When the Kerberos Auth service is installed on an Omnissa Access connector, you enable and configure the Kerberos authentication method from the Omnissa Access console. You then add the Workspace IDP identity provider and associate the Kerberos authentication method in the identity provider.
Prerequisites
The Kerberos Auth services must be correctly configured in the Omnissa Access connector. A correct configuration includes the following.
- The Windows machine on which the Kerberos Auth service is installed must be joined to the domain.
- During the installation of the Kerberos Auth service, you specified the domain user account to use to run the service. This domain user is part of the administrator group on the Windows machine on which the service is installed.
- A trusted SSL certificate signed by a public or internal CA was uploaded. If you deployed multiple instances of the Kerberos Auth service for high availability, a trusted SSL certificate signed by a public or internal CA was uploaded to each connector.
- Kerberos Auth services requires an inbound connection to the connector on port TCP 443.
- To set up high availability for Kerberos authentication, a load balancer is required. The load balancer must have a trusted SSL certificate signed by a public or internal CA. See the Installing the Omnissa Access Connector guide for configuration information.
Procedure
-
In the Omnissa Access console Integrations > Connector Authentication Methods page, click NEW and select Kerberos.
-
Select the Directory and the Service Host to configure with this authentication method.
Important: If you specify multiple connector hosts, make sure that all the connectors are version 22.09 or later. The Kerberos Auth service does not support mixing earlier versions with 22.09 or later versions.
-
Configure the Kerberos authentication method settings.
Option Description Directory UID Attribute Enter the account attribute that contains the user name. Enable Redirect Enable Redirectdisplays if redirect is enabled because you are deploying multiple connectors configured with the Kerberos Auth service for high availability with a load balancer. -
Click NEXT to review the configuration and then click SAVE.
What to do next
In the Identity Provider page, add the Workspace IDP identity provider and associate the Kerberos Authentication method with it. See Configure Workspace Identity Provider Instance with Kerberos Authentication in Omnissa Access.
Add the authentication method to the default access policy in the Resources > Policies page and edit the default policy rules to add the Kerberos authentication method to the rule in the correct authentication order, with Password authentication (cloud) configured as the fallback authentication method. See Managing Access Policies in the Omnissa Access Service.
If high availability is configured, on each connector, configure the Kerberos authentication method for the Kerberos Authentication service.
Related information
Configuring your Browser for Kerberos Authentication in Omnissa Access
Was this page helpful?