<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User authentication in WSA in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558791#M7941</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So does it mean that we need CDA when WSA is deployed in transparent mode and transparent user authentication is required?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe HTTP request contains username and domain name. WSA can verify username with AD and allow as per policy. So why we still need CDA in this case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Aug 2017 08:58:30 GMT</pubDate>
    <dc:creator>dngore</dc:creator>
    <dc:date>2017-08-03T08:58:30Z</dc:date>
    <item>
      <title>User authentication in WSA</title>
      <link>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558787#M7937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am new to WSA and wants to understand user authentication concept/flow. We want to authenticate users transparently and apply web policy as per AD group. We will integrate WSA with AD using NTLPSSP. &lt;/P&gt;&lt;P&gt;WSA needs user name for applying policy. I understand that Client web bowser sends user name in web request. Hence WSA can obtain that user name and can verify with AD for validity. This should be straight forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as per User guide for AsyncOS 11.0, Cisco Context Directory Agent (CDA) is required for transparent user identification. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure why we require CDA, if WSA is able to get username from client web browser http get request and can verify with AD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understanding may be wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly help me to understand CDA's requirement &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Mar 2019 03:40:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558787#M7937</guid>
      <dc:creator>dngore</dc:creator>
      <dc:date>2019-03-09T03:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication in WSA</title>
      <link>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558788#M7938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume that you have deployed WSA in Explicit Forward proxy mode and integrated with Microsoft AD.&amp;nbsp; If end user system is part of domain, user authentication will happen transparently. I don't think CDA is required. I have deployed WSA without CDA and transparent authentication works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Make sure that all test results are successful when you run a test query while doing Authentication integration with AD. If any one fails, you will have challenge at the user side related to authentication&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Jul 2017 17:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558788#M7938</guid>
      <dc:creator>Narasimhan VS</dc:creator>
      <dc:date>2017-07-29T17:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication in WSA</title>
      <link>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558789#M7939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WSA will be in transparent mode. Will that affect CDA requirement?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In which situation, CDA will be required?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jul 2017 15:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558789#M7939</guid>
      <dc:creator>dngore</dc:creator>
      <dc:date>2017-07-30T15:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication in WSA</title>
      <link>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558790#M7940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco CDA agent maps IP Addresses to usernames in order to allow WSA to understand which user is using which IP Address in the network.&amp;nbsp; This can be used when WSA is deployed in transparent mode..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 04:49:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558790#M7940</guid>
      <dc:creator>Narasimhan VS</dc:creator>
      <dc:date>2017-07-31T04:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication in WSA</title>
      <link>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558791#M7941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So does it mean that we need CDA when WSA is deployed in transparent mode and transparent user authentication is required?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe HTTP request contains username and domain name. WSA can verify username with AD and allow as per policy. So why we still need CDA in this case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 08:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/user-authentication-in-wsa/m-p/3558791#M7941</guid>
      <dc:creator>dngore</dc:creator>
      <dc:date>2017-08-03T08:58:30Z</dc:date>
    </item>
  </channel>
</rss>

