How to Configure Remote File Access Single Sign On (SSO) with Kerberos Constrained Delegation (KCD) Before SP1 - PART 1 Created by forefrontsupport on 10/13/2010 9:39:10 PM Before you begin
If you don't any have prior experience with the Kerberos protocol (RFC 1510 - http://www.ietf.org/rfc/rfc1510.txt), please read this article from Wikipedia first Kerberos (Protocol) - http://en.wikipedia.org/wiki/Kerberos_protocol
If you have already knowledge with Kerberos Constrained Delegation (KCD), you can move forward to the next section.
If not, please read the upcoming short and exhaustive paper - What is Kerberos Constrained Delegation (KCD), how it works, and why it's good for me
Please watch the video before implementing File Access SSO (in the Screencasts section)
Important to know!
Microsoft IAG server is the only SSLVPN product in the market today that provides secure access to internal File Shares with Smart Card or OTP authentication, and also performs:
- FULL Single-Sign-On (SSO)
- FULL Audit trail of the end user to the back-end servers (IIS, SQL, AD etc ...)
- Granular Access Controls per users/groups
Prerequisites
- Microsoft Windows Server 2003 must run in Native mode for the domain in which Kerberos Constrained Delegation (KCD) is configured
- You must raise each domain controller's domain level to Windows Server 2003 Domain Functional Level
- You must configure KCD on your IAG server
Configuration Procedures
The following How-To document describe the procedures you need to perform to configure Single Sign On (SSO) for remote File Access
The following procedures must be implemented before you configure KCD on your IAG machine
- Configure the Domain Controller
- Add File Access application to the portal
- Configure the IIS server on the IAG server
- Configure the ISA Server Publishing Rule
Configure the Domain Controller
- Go to your Domain Controller and open "Active Directory Users and Computer" (start->run->dsa.msc)
Double click on the IAG computer account and navigate to Delegation tab and add the Computer Account (that you want to use its shares) and choose "cifs" service type

- Press Ok
Add File Access application to the portal
- Open the IAG Configuration manager
- Choose the relevant Trunk
On the Applications section click "Add"

- Choose "File Access" in the "Built-in Services" section
Press "Finish"

- Choose "Admin" in the tool bar
Choose "File Access"

- You will see the following message that you are going to open NETBIOS from the ISA Server to the back-end network
Press Ok

- The File Access administration window will open
Please enter Domain Credentials in the following syntax Domain\User

- Choose the relevant Domain (if you have more than one domain)
Press Apply

- Move forward to the "Servers" section
- Choose the relevant server
Press Apply

Please continue reading part 2 of this document to finish the configuration procedures
If you have any issues with File Access and KCD please go to our Technical Forums in the following link: http://Forums.ForefrontSecurity.ORG
