<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Putting Token Login to work</title>
	<atom:link href="http://pasamio.com/2009/02/22/putting-token-login-to-work/feed/" rel="self" type="application/rss+xml" />
	<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/</link>
	<description>Sam Moffatt's Tech Blog: Writings on Technology</description>
	<lastBuildDate>Mon, 06 Feb 2012 19:31:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: pasamio</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-51479</link>
		<dc:creator>pasamio</dc:creator>
		<pubDate>Sat, 17 Dec 2011 04:21:37 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-51479</guid>
		<description>You could use the library to build a component similar to the one that I released to batch provision tokens. There isn&#039;t a way in the provided applications  as it really isn&#039;t designed to be created manually but via a scripted process (e.g. when you mail something or by providing a link in the site).</description>
		<content:encoded><![CDATA[<p>You could use the library to build a component similar to the one that I released to batch provision tokens. There isn&#8217;t a way in the provided applications  as it really isn&#8217;t designed to be created manually but via a scripted process (e.g. when you mail something or by providing a link in the site).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-51456</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Fri, 16 Dec 2011 09:14:50 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-51456</guid>
		<description>Hi,

sorry to bring this up after a while. But is there a way in batch creating tokens? With a few hundred logins you cannot create the token manually.

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>sorry to bring this up after a while. But is there a way in batch creating tokens? With a few hundred logins you cannot create the token manually.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pasamio</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-9270</link>
		<dc:creator>pasamio</dc:creator>
		<pubDate>Fri, 15 May 2009 14:06:56 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-9270</guid>
		<description>The only items that matter are the modules, the System - Single Sign On and any component that hooks into the SSO system (tokenlogin in part, com_sso and any other component that hooks in such as the component written in this tutorial).

It seems a bit strange, I&#039;m not quite sure what the answer is without digging around and having a look through things. I think I need to clone myself :S</description>
		<content:encoded><![CDATA[<p>The only items that matter are the modules, the System &#8211; Single Sign On and any component that hooks into the SSO system (tokenlogin in part, com_sso and any other component that hooks in such as the component written in this tutorial).</p>
<p>It seems a bit strange, I&#8217;m not quite sure what the answer is without digging around and having a look through things. I think I need to clone myself :S</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yellen</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-9269</link>
		<dc:creator>yellen</dc:creator>
		<pubDate>Fri, 15 May 2009 13:58:42 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-9269</guid>
		<description>I didn&#039;t mention it in my previous message, but Firefox gives the same results.

From what you just said, it could occur because of some duplicate SSO system? Maybe this is the problem. What I am trying to do is have the HTTP authtentication enabled with group mapping. There are no non-AD users. I&#039;ve enabled the following Authentication Plugins and Modules:
&gt;&gt;&gt; Plugins
- Authentication - Joomla
- Authentication - LDAP
- Authentication - Advanced LDAP
- SSO - HTTP
- System - JAuthTools Synchronization Plugin
- System - Single Sign On
- User - Joomla!
- User Source - LDAP
- User Source - Session
&gt;&gt;&gt; Modules
None

Are there some Plugins that need to be diabled?</description>
		<content:encoded><![CDATA[<p>I didn&#8217;t mention it in my previous message, but Firefox gives the same results.</p>
<p>From what you just said, it could occur because of some duplicate SSO system? Maybe this is the problem. What I am trying to do is have the HTTP authtentication enabled with group mapping. There are no non-AD users. I&#8217;ve enabled the following Authentication Plugins and Modules:<br />
&gt;&gt;&gt; Plugins<br />
- Authentication &#8211; Joomla<br />
- Authentication &#8211; LDAP<br />
- Authentication &#8211; Advanced LDAP<br />
- SSO &#8211; HTTP<br />
- System &#8211; JAuthTools Synchronization Plugin<br />
- System &#8211; Single Sign On<br />
- User &#8211; Joomla!<br />
- User Source &#8211; LDAP<br />
- User Source &#8211; Session<br />
&gt;&gt;&gt; Modules<br />
None</p>
<p>Are there some Plugins that need to be diabled?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pasamio</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-9228</link>
		<dc:creator>pasamio</dc:creator>
		<pubDate>Thu, 14 May 2009 12:23:13 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-9228</guid>
		<description>To be honest, I can&#039;t say I do understand it, it sounds rather weird. What happens if you use Firefox? There is also some funkiness that might occur if you have more than one SSO system operating, so if you have the plugin and the module running at the same time these can conflict with each other and cause awkward behaviour. The same goes for any component that uses SSO to log the user in itself, this can conflict with the rest of the system and cause weirdness.</description>
		<content:encoded><![CDATA[<p>To be honest, I can&#8217;t say I do understand it, it sounds rather weird. What happens if you use Firefox? There is also some funkiness that might occur if you have more than one SSO system operating, so if you have the plugin and the module running at the same time these can conflict with each other and cause awkward behaviour. The same goes for any component that uses SSO to log the user in itself, this can conflict with the rest of the system and cause weirdness.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yellen</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-9221</link>
		<dc:creator>yellen</dc:creator>
		<pubDate>Thu, 14 May 2009 09:28:03 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-9221</guid>
		<description>Hi again,
I havent been able to use this, but I would like to point out something weird. First I would like to point out that the test are runned without this component, only your published component were used.

Okay here we go.

To test the HTTP single sign on, I use a vhost on apache. the intranet without kerberos auth is on tech.ieccdl.lan:80 and with kerberos auth is on tech.ieccdl.lan:84

I add tech.ieccdl.lan to intranet sites on IE.

I go to tech.ieccdl.lan and I am logged out. This is normal.

I go to tech.ieccdl.lan:84 and I am logged on. This is normal, Kerberos is working.

I click the menu and I am logged out. This is the known issue.

I reload the page and I am logged on again. This is normal, Kerberos is working.

If I now type in IE7 tech.ieccdl.lan, I remain logged on. Why? beats me... If I click on menu I am still logged on... I can browse the whole site and remain logged on... WHY?!!

I&#039;ve tried the SSO on port 80 and I still get disconnected when browsing the site.

Do you understand this?</description>
		<content:encoded><![CDATA[<p>Hi again,<br />
I havent been able to use this, but I would like to point out something weird. First I would like to point out that the test are runned without this component, only your published component were used.</p>
<p>Okay here we go.</p>
<p>To test the HTTP single sign on, I use a vhost on apache. the intranet without kerberos auth is on tech.ieccdl.lan:80 and with kerberos auth is on tech.ieccdl.lan:84</p>
<p>I add tech.ieccdl.lan to intranet sites on IE.</p>
<p>I go to tech.ieccdl.lan and I am logged out. This is normal.</p>
<p>I go to tech.ieccdl.lan:84 and I am logged on. This is normal, Kerberos is working.</p>
<p>I click the menu and I am logged out. This is the known issue.</p>
<p>I reload the page and I am logged on again. This is normal, Kerberos is working.</p>
<p>If I now type in IE7 tech.ieccdl.lan, I remain logged on. Why? beats me&#8230; If I click on menu I am still logged on&#8230; I can browse the whole site and remain logged on&#8230; WHY?!!</p>
<p>I&#8217;ve tried the SSO on port 80 and I still get disconnected when browsing the site.</p>
<p>Do you understand this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pasamio</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-8578</link>
		<dc:creator>pasamio</dc:creator>
		<pubDate>Mon, 27 Apr 2009 12:18:29 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-8578</guid>
		<description>I got your email, apologies for not getting back earlier but the email was from a .lan address. I&#039;ve sent you a copy using the email&#039;s you&#039;ve provided to this site for your comments so you should get it. I was also a bit behind as well since I couldn&#039;t immediately find the file.</description>
		<content:encoded><![CDATA[<p>I got your email, apologies for not getting back earlier but the email was from a .lan address. I&#8217;ve sent you a copy using the email&#8217;s you&#8217;ve provided to this site for your comments so you should get it. I was also a bit behind as well since I couldn&#8217;t immediately find the file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yellen</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-8422</link>
		<dc:creator>yellen</dc:creator>
		<pubDate>Thu, 23 Apr 2009 08:49:16 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-8422</guid>
		<description>Hi again,
I would be really like to try it out :-)

BTW I&#039;ve sent you an email so you can have my email address</description>
		<content:encoded><![CDATA[<p>Hi again,<br />
I would be really like to try it out <img src='http://pasamio.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>BTW I&#8217;ve sent you an email so you can have my email address</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pasamio</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-8341</link>
		<dc:creator>pasamio</dc:creator>
		<pubDate>Mon, 20 Apr 2009 14:36:19 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-8341</guid>
		<description>Yeah, that&#039;s not an uncommon fix as IE won&#039;t forward credentials over the internet for security reasons. The other alternative is if you have a proxy and your site doesn&#039;t go through a proxy it should work fine because IE automatically defines it as &quot;local intranet&quot;. Vista also introduces other interesting issues as well that broke stuff particularly with Sharepoint but if you explicitly put it things should be fine.

It looks fine, certainly nothing wrong with that configuration. So transitioning between links on the site after the initial hit causes the user to lose their identity? Seems very strange. Can you email me with pasamio at gmail.com and I&#039;ll find the source of the article and send it to you for testing.</description>
		<content:encoded><![CDATA[<p>Yeah, that&#8217;s not an uncommon fix as IE won&#8217;t forward credentials over the internet for security reasons. The other alternative is if you have a proxy and your site doesn&#8217;t go through a proxy it should work fine because IE automatically defines it as &#8220;local intranet&#8221;. Vista also introduces other interesting issues as well that broke stuff particularly with Sharepoint but if you explicitly put it things should be fine.</p>
<p>It looks fine, certainly nothing wrong with that configuration. So transitioning between links on the site after the initial hit causes the user to lose their identity? Seems very strange. Can you email me with pasamio at gmail.com and I&#8217;ll find the source of the article and send it to you for testing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yellen</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-8338</link>
		<dc:creator>yellen</dc:creator>
		<pubDate>Mon, 20 Apr 2009 11:44:59 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-8338</guid>
		<description>I configured the Kerberos auth in the virtual host config file like so (I didnt you an .htaccess file): 
	
		Options Indexes FollowSymLinks MultiViews
		AllowOverride None
		Order allow,deny
		allow from all
		AuthType Kerberos
		AuthName &quot;Enter your Login&quot;
		Require valid-user
		KrbMethodNegotiate On
		KrbMethodK5Passwd On
		KrbAuthRealms MYREALM.LAN
		Krb5KeyTab /etc/apache2/keytab/kerbjoomla-http.keytab
	

BTW I had to add the site to IE Local Intranet to have it working without the password.</description>
		<content:encoded><![CDATA[<p>I configured the Kerberos auth in the virtual host config file like so (I didnt you an .htaccess file): </p>
<p>		Options Indexes FollowSymLinks MultiViews<br />
		AllowOverride None<br />
		Order allow,deny<br />
		allow from all<br />
		AuthType Kerberos<br />
		AuthName &#8220;Enter your Login&#8221;<br />
		Require valid-user<br />
		KrbMethodNegotiate On<br />
		KrbMethodK5Passwd On<br />
		KrbAuthRealms MYREALM.LAN<br />
		Krb5KeyTab /etc/apache2/keytab/kerbjoomla-http.keytab</p>
<p>BTW I had to add the site to IE Local Intranet to have it working without the password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pasamio</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-8267</link>
		<dc:creator>pasamio</dc:creator>
		<pubDate>Sat, 18 Apr 2009 00:42:53 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-8267</guid>
		<description>What Apache auth handler are you using to get Kerberos to work?

I haven&#039;t thought of putting it into a release but if there is sufficient demand I could probably do a few extra things and release it out.</description>
		<content:encoded><![CDATA[<p>What Apache auth handler are you using to get Kerberos to work?</p>
<p>I haven&#8217;t thought of putting it into a release but if there is sufficient demand I could probably do a few extra things and release it out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yellen</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-8251</link>
		<dc:creator>yellen</dc:creator>
		<pubDate>Fri, 17 Apr 2009 14:13:25 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-8251</guid>
		<description>I am experiencing this same issue. I am using Apache on a ubuntu box, kerberos is working because the ssochecker get the username from the AD. My users get authenticated and as soon as they click around the joomla site, they get disconnected.

Are there any hopes that you will release this component?</description>
		<content:encoded><![CDATA[<p>I am experiencing this same issue. I am using Apache on a ubuntu box, kerberos is working because the ssochecker get the username from the AD. My users get authenticated and as soon as they click around the joomla site, they get disconnected.</p>
<p>Are there any hopes that you will release this component?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pasamio</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-7544</link>
		<dc:creator>pasamio</dc:creator>
		<pubDate>Wed, 25 Mar 2009 12:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-7544</guid>
		<description>The issue in this case was that there was a server that authenticated the user and in that instance acted as a proxy for the user passing along the authenticated username via a server variable. So the first request to Joomla! is through the authentication server proxy and then the next request comes from the actual client. This causes issues because Joomla! creates the session for the proxy server and ties it to that instead of the actual client so when the client connects again to Joomla!, a new session is created with their true IP address not that of the authentication server which means that the user isn&#039;t logged in. In this case it was a bit of a hack to get this to work properly but its an interesting application of technology to solve a problem.</description>
		<content:encoded><![CDATA[<p>The issue in this case was that there was a server that authenticated the user and in that instance acted as a proxy for the user passing along the authenticated username via a server variable. So the first request to Joomla! is through the authentication server proxy and then the next request comes from the actual client. This causes issues because Joomla! creates the session for the proxy server and ties it to that instead of the actual client so when the client connects again to Joomla!, a new session is created with their true IP address not that of the authentication server which means that the user isn&#8217;t logged in. In this case it was a bit of a hack to get this to work properly but its an interesting application of technology to solve a problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ole</title>
		<link>http://pasamio.com/2009/02/22/putting-token-login-to-work/comment-page-1/#comment-7537</link>
		<dc:creator>Ole</dc:creator>
		<pubDate>Wed, 25 Mar 2009 09:28:14 +0000</pubDate>
		<guid isPermaLink="false">http://pasamio.com/?p=272#comment-7537</guid>
		<description>Hello Sam

Thanks for the explanation. I have installed JAuthTools 1.5.4 Core, I&#039;m able to generate a token and login. 

However, I don&#039;t understand how you proxy a username to Joomla? Is it possible you can explain it with a little more details?

Best Regards 
Ole</description>
		<content:encoded><![CDATA[<p>Hello Sam</p>
<p>Thanks for the explanation. I have installed JAuthTools 1.5.4 Core, I&#8217;m able to generate a token and login. </p>
<p>However, I don&#8217;t understand how you proxy a username to Joomla? Is it possible you can explain it with a little more details?</p>
<p>Best Regards<br />
Ole</p>
]]></content:encoded>
	</item>
</channel>
</rss>

