Table of Contents
In this article, we are going to learn how to install the Authentication Extender using the SphereShield installer.
Before proceeding make sure to follow this KB in order to generate the user properties file.
What is the Authentication Extender
The Authentication extender is an optional component that is mandatory only when using SkypeShield Credentials (Dedicated credentials).
This component is directly connected to the SfB/Lync FE and the CAS/Exchange server, it will need delegation for these servers to give it privileges over these servers.
This component is a middle-man between the DMZ Bastion and the internal traffic, it receives traffic from the DMZ and authenticates on its behalf.
Installation
1. Right-click the installer and run it as an administrator.
2. When prompted with this windows click 'SphereShield for Skype for Business'
3. If no properties file was detected you will be asked to choose (if you have).
Click yes, to specify a file and no to proceed without specifying. The default location of the file should be at:
...
7. Make sure that 'Bastion Reverse Proxy' service has been created:
Bastion.xml Configuration
1. In the Bastion.xml file of the DMZ Bastion make sure that the channels are forwarding the traffic to the Authentication Extender.
...
3. In the Authentication Extender bastion.xml file, configure a channel to forward traffic to the Front End pool
AuthConsumer.xml Configuration
In the Authconsumer.xml file configure the certificate. You can the included certificate (in the Bastion folder) for testing purposes and replace with your own
once the system is up and running.
...
C:\Agat\Bastion_Auth\filters\Skype\AuthConsumer.xml
KCD.xml Configuration
In the KCD.xml file, we will need to input our pool FQDN in the 'target' tag.
WebTicket Application Configuration
In each front end server of the pool, we need to edit the WebTicket application of the external site to support Negotiate authentication.
...
Make sure that Negotiate is at the top of the listt, above NTLM
Permissions
Follow these steps:
- Open 'Active Directory Users and Computers'
- Select the server on which the Authentication Extender is installed, right click and select properties.
- Click 'Member Of' , Click add and the text box write 'Windows Authorization Access Group'
- Click 'OK' and then 'Apply'.
.
Create the Kerberos Intermediate Account
In order for the Authentication Extender to work with a pool, it must be set with a special intermediate account which needs to be created
specifically for this purpose.
In order to create that Account run the following command from the Skype for Business Management Shell:
...
Make sure to add the user to the delegation of the machine that runs the Authentication Extender
Replacing the signing certificate with your own after the system is up and running
For security reasons, it is recommended to replace the signing certificates. You will need to create a PFX certificate file with Public and Private Key for the LAC Filter and a CRT file with the same Public Key for the Auth Consumer.
...