Using Windows integrated authentication with CodeSign Protect clients
You can set up Windows authentication so users can automatically log in and access CodeSign Protect features once they have logged into Windows. No need for a user to authenticate specifically to CodeSign Protect if they already have logged in and have access on a Windows machine running the CodeSign Protect client.
Windows integrated authentication can be used for logging in to CodeSign Protect when your IIS server runs on a corporate network that is using Microsoft Active Directory service domain identities or other Windows accounts to identify users.
Prerequisites
-
Active Directory Identity Connector should be set up in Venafi Configuration Console.
- The Windows server that Trust Protection Platform is installed on and hosts the Web Console needs to be a member of the Active Directory Forest that you want to support for Windows Integrated Authentication.
- Windows Authentication must be installed as a role service of the web server role on the Windows machine.
To install Windows Authentication role services
- In Windows, click Start, and then click Administrative Tools, and then click Server Manager.
- In Server Manager, click the Manage menu, and then click Add Roles and Features.
- In the Add Roles and Features wizard, click Next.
- Select the installation type and click Next.
- Select the destination server and click Next.
-
On the Server Roles page, expand Web Server (IIS), expand Web Server, expand Security, and then select Windows Authentication.
- Click Next.
- On the Select features page, click Next.
- On the Confirm installation selections page, click Install.
- On the Results page, click Close.
To change the authentication mode to Windows
- Open the Internet Information Services (IIS) Manager.
- In the Connections pane, navigate to the Venafi server.
- Select VEDAuth.
-
Under Management, click Configuration Editor.
- In the Configuration Editor Window, in the Section drop-down, make sure system.web/authentication is selected.
-
In the Deepest Path group, Forms node, mode entry, use the drop-down to change the mode from None to Windows.
- Click Apply.
To enable Windows integrated authentication settings for CodeSign Protect
- Open the Internet Information Services (IIS) Manager.
-
In the Connections pane, navigate to the Venafi server, then select VEDAuth.
- Under IIS, click Authentication.
-
Set Anonymous Authentication and Windows Authentication to Enabled.
How users use Windows integrated authentication for CodeSign Protect logins
After setting up Windows integrated authentication, users can choose to log in with Windows credentials by checking the checkbox labeled Autologon using Windows credentials.