115 <i class="fa-solid fa-magnifying-glass"></i>
116 <span class="search-button__default-text">Search</span>
117 <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd class="kbd-shortcut__modifier">K</kbd></span>
118</button>
119        </div>
120      
121      
122    </div>
123    
124  </div>
125  
126  
127    <div class="navbar-persistent--mobile">
128
129<button class="btn search-button-field search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip">
130 <i class="fa-solid fa-magnifying-glass"></i>
131 <span class="search-button__default-text">Search</span>
132 <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd class="kbd-shortcut__modifier">K</kbd></span>
133</button>
134    </div>
135  
136
137  
138    <button class="pst-navbar-icon sidebar-toggle secondary-toggle" aria-label="On this page">
139      <span class="fa-solid fa-outdent"></span>
140    </button>
141  
142</div>
143
144    </header>
145  
146
147  <div class="bd-container">
148    <div class="bd-container__inner bd-page-width">
149      
150      
151      
152      <dialog id="pst-primary-sidebar-modal"></dialog>
153      <div id="pst-primary-sidebar" class="bd-sidebar-primary bd-sidebar">
154        
155
156  
157  <div class="sidebar-header-items sidebar-primary__section">
158    
159    
160    
161    
162  </div>
163  
164    <div class="sidebar-primary-items__start sidebar-primary__section">
165        <div class="sidebar-primary-item"><a class="navbar-brand logo" href="/">
166    <img src="https://raw.githubusercontent.com/freeipa/freeipa.github.io/main/src/_static/freeipa-logo-small.png" class="logo__image" alt="Logo image" />
167</a></div>
168        <div class="sidebar-primary-item">
169
170<button class="btn search-button-field search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip">
171 <i class="fa-solid fa-magnifying-glass"></i>
172 <span class="search-button__default-text">Search</span>
173 <span class="search-button__kbd-shortcut"><kbd class="kbd-shortcut__modifier">Ctrl</kbd>+<kbd class="kbd-shortcut__modifier">K</kbd></span>
174</button></div>
175        <div class="sidebar-primary-item"><div class="sidebar-primary-item">
176    <nav class="bd-links" id="bd-docs-nav" aria-label="Main">
177        <div class="bd-toc-item navbar-nav active">
178            <ul class="nav bd-sidenav">
179                <li class="toctree-l1"><a class="reference internal" href="/About.html">About</a></li>
180                <li class="toctree-l1"><a class="reference internal" href="/Contribute.html">
180Contribute</a></li>
181                <li class="toctree-l1"><a class="reference internal" href="/page/Documentation.html">Documentation</a></li>
182                <li class="toctree-l1"><a class="reference internal" href="/page/Troubleshooting.html">Troubleshooting</a></li>
183                <li class="toctree-l1"><a class="reference internal" href="/Downloads.html">Downloads</a></li>
184            </ul>
185        </div>
186    </nav>
187</div></div>
188    </div>
189  
190  
191  <div class="sidebar-primary-items__end sidebar-primary__section">
192      <div class="sidebar-primary-item">
193<div id="ethical-ad-placement"
194      class="flat"
195      data-ea-publisher="readthedocs"
196      data-ea-type="readthedocs-sidebar"
197      data-ea-manual="true">
198</div></div>
199  </div>
200
201
202      </div>
203      
204      <main id="main-content" class="bd-main" role="main">
205        
206        
207
208<div class="sbt-scroll-pixel-helper"></div>
209
210          <div class="bd-content">
211            <div class="bd-article-container">
212              
213              <div class="bd-header-article d-print-none">
214<div class="header-article-items header-article__inner">
215  
216    <div class="header-article-items__start">
217      
218        <div class="header-article-item"><button class="sidebar-toggle primary-toggle btn btn-sm" title="Toggle primary sidebar" data-bs-placement="bottom" data-bs-toggle="tooltip">
219  <span class="fa-solid fa-bars"></span>
220</button></div>
221      
222    </div>
223  
224  
225    <div class="header-article-items__end">
226      
227        <div class="header-article-item">
228
229<div class="article-header-buttons">
230
231
232
233
234
235<div class="dropdown dropdown-download-buttons">
236  <button class="btn dropdown-toggle" type="button" data-bs-toggle="dropdown" aria-expanded="false" aria-label="Download this page">
237    <i class="fas fa-download"></i>
238  </button>
239  <ul class="dropdown-menu">
240      
241      
242      
243      <li><a href="../_sources/page/Web_App_Authentication.rst" target="_blank"
244   class="btn btn-sm btn-download-source-button dropdown-item"
245   title="Download source file"
246   data-bs-placement="left" data-bs-toggle="tooltip"
247>
248  
249
250<span class="btn__icon-container">
251  <i class="fas fa-file"></i>
252  </span>
253<span class="btn__text-container">.rst</span>
254</a>
255</li>
256      
257      
258      
259      
260      <li>
261<button onclick="window.print()"
262  class="btn btn-sm btn-download-pdf-button dropdown-item"
263  title="Print to PDF"
264  data-bs-placement="left" data-bs-toggle="tooltip"
265>
266  
267
268<span class="btn__icon-container">
269  <i class="fas fa-file-pdf"></i>
270  </span>
271<span class="btn__text-container">.pdf</span>
272</button>
273</li>
274      
275  </ul>
276</div>
277
278
279
280
281<button onclick="toggleFullScreen()"
282  class="btn btn-sm btn-fullscreen-button pst-navbar-icon"
283  title="Fullscreen mode"
284  data-bs-placement="bottom" data-bs-toggle="tooltip"
285>
286  
287
288<span class="btn__icon-container">
289  <i class="fas fa-expand"></i>
290  </span>
291
292</button>
293
294
295
296<div class="theme-switch-container dropdown pst-js-only" data-bs-toggle="tooltip" data-bs-placement="bottom" title="Color mode">
297  <button class="btn btn-sm nav-link pst-navbar-icon theme-switch-button dropdown-toggle" aria-label="Color mode" data-bs-toggle="dropdown">
298    <i class="theme-switch fa-solid fa-sun fa-lg fa-fw" data-mode="light" title="Light"></i>
299    <i class="theme-switch fa-solid fa-moon fa-lg fa-fw" data-mode="dark" title="Dark"></i>
300    <i class="theme-switch fa-solid fa-circle-half-stroke fa-lg fa-fw" data-mode="auto" title="System Settings"></i>
301  </button>
302  <ul class="dropdown-menu dropdown-menu-end">
303    <li><button class="dropdown-item d-flex align-items-center theme-change-button" data-mode="auto"><i class="fa-solid fa-circle-half-stroke fa-lg fa-fw me-1"></i>System Settings</button></li>
304    <li><button class="dropdown-item d-flex align-items-center theme-change-button" data-mode="light"><i class="fa-solid fa-sun fa-lg fa-fw me-1"></i>Light</button></li>
305    <li><button class="dropdown-item d-flex align-items-center theme-change-button" data-mode="dark"><i class="fa-solid fa-moon fa-lg fa-fw me-1"></i>Dark</button></li>
306  </ul>
307</div>
308
309
310<button class="btn btn-sm pst-navbar-icon search-button search-button__button pst-js-only" title="Search" aria-label="Search" data-bs-placement="bottom" data-bs-toggle="tooltip">
311    <i class="fa-solid fa-magnifying-glass fa-lg"></i>
312</button>
313<button class="sidebar-toggle secondary-toggle btn btn-sm pst-navbar-icon" title="Toggle secondary sidebar" data-bs-placement="bottom" data-bs-toggle="tooltip">
314    <span class="fa-solid fa-list"></span>
315</button>
316</div></div>
317      
318    </div>
319  
320</div>
321</div>
322              
323              
324
325<div id="jb-print-docs-body" class="onlyprint">
326    <h1>Web_App_Authentication</h1>
327    <!-- Table of contents -->
328    <div id="print-main-content">
329        <div id="jb-print-toc">
330            
331            <div>
332                <h2> Contents </h2>
333            </div>
334            <nav aria-label="Page">
335                <ul class="pst-show_toc_level nav section-nav flex-column">
336<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#the-use-of-sssd">The use of sssd</a></li>
337<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#kerberos">Kerberos</a></li>
338<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#application-change-remote-user">Application change: REMOTE_USER</a></li>
339<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#other-authentication-modules">Other authentication modules</a></li>
340<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#host-and-service-based-access-control">Host and service based access control</a></li>
341<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#hbac-rules">HBAC rules</a></li>
342<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#pam-service">PAM service</a></li>
343<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#mod-authnz-pam">mod_authnz_pam</a></li>
344<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#overview">Overview</a></li>
345<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#login-form-using-freeipa">Login form using FreeIPA</a></li>
346<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#additional-user-information">Additional user information</a></li>
347<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#namespace-separation">Namespace Separation</a></li>
348<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#saml">SAML</a></li>
349<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#references">References</a></li>
350<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#openstack">OpenStack</a></li>
351<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#spacewalk">Spacewalk</a></li>
352<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite">Satellite</a></li>
353<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman">Foreman</a></li>
354<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite-6">Satellite 6</a></li>
355<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#manageiq">ManageIQ</a></li>
356<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#cloudforms">CloudForms</a></li>
357<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#opendaylight">OpenDayLight</a></li>
358<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#videos">Videos</a></li>
359<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#using-os-level-identity-authentication-and-access-control-for-web-applications">Using OS-level identity, authentication, and access control for Web applications</a></li>
360<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-in-red-hat-enterprise-linux-web-application-authentication-series">Identity management in Red Hat Enterprise Linux: Web Application Authentication Series</a></li>
361<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#django">Django</a></li>
362<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman-demo">Foreman demo</a></li>
363<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#presentations">Presentations</a></li>
364<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-and-federated-identities-on-the-web">External and Federated Identities on the Web</a></li>
365<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#id1">Using OS-level identity, authentication, and access control for Web applications</a></li>
366<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-identity-and-authentication-providers-for-apache-http-server">External Identity and Authentication Providers For Apache HTTP Server</a></li>
367<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-scaling-out-and-up">Identity Management Scaling Out and Up</a></li>
368<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-authentication-for-django-projects">External Authentication for Django Projects</a></li>
369</ul>
370            </nav>
371        </div>
372    </div>
373</div>
374
375              
376                
377<div id="searchbox"></div>
378                <article class="bd-article">
379                  
380  <section id="web-app-authentication">
381<h1>
381Web_App_Authentication<a class="headerlink" href="#web-app-authentication" title="Link to this heading">#</a></h1>
382<p>The typical web applications nowadays use HTTP
383<a class="reference external" href="http://en.wikipedia.org/wiki/HTTP_cookie">cookie</a>-based
384authentication sessions, usually with login-form to enter login and
385password pair which is then validated by the application against some
386internal user database. Session record is then created and cookie set,
387which the browser will send with each subsequent request to the
388application. The application can then show data related to the
389authenticated user (shopping cart content, user’s posts, stored files)
390throughout their work with the application.</p>
391<p>In large organizations and enterprise deployments, user identities are
392usually managed in some central manner. Many programming languages and
393frameworks provide libraries/modules to authenticate for example against
394<a class="reference external" href="http://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol">LDAP</a>
395sources. However, when the full complexity of enterprise setups is
396considered, including
397<a class="reference external" href="http://en.wikipedia.org/wiki/Kerberos_%28protocol%29">Kerberos</a>
398authentication, <a class="reference external" href="http://en.wikipedia.org/wiki/Failover">failovers</a>,
399use of <a class="reference external" href="http://en.wikipedia.org/wiki/Active_Directory">Active
400Directory</a>, and
401identity federation, it can be useful to offload the authentication
402support to solution independent on the application code or framework –
403<a class="reference external" href="http://en.wikipedia.org/wiki/Apache_HTTP_Server">Apache</a> modules,
404and where needed, <a class="reference external" href="https://fedorahosted.org/sssd/">System Security Services Daemon
405(sssd)</a>.</p>
406<p>With fairly minimal changes, web applications can consume the results of
407authentication performed by Apache modules, using the standard
408REMOTE_USER environment variable/attribute/method. If applications know
409how to handle the authentication result coming from the underlying
410(front end) web server, it is then just a matter of configuration of the
411web server to add access control to Kerberos authentication, federated
412authentication via SAML, or use central identity management server like
413FreeIPA to authenticate [login, password] values submitted by user to
414application’s native logon-form.</p>
415<p>If the application is then extended to understand <a class="reference external" href="Environment_Variables#Proposed_Additional_Variables">additional proposed
416environment
417variables</a>, it
418can receive not just the authentication and authorization result but
419also additional information about the user, for example email address or
420full name, typically needed by application to provide the full
421functionality and good user experience. With group membership
422information available to the application, the application can base its
423application-specific roles/access rights/authorization for the user
424based on the external user information, again without having to add
425support for all of them in the application or framework code directly.</p>
426<p>There is an <a class="reference external" href="Web_App_Authentication/Example_setup">example setup</a>
427accompanying this page which demonstrates the concepts described below
428on a trivial CGI application.</p>
429<p>We do not expect applications to drop their existing functionality that
430served them well, this is merely an additional possibility.</p>
431<section id="the-use-of-sssd">
432<h2>The use of sssd<a class="headerlink" href="#the-use-of-sssd" title="Link to this heading">#</a></h2>
433<p>The <a class="reference external" href="https://fedorahosted.org/sssd/">System Security Services Daemon
434(sssd)</a> is present as a standard part
435of the latest Red Hat Enterprise Linux, Fedora, and related
436distributions. It provides access to identity and authentication
437services and is primarily aimed at the operating system level. In this
438document, we will explore ways to use it for authentication and identity
439access of web applications, while preserving the distinction of the
440operating system and web application deployed on it.</p>
441<p>We will assume that the system on which the web application is deployed
442is IPA-enrolled. Using the command</p>
443<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">ipa</span><span class="o">-</span><span class="n">client</span><span class="o">-</span><span class="n">install</span>
444</pre></div>
445</div>
446<p>the local configuration of a couple of subsystems including sssd can be
447set up to point to a FreeIPA server. It also creates a host record on
448the server, making it possible to add services and get their Kerberos
449keytab.</p>
450<p>Services are important because they make it possible to have
451fine-grained control over a user’s access to the system. We might want
452to give a network administrator ssh access to the machine, but not
453access to the accounting system running on it. We might want to allow
454employees in the finance department to be able to access the accounting
455web application, but not ssh access to the underlying host.</p>
456</section>
457<section id="kerberos">
458<h2>Kerberos<a class="headerlink" href="#kerberos" title="Link to this heading">#</a></h2>
459<p>All contemporary web browsers support SPNEGO and Kerberos. When
460accessing <a class="reference external" href="http://server.example.com/">http://server.example.com/</a> or <a class="reference external" href="https://server.example.com/">https://server.example.com/</a>, the
461server can propose <strong>Negotiate</strong> authentication method. If the user
462currently has ticket granted ticket (obtained for example via <code class="docutils literal notranslate"><span class="pre">kinit</span></code>
463command), the brower will obtain Kerberos tickets for principal
464<a class="reference external" href="mailto:HTTP/server&#46;example&#46;com&#37;&#52;&#48;EXAMPLE&#46;COM">HTTP/server<span>&#46;</span>example<span>&#46;</span>com<span>&#64;</span>EXAMPLE<span>&#46;</span>COM</a> (as opposed to ssh which uses
465<a class="reference external" href="mailto:host/server&#46;example&#46;com&#37;&#52;&#48;EXAMPLE&#46;COM">host/server<span>&#46;</span>example<span>&#46;</span>com<span>&#64;</span>EXAMPLE<span>&#46;</span>COM</a>) and use related GSSAPI data to
466authenticate to the server.</p>
467<p>To enable this method on typical Apache installation,
468<strong>mod_auth_gssapi</strong> or <strong>mod_auth_kerb</strong> module needs to be <a class="reference external" href="Web_App_Authentication/Example_setup#Kerberos">installed
469and configured</a>.</p>
470</section>
471<section id="application-change-remote-user">
472<h2>Application change: REMOTE_USER<a class="headerlink" href="#application-change-remote-user" title="Link to this heading">#</a></h2>
473<p>The application then needs to be able to retrieve the result of the
474authentication, the login (principal) of the authenticated user. The
475standard mechanism for CGI deployments is via REMOTE_USER environment
476variable, and almost every web framework has a way to get this value
477from the web server, either via environment variable, attribute, or
478dedicated method call. (It’s the same value and mechanism used for the
479HTTP Basic Authentication.)</p>
480<p>The application not only needs to retrieve the value but its processing
481flow needs to be modified to trust this value. Note that this variable
482will not be set unless the admin deploying and setting up the
483application configured the underlying Apache correctly. For application
484developers it might be a step from having complete control over the
485internal user database to more uncertainty, having to trust that the
486external value is correct.</p>
487<p>Furthermore, many applications will need to have record for any
488authenticated user in its internal database, even for the externally
489(Kerberos) authenticated ones, for foreign keys to work. That is fine –
490the first time the application sees REMOTE_USER set to value it does not
491have in the database, it can create the user record in its internal
492database on the fly. That way, even if it uses object-relational
493mapping, the application will still work. (See below if the application
494requires that the user record has certain attributes besides login NOT
495NULL.)</p>
496</section>
497<section id="other-authentication-modules">
498<h2>Other authentication modules<a class="headerlink" href="#other-authentication-modules" title="Link to this heading">#</a></h2>
499<p>Besides Kerberos (with mod_auth_gssapi or mod_auth_kerb), there are
500other mechanisms that can be configured in Apache to authenticate:</p>
501<div class="pst-scrollable-table-container"><table class="table">
502<thead>
503<tr class="row-odd"><th class="head"><p>Authentication Method</p></th>
504<th class="head"><p>Apache Authentication Module</p></th>
505</tr>
506</thead>
507<tbody>
508<tr class="row-even"><td><p>Pure Application Level</p></td>
509<td><p><em>None</em></p></td>
510</tr>
511<tr class="row-odd"><td><p>Kerberos Single Sign-On (ticket)</p></td>
512<td><p>mod_auth_gssapi</p></td>
513</tr>
514<tr class="row-even"><td><p>mod_auth_kerb</p></td>
515<td></td>
516</tr>
517<tr class="row-odd"><td><p>SAML-based</p></td>
518<td><p>mod_auth_mellon</p></td>
519</tr>
520<tr class="row-even"><td><p>Certificate-based</p></td>
521<td><p>mod_nss</p></td>
522</tr>
523<tr class="row-odd"><td><p>mod_ssl</p></td>
524<td></td>
525</tr>
526<tr class="row-even"><td><p></p></td>
527<td></td>
528</tr>
529</tbody>
530</table>
531</div>
532</section>
533<section id="host-and-service-based-access-control">
534<h2>Host and service based access control<a class="headerlink" href="#host-and-service-based-access-control" title="Link to this heading">#</a></h2>
535<p>If mod_auth_gssapi/mod_auth_kerb is configured and application extended
536to consult and trust the REMOTE_USER value, it may have a potentially
537unwanted side effect – any user who is able to get the Kerberos ticket
538for <a class="reference external" href="mailto:HTTP/server&#46;example&#46;com&#37;&#52;&#48;EXAMPLE&#46;COM">HTTP/server<span>&#46;</span>example<span>&#46;</span>com<span>&#64;</span>EXAMPLE<span>&#46;</span>COM</a> would then be able to log into
539the application. If the application is only intended for small set of
540users and if any successful external authentication will populate user
541record in application’s database, that will pollute the database with
542users who have no access rights in the application yet manage to come
543across its URL and get authenticated.</p>
544<p>A possible solution is to apply access control check to the Kerberos
545authentication method on the Apache level. That way, even if the user is
546able to get the Kerberos ticket the authentication will still fail. For
547this to work, we will use Apache module <strong>mod_authnz_pam</strong>, configure
548PAM service to use pam_sss.so, hooking it via sssd to the FreeIPA
549server, and set up host-based access control (HBAC) rule in FreeIPA to
550separate service, to only give access to a particular set or group of
551users.</p>
552</section>
553<section id="hbac-rules">
554<h2>HBAC rules<a class="headerlink" href="#hbac-rules" title="Link to this heading">#</a></h2>
555<p>We will start from the end – from the FreeIPA HBAC service. It is just
556a string which distinguishes one service from another. Running</p>
557<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">ipa</span> <span class="n">hbacsvc</span><span class="o">-</span><span class="n">find</span>
558</pre></div>
559</div>
560<p>will show pre-created services like ssh, kdm, login, or kdm. Their names
561are then used to define the respective PAM service on the client – so
562for ssh, the configuration is in /etc/pam.d/ssh. If we are adding
563service for a reporting web application in our organization, we can name
564it <strong>reporting</strong> or <strong>reporting.example.com</strong> or <strong>reporting-prod</strong> and
565<strong>reporting-qa</strong> if we have multiple environments. Please consult help
566pages</p>
567<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">ipa</span> <span class="n">help</span> <span class="n">hbacsvc</span>
568<span class="n">ipa</span> <span class="n">help</span> <span class="n">hbacrule</span>
569<span class="n">ipa</span> <span class="n">help</span> <span class="n">hbactest</span>
570</pre></div>
571</div>
572<p>for detailed description of creating HBAC services and rules in FreeIPA.
573Please also note that you will probably need to <a class="reference external" href="Howto/HBAC_and_allow_all">disable the default
574allow_all HBAC rule</a> for the mechanism to
575work properly.</p>
576</section>
577<section id="pam-service">
578<h2>PAM service<a class="headerlink" href="#pam-service" title="Link to this heading">#</a></h2>
579<p>On the IPA-enrolled machine on which the web application is being
580configured, we need to define the PAM service to use sssd. We create
581file named the same as the HBAC service we’ve created with
582<code class="docutils literal notranslate"><span class="pre">ipa</span> <span class="pre">hbacsvc-add</span></code> and configure <code class="docutils literal notranslate"><span class="pre">pam_sss.so</span></code> for both auth and
583account. For example, if the HBAC service is <strong>reporting-prod</strong>, we will
584need file <strong>/etc/pam.d/reporting-prod</strong> with content</p>
585<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">auth</span>    <span class="n">required</span>   <span class="n">pam_sss</span><span class="o">.</span><span class="n">so</span>
586<span class="n">account</span> <span class="n">required</span>   <span class="n">pam_sss</span><span class="o">.</span><span class="n">so</span>
587</pre></div>
588</div>
589</section>
590<section id="mod-authnz-pam">
591<h2>mod_authnz_pam<a class="headerlink" href="#mod-authnz-pam" title="Link to this heading">#</a></h2>
592<p>The module <strong>mod_authnz_pam</strong> adds access control checks to
593authentication phase of HTTP request processing in Apache. The typical
594mod_auth_gssapi/mod_auth_kerb configuration will have</p>
595<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">require</span> <span class="n">valid</span><span class="o">-</span><span class="n">user</span>
596</pre></div>
597</div>
598<p>in it, saying that any authenticated user should be allowed. When we
599change it to <code class="docutils literal notranslate"><span class="pre">require</span> <span class="pre">pam-account</span> <span class="pre">PAM-service</span></code>, the user will only be
600authenticated by Apache if it matches the <code class="docutils literal notranslate"><span class="pre">account</span></code> check in PAM,
601which in case of <code class="docutils literal notranslate"><span class="pre">pam_sss.so</span></code> and sssd being configured to consult
602FreeIPA will lead to HBAC rule check, with the PAM service name used as
603the HBAC service. For our <strong>reporting-prod</strong> example, the
604<code class="docutils literal notranslate"><span class="pre">require</span> <span class="pre">valid-user</span></code> will change to</p>
605<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">require</span> <span class="n">pam</span><span class="o">-</span><span class="n">account</span> <span class="n">reporting</span><span class="o">-</span><span class="n">prod</span>
606</pre></div>
607</div>
608<p>We can even used different PAM services for different parts of the
609application, provided they can be identified using URLs. If the
610application has a special admin section, we can define separate PAM
611service (which possibly more strict rules) for this part:</p>
612<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="o">&lt;</span><span class="n">Location</span> <span class="o">/</span><span class="n">app</span><span class="o">&gt;</span>
613<span class="n">require</span> <span class="n">pam</span><span class="o">-</span><span class="n">account</span> <span class="n">reporting</span><span class="o">-</span><span class="n">prod</span>
614<span class="o">&lt;/</span><span class="n">Location</span><span class="o">&gt;</span>
615<span class="o">&lt;</span><span class="n">Location</span> <span class="o">/</span><span class="n">app</span><span class="o">/</span><span class="n">admin</span><span class="o">&gt;</span>
616<span class="n">require</span> <span class="n">pam</span><span class="o">-</span><span class="n">account</span> <span class="n">reporting</span><span class="o">-</span><span class="n">prod</span><span class="o">-</span><span class="n">admin</span>
617<span class="o">&lt;/</span><span class="n">Location</span><span class="o">&gt;</span>
618</pre></div>
619</div>
620</section>
621<section id="overview">
622<h2>Overview<a class="headerlink" href="#overview" title="Link to this heading">#</a></h2>
623<p>The <strong>mod_authnz_pam</strong> module can be configured with any other module
624which uses the <code class="docutils literal notranslate"><span class="pre">require</span></code> Apache directive. The deployment matrix then
625changes to:</p>
626<div class="pst-scrollable-table-container"><table class="table">
627<thead>
628<tr class="row-odd"><th class="head"><p>Authentication Method</p></th>
629<th class="head"><p>Apache Modules</p></th>
630</tr>
631</thead>
632<tbody>
633<tr class="row-even"><td><p>Authentication</p></td>
634<td><p>Access Control</p></td>
635</tr>
636<tr class="row-odd"><td><p>Pure Application Level</p></td>
637<td><p><em>None</em></p></td>
638</tr>
639<tr class="row-even"><td><p>Kerberos Single Sign-On (ticket)</p></td>
640<td><p>mod_auth_gssapi</p></td>
641</tr>
642<tr class="row-odd"><td><p>mod_auth_kerb</p></td>
643<td></td>
644</tr>
645<tr class="row-even"><td><p>SAML-based</p></td>
646<td><p>mod_auth_mellon</p></td>
647</tr>
648<tr class="row-odd"><td><p>Certificate-based</p></td>
649<td><p>mod_nss</p></td>
650</tr>
651<tr class="row-even"><td><p>mod_ssl</p></td>
652<td></td>
653</tr>
654<tr class="row-odd"><td><p></p></td>
655<td></td>
656</tr>
657</tbody>
658</table>
659</div>
660<p>Please consult the <a class="reference external" href="Web_App_Authentication/Example_setup#Host_.28and_service.29_based_access_control_for_Kerberos">example setup
661page</a>
662for detailed configuration steps.</p>
663</section>
664<section id="login-form-using-freeipa">
665<h2>Login form using FreeIPA<a class="headerlink" href="#login-form-using-freeipa" title="Link to this heading">#</a></h2>
666<p>In many situations, neither Kerberos nor any other authentication method
667which requires some additional setup on client’s side (like
668certificates) can be used or mandated, for practical reasons. Still, if
669the organization has a central user management in the form of FreeIPA,
670it can connect its existing applications to the FreeIPA authentication
671service, while retaining the application-specific look and feel of its
672login form. All that it takes for application is to understand the
673REMOTE_USER result of Apache authentication modules.</p>
674<p>The central authentication is achieved using the HBAC and PAM service
675described above, and Apache module <strong>mod_intercept_form_submit</strong>. The
676module can be configured to look at HTTP POST request resulting from
677user submitting application’s login form, and if login and password are
678found in the request, it will run PAM authentication and access control
679checks, using service specified with <code class="docutils literal notranslate"><span class="pre">InterceptFormPAMService</span></code>
680directive. The module internally calls mod_authnz_pam. When the service
681is properly configured to use <code class="docutils literal notranslate"><span class="pre">pam_sss.so</span></code> and sssd is configured to
682use FreeIPA, this form submit interception will validate the
683login/password pair, plus do the access control check like in the setup
684with Kerberos, described above.</p>
685<p>The successful result of this authentication is again passed using the
686REMOTE_USER mechanism. If application consults this value and trusts it,
687it will consider the user authenticated without checking its local user
688database.</p>
689<p>The failed authentication result is signalled to the application via
690environment variable EXTERNAL_AUTH_ERROR and applications are welcome to
691use this result indication.</p>
692<p>The proposed mix of authentication setups expands to</p>
693<div class="pst-scrollable-table-container"><table class="table">
694<thead>
695<tr class="row-odd"><th class="head"><p>Authentication Method</p></th>
696<th class="head"><p>Apache Modules</p></th>
697</tr>
698</thead>
699<tbody>
700<tr class="row-even"><td><p>Authentication</p></td>
701<td><p>Access Control</p></td>
702</tr>
703<tr class="row-odd"><td><p>Pure Application Level</p></td>
704<td><p><em>None</em></p></td>
705</tr>
706<tr class="row-even"><td><p>Kerberos Single Sign-On (ticket)</p></td>
707<td><p>mod_auth_gssapi</p></td>
708</tr>
709<tr class="row-odd"><td><p>mod_auth_kerb</p></td>
710<td></td>
711</tr>
712<tr class="row-even"><td><p>SAML-based</p></td>
713<td><p>mod_auth_mellon</p></td>
714</tr>
715<tr class="row-odd"><td><p>Certificate-based</p></td>
716<td><p>mod_nss</p></td>
717</tr>
718<tr class="row-even"><td><p>mod_ssl</p></td>
719<td></td>
720</tr>
721<tr class="row-odd"><td><p>Login form-based</p></td>
722<td><p>mod_intercept_form_submit</p></td>
723</tr>
724<tr class="row-even"><td><p></p></td>
725<td></td>
726</tr>
727</tbody>
728</table>
729</div>
730<p>The <a class="reference external" href="Web_App_Authentication/Example_setup#External_identities_for_login_form">example setup
731page</a>
732has more details about the configuration.</p>
733</section>
734<section id="additional-user-information">
735<h2>Additional user information<a class="headerlink" href="#additional-user-information" title="Link to this heading">#</a></h2>
736<p>The FreeIPA server can not only store plain login identities and
737passwords for authentication services, it can also hold additional user
738attributes like email addresses, phone numbers, or full names of users,
739as well as group membership. The sssd is then able to access this
740information and make it available to applications via new <strong>sssd-dbus</strong>
741package.</p>
742<p>Using Apache module <strong>mod_lookup_identity</strong> which can talk to sssd’s ifp
743service over dbus, any Apache module’s authenticated user can have
744additional environment variables populated from the central identity
745provider like FreeIPA. This can be used if the application requires that
746additional attributes are filled before storing the user in its internal
747database, or simply if the application makes use of such data. On the
748sssd side, the list of LDAP attributes that need to be retrieved and
749cached is specified, and then in mod_lookup_identity’s configuration,
750these attributes are mapped to environment variables.</p>
751<p>One type of data that the sssd-dbus calls provides is user’s group
752membership. This can be used to populate application-specific roles of
753the externally-authenticated user. Consider a situation when a newly
754hired network administrator is added to group <strong>netadmin</strong> in
755organization’s FreeIPA server. Module mod_lookup_identity is able to
756retrieve this group name and populate environment variable like
757REMOTE_USER_GROUP_N, REMOTE_USER_GROUP_1, …, or REMOTE_USER_GROUPS as
758colon-separated list. System management and provisioning application can
759hold internal mapping of the external group <strong>netadmin</strong> to its internal
760role and access control handling, making such a user automatically have
761appropriate privileges.</p>
762<p>When using the attributes to populate the database with
763externally-authenticated users, it is good to consider the case when
764user’s details or group membership in the central identity provider
765change. It might be useful to not only populate the user record when it
766is not found in application’s database the first time the user
767authenticates, but also compare and update the information every time
768the user authenticates, if needed. This is especially important if group
769membership is linked to application’s role handling.</p>
770<p>Populating of additional attributes, mapping of groups to roles, and
771update of this information in application’s database are therefore
772additional changes that the web application developers might consider
773adding to their application to make deployment of their application
774easier in large enterprise environment, without getting necessarily deep
775into the details of each possible identity provider which the
776organizations might use. The applications only need to assume that the
777environment variables (or whatever is the method of handling this
778information in its programming language or framework) might be populated
779by the HTTP daemon setup and its modules.</p>
780<p>It is also our hope that other modules that might have the additional
781user attributes available (like SAML) might populate the <a class="reference external" href="Environment_Variables#Proposed_Additional_Variables">proposed
782environment
783variables</a>
784directly, so even if the web application deployment does not use neither
785FreeIPA, sssd, nor any of the Apache modules mentioned on this page,
786effort that went into modifications of web applications can still be
787used.</p>
788<p>The <a class="reference external" href="Web_App_Authentication/Example_setup#Storing_external_users_in_internal_databases">example setup
789page</a>
790describes the sssd-dbus and mod_lookup_identity setup in more detail.</p>
791<p>The whole proposed solution for web application authentication using
792sssd:</p>
793<div class="pst-scrollable-table-container"><table class="table">
794<thead>
795<tr class="row-odd"><th class="head"><p>Authentication Method</p></th>
796<th class="head"><p>Apache Modules</p></th>
797</tr>
798</thead>
799<tbody>
800<tr class="row-even"><td><p>Authentication</p></td>
801<td><p>Access Control</p></td>
802</tr>
803<tr class="row-odd"><td><p>Pure Application Level</p></td>
804<td><p><em>None</em></p></td>
805</tr>
806<tr class="row-even"><td><p>Kerberos Single Sign-On (ticket)</p></td>
807<td><p>mod_auth_gssapi</p></td>
808</tr>
809<tr class="row-odd"><td><p>mod_auth_kerb</p></td>
810<td></td>
811</tr>
812<tr class="row-even"><td><p>SAML-based</p></td>
813<td><p>mod_auth_mellon</p></td>
814</tr>
815<tr class="row-odd"><td><p>Certificate-based</p></td>
816<td><p>mod_nss</p></td>
817</tr>
818<tr class="row-even"><td><p>mod_ssl</p></td>
819<td></td>
820</tr>
821<tr class="row-odd"><td><p>Login form-based</p></td>
822<td><p>mod_intercept_form_submit</p></td>
823</tr>
824<tr class="row-even"><td><p></p></td>
825<td></td>
826</tr>
827</tbody>
828</table>
829</div>
830<p>Note: sssd call also be configured to use different identity providers
831than FreeIPA but such setup is beyond the scope of this overview.</p>
832</section>
833<section id="namespace-separation">
834<h2>Namespace Separation<a class="headerlink" href="#namespace-separation" title="Link to this heading">#</a></h2>
835<p>In the above description we have assumed that the admin wants to handle
836all their application users with external authentication and that the
837set of user identities (locally created/managed and the
838externally-authenticated) overlap. Depending on the use case this might
839or might not be desirable. Consult <a class="reference external" href="Web_App_Authentication/Namespace_separation">Namespace
840separation</a> for possible
841setups with externally-authenticated users marked with &#64;REALM and
842multiple IPA server setups.</p>
843</section>
844<section id="saml">
845<h2>SAML<a class="headerlink" href="#saml" title="Link to this heading">#</a></h2>
846<p>As mentioned above, when the Web application / framework is amended to
847be able to process REMOTE_USER and REMOTE_USER_GROUP_* environment
848variables, it’s then just a matter of configuration of the front-end
849server to enable a particular mechanism of external authentication. For
850example, for SAML (Security Assertion Markup Language),
851<a class="reference external" href="https://github.com/UNINETT/mod_auth_mellon">mod_auth_mellon</a> can be
852used and starting with version 0.11.0, it can be configured to populate
853environment variables exactly like mod_lookup_identity does:</p>
854<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_GROUP"</span> <span class="s2">"groups"</span>
855<span class="n">MellonEnvVarsIndexStart</span> <span class="mi">1</span>
856<span class="n">MellonEnvVarsSetCount</span> <span class="n">On</span>
857</pre></div>
858</div>
859<p>and we can pass other attributes as well:</p>
860<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_LASTNAME"</span> <span class="s2">"surname"</span>
861<span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_FIRSTNAME"</span> <span class="s2">"givenname"</span>
862<span class="n">MellonSetEnvNoPrefix</span> <span class="s2">"REMOTE_USER_EMAIL"</span> <span class="s2">"email"</span>
863</pre></div>
864</div>
865</section>
866<section id="references">
867<h2>References<a class="headerlink" href="#references" title="Link to this heading">#</a></h2>
868</section>
869<section id="openstack">
870<h2>OpenStack<a class="headerlink" href="#openstack" title="Link to this heading">#</a></h2>
871<ul class="simple">
872<li><p>Nathan Kinder’s <a class="reference external" href="https://blog-nkinder.rhcloud.com/?p=130">https://blog-nkinder.rhcloud.com/?p=130</a></p></li>
873<li><p>Adam Young’s <a class="reference external" href="http://adam.younglogic.com/2015/03/key-fed-lookup-redux/">http://adam.younglogic.com/2015/03/key-fed-lookup-redux/</a></p></li>
874</ul>
875</section>
876<section id="spacewalk">
877<h2>Spacewalk<a class="headerlink" href="#spacewalk" title="Link to this heading">#</a></h2>
878<p>In Spacewalk 2.1, it is possible to use both the Kerberos
879authentication, and the form-based PAM authentication, including the
880HBAC management from FreeIPA and mapping of group membership from the
881identity provider to Spacewalk roles (access rights) – see
882<a class="reference external" href="https://fedorahosted.org/spacewalk/wiki/SpacewalkAndIPA">https://fedorahosted.org/spacewalk/wiki/SpacewalkAndIPA</a> for full
883documentation of the feature.</p>
884</section>
885<section id="satellite">
886<h2>Satellite<a class="headerlink" href="#satellite" title="Link to this heading">#</a></h2>
887<p>Based on Spacewalk upstream, the capability is now also available in
888Satellite 5.7 and documented in the <a class="reference external" href="https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/5.7/html/Installation_Guide/ch06s02.html">Using Identity Management for
889Authentication</a>
890chapter of the Installation Guide.</p>
891</section>
892<section id="foreman">
893<h2>Foreman<a class="headerlink" href="#foreman" title="Link to this heading">#</a></h2>
894<p>In Foreman 1.5, the external authentication is fully implemented as
895described on this page – see the <a class="reference external" href="http://projects.theforeman.org/issues/5031">tracking
896issue</a> with links to
897individual issues and pull requests that introduced the feature. It is
898now documented in <a class="reference external" href="http://theforeman.org/manuals/1.6/index.html#5.7ExternalAuthentication">Foreman
899manual</a>.</p>
900</section>
901<section id="satellite-6">
902<h2>Satellite 6<a class="headerlink" href="#satellite-6" title="Link to this heading">#</a></h2>
903<p>Based on Foreman upstream, the capability is now also available in
904Satellite 6.0:
905<a class="reference external" href="https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.1/html/User_Guide/sect-Using-I
905dM-for-Authentication.html">https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.1/html/User_Guide/sect-Using-IdM-for-Authentication.html</a></p>
906</section>
907<section id="manageiq">
908<h2>ManageIQ<a class="headerlink" href="#manageiq" title="Link to this heading">#</a></h2>
909<p>The support for external authentication is now in manageiq master:
910<a class="github reference external" href="https://github.com/ManageIQ/manageiq/commit/e0423c18d48380ff8d490ccb08291d2098fde69f">ManageIQ/manageiq</a>.
911The feature is configured by the console:
912<a class="github reference external" href="https://github.com/ManageIQ/manageiq/commit/cc6ea8b103a23bee5af8f9d88eac3024fc26cf18">ManageIQ/manageiq</a>,
913or manually:
914<a class="github reference external" href="https://github.com/ManageIQ/guides/blob/master/external_auth.md">ManageIQ/guides</a> and
915<a class="github reference external" href="https://github.com/ManageIQ/guides/blob/master/external_auth/configuration.md">ManageIQ/guides</a>.</p>
916</section>
917<section id="cloudforms">
918<h2>CloudForms<a class="headerlink" href="#cloudforms" title="Link to this heading">#</a></h2>
919<p>Based on the ManageIQ upstream, the capability is now also available in
920CFME 5.3 and documented in the
921<a class="reference external" href="https://access.redhat.com/documentation/en-US/Red_Hat_CloudForms/3.1/html/Management_Engine_5.3_Settings_and_Operations_Guide/chap-Configuration.html">Configuration</a>
922chapter of the Settings and Operations Guide.</p>
923</section>
924<section id="opendaylight">
925<h2>OpenDayLight<a class="headerlink" href="#opendaylight" title="Link to this heading">#</a></h2>
926<p><a class="reference external" href="https://jdennis.fedorapeople.org/doc/sssd_configuration.pdf">Federated Authentication Utilizing Apache &amp;
927SSSD</a> by
928John Dennis.</p>
929</section>
930<section id="videos">
931<h2>Videos<a class="headerlink" href="#videos" title="Link to this heading">#</a></h2>
932</section>
933<section id="using-os-level-identity-authentication-and-access-control-for-web-applications">
934<h2>Using OS-level identity, authentication, and access control for Web applications<a class="headerlink" href="#using-os-level-identity-authentication-and-access-control-for-web-applications" title="Link to this heading">#</a></h2>
935<ul class="simple">
936<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/os-auth-stack-for-web-applications">Presentation at DevConf
9372015</a>
938<a class="reference external" href="https://www.youtube.com/watch?v=Hhy5__C-XFc">https://www.youtube.com/watch?v=Hhy5__C-XFc</a>
939{{#ev:youtube|Hhy5__C-XFc}}
940Sadly, the first five minutes of the video are without sound.</p></li>
941</ul>
942</section>
943<section id="identity-management-in-red-hat-enterprise-linux-web-application-authentication-series">
944<h2>Identity management in Red Hat Enterprise Linux: Web Application Authentication Series<a class="headerlink" href="#identity-management-in-red-hat-enterprise-linux-web-application-authentication-series" title="Link to this heading">#</a></h2>
945<ul class="simple">
946<li><p>Part I: Current standard: logon forms and cookie-based sessions
947<a class="reference external" href="https://www.youtube.com/watch?v=Qdv8waOk6UE">https://www.youtube.com/watch?v=Qdv8waOk6UE</a>
948{{#ev:youtube|Qdv8waOk6UE}}</p></li>
949<li><p>Part II: Kerberos single sign-on
950<a class="reference external" href="https://www.youtube.com/watch?v=_We4O8OuJAY">https://www.youtube.com/watch?v=_We4O8OuJAY</a>
951{{#ev:youtube|_We4O8OuJAY}}</p></li>
952<li><p>Part III: Additional services of central identity provider
953<a class="reference external" href="https://www.youtube.com/watch?v=uG1rxZ4ydUE">
953https://www.youtube.com/watch?v=uG1rxZ4ydUE</a>
954{{#ev:youtube|uG1rxZ4ydUE}}</p></li>
955</ul>
956</section>
957<section id="django">
958<h2>Django<a class="headerlink" href="#django" title="Link to this heading">#</a></h2>
959<ul class="simple">
960<li><p>External Authentication for Django Projects
961<a class="reference external" href="https://www.youtube.com/watch?v=62_jD-8zV4M">https://www.youtube.com/watch?v=62_jD-8zV4M</a>
962{{#ev:youtube|62_jD-8zV4M}}</p></li>
963</ul>
964</section>
965<section id="foreman-demo">
966<h2>Foreman demo<a class="headerlink" href="#foreman-demo" title="Link to this heading">#</a></h2>
967<ul class="simple">
968<li><p>External authentication with and installer improvements, presented by
969Marek Hulán
970<a class="reference external" href="https://www.youtube.com/watch?v=S-8PESGbOUk#t=475">https://www.youtube.com/watch?v=S-8PESGbOUk#t=475</a>
971{{#ev:youtube|S-8PESGbOUk|||||#t=475}}</p></li>
972</ul>
973</section>
974<section id="presentations">
975<h2>Presentations<a class="headerlink" href="#presentations" title="Link to this heading">#</a></h2>
976</section>
977<section id="external-and-federated-identities-on-the-web">
978<h2>External and Federated Identities on the Web<a class="headerlink" href="#external-and-federated-identities-on-the-web" title="Link to this heading">#</a></h2>
979<ul class="simple">
980<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/external-and-federated-identities">ApacheCon Core Europe 2015
981presentation</a>
982(also as <a class="reference external" href="http://www.adelton.com/docs/idm/external-and-federated-identities.pdf">PDF
983slides</a>)</p></li>
984</ul>
985</section>
986<section id="id1">
987<h2>Using OS-level identity, authentication, and access control for Web applications<a class="headerlink" href="#id1" title="Link to this heading">#</a></h2>
988<ul class="simple">
989<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/os-auth-stack-for-web-applications">Developer Conference 2015
990presentation</a>
991(also as <a class="reference external" href="http://www.adelton.com/docs/idm/os-auth-stack-for-web-applications.pdf">PDF
992slides</a>)</p></li>
993</ul>
994</section>
995<section id="external-identity-and-authentication-providers-for-apache-http-server">
996<h2>External Identity and Authentication Providers For Apache HTTP Server<a class="headerlink" href="#external-identity-and-authentication-providers-for-apache-http-server" title="Link to this heading">#</a></h2>
997<ul class="simple">
998<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/apache-external-idm-auth">ApacheCon Europe 2014
999presentation</a>
1000(also as <a class="reference external" href="http://www.adelton.com/docs/idm/apache-external-idm-auth.pdf">PDF
1001slides</a>)</p></li>
1002</ul>
1003</section>
1004<section id="identity-management-scaling-out-and-up">
1005<h2>Identity Management Scaling Out and Up<a class="headerlink" href="#identity-management-scaling-out-and-up" title="Link to this heading">#</a></h2>
1006<ul class="simple">
1007<li><p><a class="reference external" href="http://www.adelton.com/docs/idm/idm-scaling-out-and-up">LinuxCon Europe 2014
1008presentation</a>
1009(also as <a class="reference external" href="http://www.adelton.com/docs/idm/idm-scaling-out-and-up.pdf">PDF
1010slides</a>)</p></li>
1011</ul>
1012</section>
1013<section id="external-authentication-for-django-projects">
1014<h2>External Authentication for Django Projects<a class="headerlink" href="#external-authentication-for-django-projects" title="Link to this heading">#</a></h2>
1015<ul class="simple">
1016<li><p><a class="reference external" href="http://www.adelton.com/django/external-authentication-for-django-projects">EuroPython 2015
1017presetnation</a>
1018(also as <a class="reference external" href="http://www.adelton.com/django/external-authentication-for-django-projects.pdf">PDF
1019slides</a>)</p></li>
1020</ul>
1021</section>
1022</section>
1023
1024
1025                </article>
1026              
1027
1028              
1029              
1030              
1031              
1032                <footer class="prev-next-footer d-print-none">
1033                  
1034<div class="prev-next-area">
1035</div>
1036                </footer>
1037              
1038            </div>
1039            
1040            
1041              
1042                <dialog id="pst-secondary-sidebar-modal"></dialog>
1043                <div id="pst-secondary-sidebar" class="bd-sidebar-secondary bd-toc"><div class="sidebar-secondary-items sidebar-secondary__inner">
1044
1045
1046  <div class="sidebar-secondary-item"><div
1047    id="pst-page-navigation-heading-2"
1048    class="page-toc tocsection onthispage">
1049    <i class="fa-solid fa-list"></i> Contents
1050  </div>
1051  <nav id="pst-page-toc-nav" class="page-toc" aria-labelledby="pst-page-navigation-heading-2">
1052    <ul class="pst-show_toc_level nav section-nav flex-column">
1053<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#the-use-of-sssd">The use of sssd</a></li>
1054<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#kerberos">Kerberos</a></li>
1055<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#application-change-remote-user">Application change: REMOTE_USER</a></li>
1056<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#other-authentication-modules">Other authentication modules</a></li>
1057<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#host-and-service-based-access-control">Host and service based access control</a></li>
1058<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#hbac-rules">HBAC rules</a></li>
1059<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#pam-service">PAM service</a></li>
1060<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#mod-authnz-pam">mod_authnz_pam</a></li>
1061<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#overview">Overview</a></li>
1062<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#login-form-using-freeipa">Login form using FreeIPA</a></li>
1063<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#additional-user-information">Additional user information</a></li>
1064<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#namespace-separation">Namespace Separation</a></li>
1065<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#saml">SAML</a></li>
1066<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#references">References</a></li>
1067<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#openstack">OpenStack</a></li>
1068<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#spacewalk">Spacewalk</a></li>
1069<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite">Satellite</a></li>
1070<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman">Foreman</a></li>
1071<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#satellite-6">Satellite 6</a></li>
1072<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#manageiq">ManageIQ</a></li>
1073<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#cloudforms">CloudForms</a></li>
1074<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#opendaylight">OpenDayLight</a></li>
1075<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#videos">Videos</a></li>
1076<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#using-os-level-identity-authentication-and-access-control-for-web-applications">Using OS-level identity, authentication, and access control for Web applications</a></li>
1077<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-in-red-hat-enterprise-linux-web-application-authentication-series">Identity management in Red Hat Enterprise Linux: Web Application Authentication Series</a></li>
1078<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#django">Django</a></li>
1079<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#foreman-demo">Foreman demo</a></li>
1080<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#presentations">Presentations</a></li>
1081<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-and-federated-identities-on-the-web">External and Federated Identities on the Web</a></li>
1082<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#id1">Using OS-level identity, authentication, and access control for Web applications</a></li>
1083<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-identity-and-authentication-providers-for-apache-http-server">External Identity and Authentication Providers For Apache HTTP Server</a></li>
1084<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#identity-management-scaling-out-and-up">Identity Management Scaling Out and Up</a></li>
1085<li class="toc-h2 nav-item toc-entry"><a class="reference internal nav-link" href="#external-authentication-for-django-projects">External Authentication for Django Projects</a></li>
1086</ul>
1087  </nav></div>
1088
1089</div></div>
1090              
1091            
1092          </div>
1093          <footer class="bd-footer-content">
1094            
1095<div class="bd-footer-content__inner container">
1096  
1097  <div class="footer-item">
1098    
1099<p class="component-author">
1100By FreeIPA Team
1101</p>
1102
1103  </div>
1104  
1105  <div class="footer-item">
1106    
1107
1108  <p class="copyright">
1109    
1110      © Copyright 2023, FreeIPA Team.
1111      <br/>
1112    
1113  </p>
1114
1115  </div>
1116  
1117  <div class="footer-item">
1118    
1119  </div>
1120  
1121  <div class="footer-item">
1122    
1123  </div>
1124  
1125</div>
1126          </footer>
1127        
1128
1129      </main>
1130    </div>
1131  </div>
1132  
1133  <!-- Scripts loaded after <body> so the DOM is not blocked -->
1134  
1134<script defer src="../_static/scripts/bootstrap.js?digest=90905a2f556bf617f1a9"></script>
vendor: 1 bytes, line 1134
1134
1135<script defer src="../_static/scripts/pydata-sphinx-theme.js?digest=90905a2f556bf617f1a9"></script>
1135
1136
1137  <footer class="bd-footer">
1138  </footer>
1139  </body>
1140</html>

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.