

Agent for Windows Authentication Guide › Introduction to the Federation Agent for Windows Authentication › Kerberos Protocol
Kerberos Protocol
The following illustration shows how CA SiteMinder® Federation Standalone and the Federation Agent Agent use the Kerberos protocol:

The following process references annotations in the preceding diagram:
- An authentication request is made to the federation system at the asserting party.
The federation system recognizes that this request is a delegated authentication request.
- CA SiteMinder® Federation Standalone redirects to the Federation Agent.
- The Federation Agent requests an HTTP authorization from the browser.
- If the browser is configured for IWA, it sends a SPNEGO token to the Federation Agent. This token allows initiators and acceptors to negotiate whether to use Kerberos or NTLM.
- The Federation Agent extracts a Kerberos token from the SPNEGO token.
- After the security context is established from the Kerberos token, the Agent retrieves the user identity information.
- The Agent creates the open format cookie and builds a redirect URL.
- The Agent sends the cookie to the federation system.
- CA SiteMinder® Federation Standalone does the required processing and sends an assertion to the relying party.
Copyright © 2013 CA.
All rights reserved.
 
|
|