01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Kerberos<br />

Settings specifying the Kerberos method to authenticate users<br />

Authentication and access management<br />

Standard authentication 5<br />

Note: These settings are provided if you have selected the Kerberos authentication method and configured<br />

the settings for the Authentication module accordingly. The settings name can vary.<br />

Authentication Method<br />

Settings for selecting an authentication method<br />

For more information, see User Database.<br />

Kerberos Specific Parameters<br />

The specific settings of the parameters for the Kerberos authentication method are not configured as<br />

settings of the authentication module, but as settings of the appliance system.<br />

They can be accessed on the Appliances tab of the Configuration top-level menu under Kerberos<br />

Administration.<br />

After selecting Kerberos in the Authentication Method section of the Kerberos settings, you need to go<br />

to the Appliances tab and continue the configuration there.<br />

For more information, see Kerberos Administration system settings.<br />

Kerberos Administration system settings<br />

Settings for the Kerberos authentication method<br />

Key tab file — Input field for entering the file that contains the master key required to access the<br />

Kerberos server<br />

Note: You can type a file name or use the Browse button to browse to the file and enter its name in the field.<br />

When a ticket is issued for authentication according to the Kerberos method, the master key is read on<br />

the appliance and used to verify the ticket.<br />

If you are running a load balancer that directs web requests to the appliance, tickets are issued for the<br />

load balancer and verified on the appliance. It is then not checked whether a request is directed to the<br />

appliance.<br />

Kerberos realm — Administrative domain configured for authentication purposes<br />

Within the boundaries of this domain the Kerberos server has the authority to authenticate a user who<br />

submits a request from a host or using a service.<br />

Note: The realm name is case sensitive, however. normally only uppercase letters are used and it is good<br />

practice to make the realm name the same as that of the relevant DNS domain.<br />

Maximal time difference between appliance and client — Maximal time (in seconds) that the<br />

system clocks on the appliance and its clients are allowed to differ<br />

Note: Configuring Kerberos as the authentication method can lead to problems when particular browsers are<br />

used for sending requests:<br />

– When the Microsoft Internet Explorer is used in a version lower than 7.0, Kerberos authentication might not<br />

be possible at all.<br />

– When this explorer runs on Windows XP, Kerberos authentication might not work as expected.<br />

– When Mozilla Firefox is used, Kerberos authentication must be configured in the browser settings to enable<br />

this authentication method.<br />

Enable replay cache — When selected, a ticket that is issued for authentication cannot be used more<br />

than once<br />

Note: Selecting this option reduces authentication performance.<br />

Advanced Parameters<br />

The meaning and usage of these settings are the same as for the User Database settings.<br />

For more information, see User Database.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 135

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!