On Tue, Sep 05, 2017 at 11:16:03AM -0500, Kat via FreeIPA-users wrote:
> Hi all,
> 
> Looking to proxy some applications with a reverse proxy. Want to ingrate
> with IPA to do auth on the front end of the proxy so it passes kerberos
> tickets to the back-end applications. Any suggestions on which proxy would
> be best for this and integrating with IPA?
> 
Use Apache - the state of authentication / authorisation plugins
that can integrate with FreeIPA is much more advanced in Apache.

mod_auth_gssapi, mod_lookup_identity, mod_authnz_pam are the main
modules of interest.

HTH,
Fraser

> Just to clarify I am not trying to put a proxy in front of IPA UI as most of
> the writeups I have found refer to.
> 
> thanks
> 
> K
> _______________________________________________
> FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
> To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

Reply via email to