IIS, php, kerberos and multi-hop

Dave Gudgeon DaveG at jadu.co.uk
Mon Dec 4 12:45:53 EST 2006


Hi,

I am currently developing a web application for a windows 2003 server 
running kerberos and wondered if anyone could help me out. I am using 
integrated windows authentication to provide single sign on for my php 
application running on IIS. The problem I am having is that I need to 
request data from a second server and maintain the access rights of the 
user logged in to my application. I understand this is called multi-hop 
authentication and is quite a common issue. The research I have 
conducted leads me to believe that I need to pass kerberos tokens to the 
second server along with my HTTP request, is this correct? I have been 
able to find very little information about the structure of these 
tokens, or how I can access them via php.

If you have any documentation / APIs / resources that you could 
recommend or any advice to help me in the right direction it would be 
most appreciated.

Many thanks

Dave Gudgeon



-- 
Dave Gudgeon
Software Engineer

Jadu announces the content management revolution with Jadu Galaxies
Find out how you can design, deploy and devolve web content management - no technical skills required:
http://www.jadu.co.uk/galaxies

--
Jadu Limited,
Development Centre: LCB, 31 Rutland Street, Leicester LE1 1RE
Main office: PO Box 2554, Rugby, Warwickshire CV21 4ZE

T: 0116 253 3423 F: 0116 253 3424 

http://www.jadu.co.uk
--
ISO 9001:2000 registered firm GB2001425




More information about the Kerberos mailing list