Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Client Certificate Mapping authentication using Active Directory across trusted forests

$
0
0

Hi,

We currently have a setup where the on-premises environment and the cloud environment are based on two separate forests linked by a 1-way trust, i.e., the exist in the on-premises AD and the 1-way trust allows them to use their credentials to login to a cloud domain joined server. This works fine with the Windows authentication.

We are now looking at implementing a 2-Factor authentication using Certificate. The PKI infrastructure exists in the On-Premises Forest. The users are able to successfully login to on-premise servers configured with "AD CLient Certificate Mapping".

However, we are unable to achieve the same functionality on the cloud domain joined servers. I would like to know

1. Is this possible?

2. If yes, what do we need to do to make this work.

Just to clarify, we are able to authenticate using certificates by enabling anonymous authentication. However, we are unable to do the same after turning on "Client Certificate Mapping authentication using Active Directory"


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>