Skip to main content

2026년 3월 14일

Configure a Web Reverse Proxy for Identity Bridging (Certificate to Kerberos)

Configure the Unified Access Gateway bridging feature to provide single sign-on (SSO) to on-premises legacy non-SAML applications using certificate validation.

Prerequisites

Before starting the configuration process, make sure that you have the following files and certificates available:

See the relevant product documentation to generate the root and user certificates and the keytab file for non-SAML applications.

Ensure that TCP/UDP port 88 is open since Unified Access Gateway uses this port for Kerberos communication with Active Directory.

Procedure

  1. From Authentication Settings > X509 Certificate, go to:

    1. At Root and Intermediate CA certificate, click Select and upload the entire cert chain.

    2. Turn on the Enable Cert Revocation toggle.

    3. Select the check box for Enable OCSP Revocation.

    4. Enter the OCSP responder URL in the OCSP URL text box.

      Unified Access Gateway sends the OCSP request to the specified URL and receives a response that contains the information indicating if the certificate is revoked.

    5. Select the check box Use OCSP URL from certificate only if there is a use case to send the OCSP request to the OCSP URL in the client certificate. If this is not enabled, then it defaults to the value in the OCSP URL text box.

  2. From Advanced Settings > Identity Bridging Settings > OSCP settings, click Add.

    1. Click Select and upload the OCSP signing certificate.
  3. Select the Realm Settings gearbox icon and configure the Realm settings as described in Configure Realm Settings.

  4. From General Settings > Edge Service Settings, select the Reverse Proxy Settings gearbox icon.

  5. Turn on the Enable Identity Bridging Settings toggle, configure the following Identity Bridging settings, then click Save.

    OptionDescription
    Authentication TypesSelect CERTIFICATE from the drop-down menu.
    KeytabIn the drop-down menu, select the configured keytab for this reverse proxy.
    Target Service Principal NameEnter the Kerberos service principal name. Each principal is always fully qualified with the name of the realm. For example, myco_hostname@MYCOMPANY. Type the realm name in uppercase. If you do not add a name to the text box, the service principal name is derived from the host name of the proxy destination URL.
    User Header NameFor header-based authentication, enter the name of the HTTP header that includes the user ID derived from the assertion or use the default, AccessPoint-User-ID.

What to do next

When you use the Workspace ONE Web to access the target website, the target website acts as the reverse-proxy. Unified Access Gateway validates the presented certificate. If the certificate is valid, the browser displays the user interface page for the back-end application.

For specific error messages and troubleshooting information, see Identity Bridging Errors.

이 페이지가 도움이 되었나요?

이 항목에 대한 피드백 보내기

이 항목이 도움이 되었나요?

개인정보나 기밀정보는 입력하지 마세요.

링크를 생성하는 중…