On Tue, Sep 05, 2017 at 11:16:03AM -0500, Kat via FreeIPA-users wrote: > Hi all, > > Looking to proxy some applications with a reverse proxy. Want to ingrate > with IPA to do auth on the front end of the proxy so it passes kerberos > tickets to the back-end applications. Any suggestions on which proxy would > be best for this and integrating with IPA? > Use Apache - the state of authentication / authorisation plugins that can integrate with FreeIPA is much more advanced in Apache.
mod_auth_gssapi, mod_lookup_identity, mod_authnz_pam are the main modules of interest. HTH, Fraser > Just to clarify I am not trying to put a proxy in front of IPA UI as most of > the writeups I have found refer to. > > thanks > > K > _______________________________________________ > FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org > To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org _______________________________________________ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org