Version Affected: All versions
Overview
This article explains how to configure a demilitarized zone (DMZ)-facing SecureAuth Identity Provider (IdP) realm to reach a datastore indirectly, through an internal IdP realm, using a Web Service connection. In an environment with separate IdP servers for internal and external traffic, this configuration removes the direct datastore connection from the externally-facing (DMZ) server: the DMZ realm authenticates users by connecting to an internal realm's Data tab configuration instead of connecting to the datastore itself, adding an extra layer of security.
Configure the DMZ Web Service Realm
- From the DMZ IdP server, confirm network connectivity to the internal IdP server: open a browser on the DMZ server and browse to the internal server by host name or IP address.
- Confirm a trusted SSL connection to the internal IdP server: browse to it by host name and confirm there are no certificate errors. Without a successful SSL connection, the Web Service realm returns an invalid user error on login. By default, SecureAuth appliances use appliance certificates in their IIS site bindings, which are not publicly trusted — as a workaround, add the internal server's appliance certificate name to the DMZ server's hosts file to establish trust.
- On an internal IdP realm, configure a Data tab connection to the desired datastore, per the Web Service (Multi-Data Store) Configuration Guide.
- On the DMZ IdP server, create (or configure) the Web Service realm and use the Add Realm from Another Server option to list the internal realm that has the desired Data tab configuration, for example https://YourDomainName.com/SecureAuth# or https://YourDomainName.com/SecureAuth#/webservice/membershipws.svc.
- On the internal server, configure the listed realm's FBA WebService section under the Workflow tab.
The screenshot below shows Internet Explorer displaying a certificate error in the address bar when browsing to the internal IdP server by IP address instead of host name.
The screenshot below shows the same login page loading with no certificate error once the DMZ server instead browses to the internal IdP server by host name, confirming that trust has been established.
Once configured, the Web Service realm on the DMZ server is functional: its own settings are configured like any other realm, but its Data tab information is sourced from the internal realm(s) it lists, so the DMZ server never connects to the datastore directly.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.