Using Windows integrated authentication with Code Sign Manager - Self-Hosted clients
You can set up Windows authentication so users can automatically log in and access Code Sign Manager - Self-Hosted features once they have logged into Windows. No need for a user to authenticate specifically to Code Sign Manager - Self-Hosted if they already have logged in and have access on a Windows machine running the Code Sign Manager - Self-Hosted client.
Windows integrated authentication can be used for logging in to Code Sign Manager - Self-Hosted when your IIS server runs on a corporate network that is using Microsoft Active Directory service domain identities or other Windows accounts to identify users.
Prerequisites
-
Active Directory Identity Connector should be set up in CyberArk Configuration Console.
- The Windows server that Trust Protection Foundation is installed on and hosts the Web Console needs to be a member of the Active Directory Forest that you want to support for Windows Integrated Authentication.
- Windows Authentication must be installed as a role service of the web server role on the Windows machine.
To install Windows Authentication role services
- In Windows, click Start, and then click Administrative Tools, and then click Server Manager.
- In Server Manager, click the Manage menu, and then click Add Roles and Features.
- In the Add Roles and Features wizard, click Next.
- Select the installation type and click Next.
- Select the destination server and click Next.
-
On the Server Roles page, expand Web Server (IIS), expand Web Server, expand Security, and then select Windows Authentication.
- Click Next.
- On the Select features page, click Next.
- On the Confirm installation selections page, click Install.
- On the Results page, click Close.
To change the authentication mode to Windows
- Open the Internet Information Services (IIS) Manager.
- In the Connections pane, navigate to the Venafi server.
- Select VEDAuth.
-
Under Management, click Configuration Editor.
- In the Configuration Editor Window, in the Section drop-down, make sure system.web/authentication is selected.
-
In the Deepest Path group, Forms node, mode entry, use the drop-down to change the mode from None to Windows.
- Click Apply.
To enable Windows integrated authentication settings for Code Sign Manager - Self-Hosted
- Open the Internet Information Services (IIS) Manager.
-
In the Connections pane, navigate to the Venafi server, then select VEDAuth.
- Under IIS, click Authentication.
-
Set Anonymous Authentication and Windows Authentication to Enabled.
How users use Windows integrated authentication for Code Sign Manager - Self-Hosted logins
After setting up Windows integrated authentication, users can choose to log in with Windows credentials by checking the checkbox labeled Autologon using Windows credentials.