• November 28, 2024

Authentication Proxy v5. 0 and later will use LDAP Signing and Encryption (or “”Sign and Seal””) if the domain controller allows it.

Frequently Asked Questions about If the transport type is CLEAR and the auth_type is ntlm2 (the proxy default) or sspi

Read More

your Active Directory server must be configured with an SSL certificate

Frequently Asked Questions about The proxy defaults to “”clear”” communication because not all Active Directory server configurations will support SSL/TLS out-of-the-box. To enable either “”ldaps”” or “”starttls””

Read More

by default)

Frequently Asked Questions about Open an unencrypted connection (to port 389

Read More

this will cause the proxy to contact your Active Directory server on port 636 rather than 389.

Frequently Asked Questions about Wrap the entire LDAP connection in SSL. Unless you specify a custom port

Read More

CN=… )(memberOf=CN=VPN

Frequently Asked Questions about ldap_filter=(|(memberOf=CN=Admin

Read More

OU=Groups

Frequently Asked Questions about security_group_dn=CN=DuoVPNUsers

Read More

host_4

Frequently Asked Questions about The hostname or IP address of a secondary/fallback domain controller. You can add additional domain controllers as host_3

Read More

DC=com

Frequently Asked Questions about search_dn=DC=example

Read More

see Encrypting Passwords and use service_account_password_protected instead.

Frequently Asked Questions about If you’re on Windows and would like to encrypt this password

Read More

which means you can have any mixture of [ad_client]

Frequently Asked Questions about Multiple client types may coexist in the same configuration file

Read More

append a number to the section name e. [ad_client2] or [radius_client2].

Frequently Asked Questions about Multiple server section configurations can use the same client section configuration. To configure more than one client configuration of the same type (in order to specify a different primary authentication source for some of your applications)

Read More

you will need to include one or more of the following configuration sections. These sections provide the proxy the information it needs to act as a client

Frequently Asked Questions about When deploying the Duo Authentication Proxy in order to service user authentications

Read More

then it cannot also act as an HTTP proxy for Duo applications itself.

Frequently Asked Questions about Note that if the Authentication Proxy is configured to use an upstream HTTP proxy

Read More

will be used for communicating with Duo Security’s service. Must support the CONNECT protocol.

Frequently Asked Questions about Hostname or IP address of an HTTP proxy. If set

Read More

the SIEM-consumable event entries do not redirect to syslog.

Frequently Asked Questions about Log to syslog when set to “”true””. Only available for Unix systems. 2 or later. If log_auth_events is enabled

Read More

the SIEM-consumable event entries do not redirect to stdout.

Frequently Asked Questions about Log to stdout when set to “”true””. If log_auth_events is enabled

Read More