Controlling web access through LDAP
This presentation is part of the Authentication Overview Self-Study Course.
Let’s look at a typical Web Access Management implementation with PRPC using CA SiteMinder. The same general mechanism applies to all off-the-shelf Web Access Management solutions.
- User Requests a protected resource – For example: http://www.mycorp.com/PRExtAuthServlet
- Web Agent examines request and queries Policy Server to determine if /PRExtAuthServlet is a protected resource. If so, Web Agent checks whether or not the user has been authenticated.
- If they have not been, the user is presented with the login form.
- The Policy Server passes the credentials to LDAP directory for authentication.
- If successful the Web Agent writes an encrypted cookie onto the user’s browser, which will identify the user to the web agent for subsequent requests.
- The Web Agent then queries the Policy Server to determine authorizations for the requested resource.
- The policies mandate that to access /PRExtAuthServlet/* the user must belong to the group PRPC_User or PRPC_WorkMgr (hypothetical)
- The Policy Server queries the directory to determine if the user is in one of the appropriate groups
- If so, the web agent caches the authorization and allows the request to pass through to the reverse proxy, appending customized http header variables containing the user ID, group name and other information about the user. The Reverse Proxy routes the request to the appropriate application server.
- The PRPC application generates the page and responds to the request.
- If needed, the PRPC application polls the LDAP Directory for additional user information.