cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Use Kerberos SSO Authentication in Synthetic Monitoring

CMEL
Newcomer

Hi community (my first post !) !

I tried to register a Synthetic monitoring on a WebAp using Kerberos Auth only.

Some considerations :

> From a Windows opened user session, I'm available to access this WebAp with my Kerberos token.

> There is no prompt for login/password (no other possibility that Kerberos, no Auth alternatives)

It looks like Synthetic Monitor can"t run that kind of Authentication.

Manually, I succeeded to log in, setting manually in cookie a "gssapi_session / MagBearerToken=xxxx" in the advanced setup of the Monitor Settings. (Token retrieved from browser debug to accessing WebAp)

But this token is only valid for some hours, so that can't be the solution to run for monitoring.

Vault doesn't seem to be the only solution, as (I think) it doesn't/can't play the Kerberos Auth.

So the idea may be to run something like "kinit" via the Vault to run the Kerveros Auth and then be able to use it in the Synthetic Monitoring.

If you have any experience, confirmaton/invalidation, suggestion ...

Thanks for your help !

CMEL

(Depending on the replies, it may be a post to recreate in "Product Ideas" ?)

(1st post ! Hope that's a good one ^_^)

Regards,
CMEL.
I was told I was using a broken english, sorry for that 🙂
6 REPLIES 6

Julius_Loman
DynaMight Guru
DynaMight Guru

I assume you are doing the synthetic tests from a private location, right? In the case of Synthetic ActiveGate for Windows this is achievable by running the synthetic engine as the user who has access to the Web Application.

Certified Dynatrace Master | Alanata a.s., Slovakia, Dynatrace Master Partner

Oh, yes I'm running in private location, but I have tried for now only under Linux AG ! (running Dynatrace  Managed on-prem, forgot to say it)
I'm gonna try on Windows AG and set a service account user to try this.

> I'll let you know the result (next year now) 🙂

(But it could be also a great thing to be able to run this kind of test under Linux !)

Thx !

Regards,
CMEL.
I was told I was using a broken english, sorry for that 🙂

Well - I'm not sure about getting that working on Linux - but I would guess the same applies - and you have to "log in" the user which is running those synthetic tests.

@HannahM is there any recommended solution?

Certified Dynatrace Master | Alanata a.s., Slovakia, Dynatrace Master Partner

Kerberos definitely prefers windows, so I would go with Julius's suggestion of trying that and logging the Dynatrace Synthetic service on as a domain user - you will need to disable auto-updates if you do that though, as the Service defaults back to the Local Service user on update. So you will need to add the extra step of resetting it to your upgrade run book. 
For Linux machines, we will likely need to add the following line/ lines (depending on what the setup) to the user.properties file in the \dynatrace\synthetic\config directory.

com.ruxit.vuc.poolConfig.playerConfig.additionalStartupParams=--auth-server-whitelist="_"

or 

com.ruxit.vuc.poolConfig.playerConfig.additionalStartupParams=--auth-server-whitelist="customerdomain"
com.ruxit.vuc.poolConfig.playerConfig.additionalStartupParams=--auth-negotiate-delegate-whitelist="customerdomain"

 

Hello,

Thanks for the reply.

The problem is that we have hundreds of applications to check. And we can't have common user credentials to test them. So that means that we must run a dedicated ActiveGate for each credential we have to access via Kerberos ...

So, I think that we can't run our checks like this.

Do you think I can post as an "idea" to have Kerberos credentials managed for Synthetic ? I must not be alone having those security constraints.

Having in the monitoring script something like a checkbox to use a credential Vault with a Kerberos init (providing domain informations) would be perfect !

Thanks,
CMEL.

Regards,
CMEL.
I was told I was using a broken english, sorry for that 🙂

HannahM
Dynatrace Champion
Dynatrace Champion

For many instances just adding the credentials using HTTP Authentication is sufficient but it really depends on the set up. If you create a support ticket we can try to see if we can get it working and then you can decide if a Product Idea is required.