Use a proxy server for authentication

The Intrexx Portal Manager can be connected to the Intrexx Portal Server via a proxy server. This is also possible if the Portal Manager and Portal Server are located on different networks.

Authentication Methods

You have three options for configuring authentication on the proxy server:

  • You can skip the authentication step

  • Basic Authentication

  • Kerberos Authentication

To enable a proxy server and specify the authentication method, go to the Portal Manager and select "Tools > Options" from the main menu.

You can also access the server using a Portable Portal Manager.

Advantages of a Proxy Server

Using a proxy server, you can insert an additional "layer of security" between Portal Manager and Portal Server. The proxy server can monitor communication between the Portal Manager and the Portal Server. You can define users who must first authenticate with the proxy server before they can access the portal server.

The login dialog is displayed only if you have selected the "Basic Authentication" option. When using Kerberos authentication, no separate login is required.

The proxy server described in this chapter ensures that a Portal Manager user is authenticated on the Portal Server.

In contrast, the front-end web server (reverse proxy) handles the authentication of portal users on the portal. See the following section: Using a Front-End Web Server (Reverse Proxy).

Restrictions

Please note that you can only use a proxy server for authentication if the proxy server is running on Linux.

Set Up a Proxy Server for Authentication

Step-by-Step

To set up a proxy server for authenticating a Portal Manager user on the Portal Server, follow these steps:

  1. In the main menu, click Tools > Options.

    The "Options" dialog box appears.

  2. In the left navigation pane, select "Proxy."

    The various options for configuring the proxy server are displayed in the right-hand pane.

    Name

    Description

    No proxy

    Select this option if you are not using a proxy server for authentication.

    This option is enabled by default.

    Apply the operating system's proxy settings

    Select this option if you want to use your operating system's proxy settings.

    Manually Configure the Proxy

    Select this option if you want to configure the proxy settings manually. You can then configure which authentication method should be used for the proxy.
    Proxy without authentication Select this option if you are using a proxy server and if authentication is not required on the proxy server.
    Proxy with Basic Authentication Select this option if you are using a proxy server and if the user authenticates with the proxy server using Basic authentication.

    Proxy with Kerberos Authentication

    Select this option if you are using a proxy server and if the user authenticates to the proxy server using Kerberos authentication. In this case, you can specify your own Kerberos configuration file (see below).

    Host

    Enter the proxy server's host here. This can be the IP address or the URL of the proxy server.

    Port

    Enter the proxy server's port here. Port 3128 is frequently used.

    No proxy for:

    If you are using a proxy but want to exclude certain hosts (e.g., within your company's internal network) from being accessed through the proxy, you can enter them here. Separate the individual hosts with a comma.

    Do not use the default Kerberos configuration file

    Select this checkbox if you want to use your own Kerberos configuration file to configure authentication on the proxy server.

    Kerberos configuration file

    Enter the path to the Kerberos configuration file here, or use the " " icon to locate the file.

  3. Select the desired option and fill in the required information.

  4. Click "OK."

  5. Restart the Portal Manager so that the settings you've made take effect.

    You have set up a proxy server for authentication.

    The next time you start the Intrexx Portal Manager, you will be prompted to enter your authentication credentials for the proxy server.

Logging In to the Proxy Server

After you have set up a proxy server with the "Basic Authentication" option, you will first be prompted to authenticate with the proxy server when you start the Intrexx Portal Manager.

Logging in to the Manager portal without authenticating with the proxy server

You can log in to the Intrexx Portal Manager even without logging in to the proxy server. This may be desirable in certain cases for tasks that do not require a connection to the portal server.

To do this, cancel the login dialog for the proxy server. Confirm the subsequent message by clicking "Yes." After that, do not connect to the portal server.

More Information

Objects, Classes, and Attributes

Create Object

The sections of the "Users" module

Options

User Groups and Users

Schema Manager

User Account

Filters in the Users module

Replication - Importing Users and Groups

Portal Login via Identity Provider