I would like you to examine whether DW supports ADFS / SAML. Can for example be done by using WIF SDK from MS."
Developer forum
E-mail notifications
Single Sign-On
I would like you to examine whether DW supports ADFS / SAML. Can for example be done by using WIF SDK from MS."
Replies
It is possible though to implement it on a custom solution.
Hi,
I also have a request from a customer about what it would take to implement SSO using ADFS on their website.
Does anyone have any experience or recommendations regarding how to implement SSO via ADFS in a Dynamicweb solution?
Thanks.
Hi Christian
With Dynamicweb 8.5 we have released an integration to Active Directory where security groups and users are syncronoized to the webserver using a Service. When users on the website authenticates, they will be authenticated against the Service as well - so user login information is only handled by the AD. See preleminary documentation attached.
You can also integrate the ADFS service to the webserver itself and connect Dynamicweb directly to the local AD.
Hi,
The AD integrtion does it support SSO (Single sign-on)?
Thanks.
Hi Magnus
SSO can be 2 things:
- The same username and password from the same user store used in more places
- The user only logs in to his Windows machine and then the user does not have to login in other places, i.e. in the browser
Dynamicweb supports both - question is if you can get it up and running in your customers environment.
@1: Yes, no problem
@2: It is in theory possible but really difficult. The webserver has to be a member of the domain, you need to set up the website to use only Windows Authentication (meaning anonymous users cannot access the site), the application pool has to run under credentials that has permissions to talk to the AD (usually Network Services will do). Then you need to configure your browsers to include Windows Credentials for the website hostname, see i.e. https://www.liquidstate.net/enabling-ntlm-authentication-single-sign-on-in-firefox/.
It has to be setup for each browser on each users machine. It can be done for Chrome, Firefox and IE. Edge maybe. The settings can be distributed with AD policies if you have an AD administrator who knows hes way around policies.
When the browsers have been setup, it should work - in theory. But it all depends on permissions and policies on the machines, and sometimes it can give some issues.
If you do not change the browsers to include windows credentials automatically, users will be prompted to specify username and password when they visit the website. They can then mark the username/password to be stored by the browser.
BR Nicolai
Hej Nicolai,
Vi ønsker at implementere ADFS i vores hostede DynamicWeb.
Hvad skal der konkret til?
/Niels M. Thorsen
You must be logged in to post in the forum