-
Notifications
You must be signed in to change notification settings - Fork 253
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
LDAP: No re-authentication with auth_ldap_cache_enabled off #223
Comments
@kvspb Can you please help me out here. |
This is likely handled in the cookie you're getting when you auth. They tend to have an expiration that time in the cookie which will determine with you'll have to re-auth. Pretty sure this isn't a module issue but one tied to your browser or LDAP server. |
Hi @mithun0119 - did you manage to achieve this? Thanks! |
No Harrtron, I never managed to find a fix. Please do let me know if you find any. |
Hi @mithun0119 |
Hi Amrutha, No luck. I just left it there. So if the browsers are all closed and reopened, then the cookie is gone and it prompts for credentials, else it just takes me in. |
I am running a web application behind nginx, using it as a reverse proxy to authenticate with AD and for SSL termination. now my issue is , if I login with credentials in a particular browser(chrome for eg;), the session doesnt terminate even if I leave the any of my chrome tabs(with anything open) for days together it never asks for credentials again when I refresh or open the URL in a new tab, unless I close all the instances of chrome or clear the cache/cookie.
My config:
###Using nested groups, hence no group directive used##
ldap_server adauth {
url "ldap://xxxx?sAMAccountName?sub?";
url "ldap://xxxx?sAMAccountName?sub?(&(memberOf:1.2.840.113556.1.4.1941:=CN=,OU=xx,DC=xx,DC=,DC=xx0(objectClass=person))";
binddn "@";
binddn_passwd "*****";
UAT,OU=xx,DC=xx,DC=xx,DC=xx";
require valid_user;
max_down_retries 10;
connections 50;
}
##Authentication with Active Directory##
auth_ldap_cache_enabled off;
proxy_cache_path /opt/nginx/cache levels=1:2 keys_zone=mycache:20m max_size=1G;
proxy_temp_path /opt/nginx/tmp_cache/;
proxy_cache_use_stale error timeout invalid_header http_502;
proxy_cache_bypass $cookie_nocache;
proxy_no_cache $cookie_nocache;
server {
listen 443 ssl;
server_name testserver.com;
auth_ldap "Enter your AD username/password";
auth_ldap_servers adauth;
ssl on;
ssl_session_cache shared:SSL:20m;
ssl_session_timeout 1m;
ssl_protocols SSLv2 SSLv3 TLSv1.2;
ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv3:+EXP;
ssl_prefer_server_ciphers on;
ssl_certificate /xxx.cer;
ssl_certificate_key /xxx.key;
access_log /var/log/nginx/test.log;
error_log /var/log/nginx/test-error.log error;
location / {
add_header 'Cache-Control' 'no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0';
expires off;
keepalive_timeout 5s;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_pass http://localhost:3838;
proxy_read_timeout 90;
proxy_buffering off;
proxy_redirect / $scheme://$host/;
}
}
I am using nginx 1.13.1 configured with below options:
The text was updated successfully, but these errors were encountered: