Setting up IWA using PingFederate
About this task
Set up an application to be protected with Kerberos authentication using PingFederate’s Kerberos Adapter, while PingFederate is protected by PingAccess:
Steps
-
Configure your Kerberos adapter in PingFederate.
For more information, see Configure a Kerberos adapter instance in the PingFederate documentation.
-
Add a new site in PingAccess.
-
Go to Applications → Sites and click Add Site.
-
In the Name field, enter a desired name for the site.
-
In the Targets field, enter one or more hostname:port pairs for the site.
The host and port to point to PingFederate on port
9031
. -
Click Save.
For more information, see Adding sites.
-
-
Add a new application in PingAccess.
-
Go to Applications → Applications and click Add Application.
-
In the Name field, enter a desired name for the site.
-
In the Context Root field, specify the first part of the URL path for the application and its resources.
-
In the Virtual Host field, enter the host desired for the target application.
-
In the Destination list, select Site.
-
In the Site list, select the PingFederate site previously created.
-
Configure the remaining fields as desired. Click Save.
For more information, see Adding an application.
-
-
Enable the application.
Result:
The protected application can utilize the Kerberos protocol for authentication through PingAccess, using PingFederate.