Reverse Proxy single sign-on The Next CEO of Stack OverflowApache reverse proxy access controlProtocol switching with reverse proxy and application server with static linksWhen Using Reverse Proxy, Backend Server Does 301 Back to The Proxy Server or Changes URLReverse proxy with single sign-on and backend authentication modulesConfiguring Apache reverse proxyLightweight reverse http proxy with websocket supportReverse Proxy and requested URL aware tomcatBasic auth Apache with TomcatTry to reverse-proxy vsphere webclient with Apache
Why didn't Khan get resurrected in the Genesis Explosion?
Several mode to write the symbol of a vector
How do scammers retract money, while you can’t?
How powerful is the invisibility granted by the Gloom Stalker ranger's Umbral Sight feature?
Can I equip Skullclamp on a creature I am sacrificing?
How do I transpose the 1st and -1th levels of an arbitrarily nested array?
sp_blitzCache results Memory grants
What can we do to stop prior company from asking us questions?
Is micro rebar a better way to reinforce concrete than rebar?
If a black hole is created from light, can this black hole then move at speed of light?
How did people program for Consoles with multiple CPUs?
Return the Closest Prime Number
Has this building technique been used in an official set?
Would a galaxy be visible from outside, but nearby?
What benefits would be gained by using human laborers instead of drones in deep sea mining?
Is there an analogue of projective spaces for proper schemes?
In excess I'm lethal
How to avoid supervisors with prejudiced views?
Why do remote companies require working in the US?
What does "Its cash flow is deeply negative" mean?
Bold, vivid family
What's the best way to handle refactoring a big file?
Is it ever safe to open a suspicious html file (e.g. email attachment)?
Should I tutor a student who I know has cheated on their homework?
Reverse Proxy single sign-on
The Next CEO of Stack OverflowApache reverse proxy access controlProtocol switching with reverse proxy and application server with static linksWhen Using Reverse Proxy, Backend Server Does 301 Back to The Proxy Server or Changes URLReverse proxy with single sign-on and backend authentication modulesConfiguring Apache reverse proxyLightweight reverse http proxy with websocket supportReverse Proxy and requested URL aware tomcatBasic auth Apache with TomcatTry to reverse-proxy vsphere webclient with Apache
I have a reverse proxy handling ssl termination and mod_security. The issue is after sso reaches the backend server it tries to authenticate with cas directly instead of the through the proxy still, and since the backend server is inside our firewall, and only the proxy is in cas the authentication fails.
current configuration for reverse proxy:
<Location /test/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass /TEST/ http://backend.server.com:7010/
ProxyPassReverse http://backend.server.com:7010/
ProxyHTMLURLMap http://backend.server.com:7010
Order allow,deny
Allow from all
</Location>
<Location /sso/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass http://backend.server.com:7007/sso/
ProxyPassReverse http://backend.server.com:7007/sso/
ProxyHTMLURLMap http://backend.server.com.edu:7007/sso
Order allow,deny
Allow from all
It there some setting i am missing that causes the backend server to not continue with using the proxy name?
reverse-proxy single-sign-on cas
bumped to the homepage by Community♦ yesterday
This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.
add a comment |
I have a reverse proxy handling ssl termination and mod_security. The issue is after sso reaches the backend server it tries to authenticate with cas directly instead of the through the proxy still, and since the backend server is inside our firewall, and only the proxy is in cas the authentication fails.
current configuration for reverse proxy:
<Location /test/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass /TEST/ http://backend.server.com:7010/
ProxyPassReverse http://backend.server.com:7010/
ProxyHTMLURLMap http://backend.server.com:7010
Order allow,deny
Allow from all
</Location>
<Location /sso/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass http://backend.server.com:7007/sso/
ProxyPassReverse http://backend.server.com:7007/sso/
ProxyHTMLURLMap http://backend.server.com.edu:7007/sso
Order allow,deny
Allow from all
It there some setting i am missing that causes the backend server to not continue with using the proxy name?
reverse-proxy single-sign-on cas
bumped to the homepage by Community♦ yesterday
This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.
add a comment |
I have a reverse proxy handling ssl termination and mod_security. The issue is after sso reaches the backend server it tries to authenticate with cas directly instead of the through the proxy still, and since the backend server is inside our firewall, and only the proxy is in cas the authentication fails.
current configuration for reverse proxy:
<Location /test/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass /TEST/ http://backend.server.com:7010/
ProxyPassReverse http://backend.server.com:7010/
ProxyHTMLURLMap http://backend.server.com:7010
Order allow,deny
Allow from all
</Location>
<Location /sso/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass http://backend.server.com:7007/sso/
ProxyPassReverse http://backend.server.com:7007/sso/
ProxyHTMLURLMap http://backend.server.com.edu:7007/sso
Order allow,deny
Allow from all
It there some setting i am missing that causes the backend server to not continue with using the proxy name?
reverse-proxy single-sign-on cas
I have a reverse proxy handling ssl termination and mod_security. The issue is after sso reaches the backend server it tries to authenticate with cas directly instead of the through the proxy still, and since the backend server is inside our firewall, and only the proxy is in cas the authentication fails.
current configuration for reverse proxy:
<Location /test/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass /TEST/ http://backend.server.com:7010/
ProxyPassReverse http://backend.server.com:7010/
ProxyHTMLURLMap http://backend.server.com:7010
Order allow,deny
Allow from all
</Location>
<Location /sso/>
ProxyPreserveHost on
RequestHeader set WL-Proxy-SSL true
ProxyPass http://backend.server.com:7007/sso/
ProxyPassReverse http://backend.server.com:7007/sso/
ProxyHTMLURLMap http://backend.server.com.edu:7007/sso
Order allow,deny
Allow from all
It there some setting i am missing that causes the backend server to not continue with using the proxy name?
reverse-proxy single-sign-on cas
reverse-proxy single-sign-on cas
asked May 28 '15 at 17:22
Rory McDonaldRory McDonald
262
262
bumped to the homepage by Community♦ yesterday
This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.
bumped to the homepage by Community♦ yesterday
This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
Most applications I've seen that support being behind a load balancer or reverse proxy have a setting such as "base URL" that you can set to the front end's URL. This allows the application to create the proper hyperlinks in itself and things like mail notifications.
The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of.
– Rory McDonald
Jun 15 '15 at 21:20
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f695073%2freverse-proxy-single-sign-on%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Most applications I've seen that support being behind a load balancer or reverse proxy have a setting such as "base URL" that you can set to the front end's URL. This allows the application to create the proper hyperlinks in itself and things like mail notifications.
The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of.
– Rory McDonald
Jun 15 '15 at 21:20
add a comment |
Most applications I've seen that support being behind a load balancer or reverse proxy have a setting such as "base URL" that you can set to the front end's URL. This allows the application to create the proper hyperlinks in itself and things like mail notifications.
The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of.
– Rory McDonald
Jun 15 '15 at 21:20
add a comment |
Most applications I've seen that support being behind a load balancer or reverse proxy have a setting such as "base URL" that you can set to the front end's URL. This allows the application to create the proper hyperlinks in itself and things like mail notifications.
Most applications I've seen that support being behind a load balancer or reverse proxy have a setting such as "base URL" that you can set to the front end's URL. This allows the application to create the proper hyperlinks in itself and things like mail notifications.
answered May 28 '15 at 18:40
Ryan BolgerRyan Bolger
14.1k23051
14.1k23051
The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of.
– Rory McDonald
Jun 15 '15 at 21:20
add a comment |
The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of.
– Rory McDonald
Jun 15 '15 at 21:20
The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of.
– Rory McDonald
Jun 15 '15 at 21:20
The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of.
– Rory McDonald
Jun 15 '15 at 21:20
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f695073%2freverse-proxy-single-sign-on%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown