zettelkasten/OneNoteExport/Kommunikationstechnologie/Sharepoint/Infrastruktur/39_WebApp extended.md
Ralf Koop 5a108aa2b4 .
2023-08-25 23:29:11 +02:00

5.0 KiB

WebApp extended

Donnerstag, 13. Dezember 2018

13:11

 

DNS

 

Hier muss der Name unter dem die Extended Webapplikation genutzte werden soll hinterlegt werden.

 

kerbportal-spt // 10.96.73.77

 

 

 

SharePoint

Name: (automatisch), dann anpassen: SPT - kerbportal-spt.bkk-mobiloil.de

Port: 443

Hostheader: kerbportal-spt.bkk-mobiloil.de

Use SSL anhaken!

Enable Windows Authentication

Integrated Windows Authentication - Negotiate (Kerberos)

Default Sign In Page (optional) - "/_trust/default.aspx"

Zone : Intranet?

 

Computergenerierter Alternativtext: Authentication Providers Default Intranet Membership \*wider Name Claims Based Authentication Claims Based Authentication {width="5.677083333333333in" height="1.78125in"}

 

Erfasster Bildschirmausschnitt: 13.12.2018 13:19

 

 

Computergenerierter Alternativtext: Authentication Providers These authentication settirgs are to folbwing Zone. Anonyrrrous Access Vou can enable amnyrnous access for Sites on this server or s acces for all Sites. Enablirg SZCeSS allows Site administrators to tum anomy•mous access on, Disabling anonymous users in the w•eb.config file for this Zone. Note: lI access is off using authentiaticn mode, Forms aware Client applications fail to authenticate correct\'y, Client Object Mcdel Permassbon Require,ment Vou can that the user must have the Use Remote Interfa the Client Model to access the server. The Client Obect Model is used by same Parts of the Ul. prevents users from performing some tasks us•ng the Ul if do not have the Use Remote Claims Authentication Types Choose the type of authentication You to use for this Negobate (Kerberos) is the recommended Security confguration to Windows authenticaticm. lI this option is seected and Kerberos is not configured, NTLM \*ill tk u;ed\_ Fo. Kerbeos, the needs to be Network Service o\' an account that has confiyured Intranet Enable anonymous access Require Use Remote Interfaces permission Enable Windows Authentication Integrated Windows authentication Otiate (Kerberos) (3 Basic authentication (credentials are sent in Clear text) Enable Forms Based Authentication (FBA) ASP.NET Membership Provider name ASP .NET Role manager name {width="5.635416666666667in" height="8.802083333333334in"}

 

Erfasster Bildschirmausschnitt: 13.12.2018 13:26

 

 

Computergenerierter Alternativtext: Authentication Providers NTLM authentication will \'\*Ork \',ith arry Pool account and With domain C onfgur•tion. Basic authenticaticn rnethcd passes users\' credentials over a network in an wencrypted foml. lI Fu Select this Option, that Secure Sczkets Layer (SSL) is ASP .NET and role Provider used tC enab•le Forms Based Authentication (FRA) for this Web application. After Create an FBA Web additional confguration is required. Trustee Hentity P rwider tion enables fderated in this Web application. This authenbcation is Claims token based and the user is to a Icon form for Learn abc•at confgurirg Sign In Page URL When Clairns Based Authentication Bypes are enabled, a URI for redirecting the user to the Sign In Page is Learn Sen In redirecüon URL Client Integration \'\*hich Client applicabons. Sone authentication mechanism5 (such as Foms) dient applications. In this confguration, users will either have to use brmvser-based to edit or work on them locallv and uøload D Trusted Identity provider T rusted Identity P rwider ADFS4.O C) Default Sign In Page \@Custom Sign In Page /\_trust/default.aspx Enable Client Integration? ON0 {width="5.65625in" height="8.802083333333334in"}

 

Erfasster Bildschirmausschnitt: 13.12.2018 13:26

 

 

Computergenerierter Alternativtext: Client Integration Dsabling clent remove features \*hich launch Client applications, Some authentication (such as \"Il With dient applications. In this confguration. users will either have to use brcwser-based to edit their work on them Locally and upload changes. Note If Client integration is tumed on in e O njurrticn With Forms mode, anonymous access should aso be turned on or Forms .mvare Client m 3,\' fail to Enable Client Ir,tegraton? \@Yes ONO Carcel {width="5.53125in" height="3.7083333333333335in"}

 

Erfasster Bildschirmausschnitt: 13.12.2018 13:26

 

 

 

 

 

IIS

Binding anpassen und das Zertifikat *.bkk-mobiloil.de einpflegen.

IISreset

 

Testaufruf:

 

https://kerbportal-spt.bkk-mobiloil.de/sites/portal

 

 

 

 

http://anothersharepointblog.blogspot.com/2013/04/unextending-web-application-why-you.html

 

https://fillzephyr.wordpress.com/2009/04/20/change-my-site-webapplication/

 

/_trust/default.aspx

ist falsch darf nicht gesetzt werden bei kerberos!