Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Kerberos Settings & Kerberos Suggests

ETS
This section configures simplified authentication (SSO) for users in web and desktop apps (3.67 and higher, server software 3.65 and higher) using the Kerberos protocol via Active Directory. You can also upload a keytab file with user credentials.

Kerberos Suggests

In the Kerberos Suggests subsection, you can configure the mapping of Active Directory groups to corporate servers. This ensures that users in organization with multiple
eCTS
servers don't have to select them manually.

What Happens if a User Has Groups/Roles Associated With Different Servers?

If a separate server was configured for each of the user's groups, the user will see a list of those servers to choose from.

For example, several groups are mapped to different servers:
  • ad_group_1 > server_1
  • ad_group_2 > server_2
  • ad_group_3 > server_3
The user belongs to ad_group_1 and ad_group_3. Then the user will see a list of servers:
  • server_1
  • server_3

Which Browser Policies Are Required for Kerberos Login in the Web App?

To enable Kerberos authentication in the browser, add the following policies:
  • AuthServerAllowlist — domains allowed to request a Kerberos ticket
  • AuthNegotiateDelegateAllowlist — domains allowed to delegate the ticket
If your organization uses a single domain, listing it once in both policies is sufficient — you do not need to separately list the FQDNs of the web and corporate servers.

Which Encryption Type Is Required for the Keytab File?

The keytab must be generated with support for AES256-SHA1 encryption, and the associated Active Directory account must support this encryption type. The service principal name (SPN) for the server is registered in Active Directory using the command:
setspn -S HTTP/<server-fqdn> <AD_account>