---
title: "EasySSO with header-based authentication configuration"
canonical: "https://www.techtime-initiative.com/space/EasySSO/4948283/EasySSO%20with%20header-based%20authentication%20configuration"
format: markdown
---
Instructions on how to configure [SSO with Headers and Attributes](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4980915), aka EasySSO custom authentication

> ⚠️ **Before you configure:** Ensure you have understood the Security Notice [here](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4980915).

## To start using Custom Authentication

### Navigate to the EasySSO Custom Authentication settings

1. Click the EasySSO link under "TechTime Add-Ons" section usually located in the left panel of the Admin screen.
2. Click "Headers" to configure headers-based authenticator

### Configure the following parameters

1. Type: select Header or Attribute from the drop down box
2. Name: enter the name of the header or attribute
3. Check the `Get Username` checkbox if you want the value of the header or attribute to be used as the user identity during SSO
4. Check `disable NTLM/Kerberos` if the presence of the header or the attribute should disable NTLM/Kerberos authenticator.
5. IP Filter: enter allowlist values for sources that should be considered when supplying header values, as a comma-separated IP addresses, IP ranges x.x.x.x-y.y.y.y, or networks CIDR notation
6. If you have additional headers or attributes you wish to inspect click on the plus under `Type` and repeat steps 1 - 6 until all required rules for the attributes and headers are set up (consider a use case when a header should stop NTLM/Kerberos, but needs to be pre-processed first by the custom code, so the real identity will be set via attribute – see [SSO with Headers and Attributes](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4980915) for more details)
7. Click Save, and you are done!

### Example of Apache configuration

Below is an example of Apache configuration where Apache does Kerberos-based authentication (lines 2-11), verifies against LDAP (lines 14-18) and simply passes the username to EasySSO in Confluence via a header X-REMOTE-USER set from the variable REMOTE_USER (line 20).

Please note the emphasis here is on line 20, setting the header using [mod_headers](https://httpd.apache.org/docs/2.4/mod/mod_headers.html) after the user is identified by some other means, so the rest of the example should not be taken as is.

```
<Location /confluence>
        AuthType Kerberos
        AuthName "Please enter password for Confluence"
        KrbAuthRealms TEST.YOURDOMAIN.COM
        KrbMethodNegotiate On
        KrbMethodK5Passwd Off
        KrbAuthoritative on
        Krb5KeyTab /etc/apache2/httpd.keytab
        KrbServiceName HTTP/wiki.yourdomain.com@TEST.YOURDOMAIN.COM
        KrbLocalUserMapping On
        require valid-user
 
 
        AuthLDAPUrl "ldap://dc.yourdomain.com/DC=yourdomain,DC=com?samaccountname"
        AuthLDAPBindDN *****************
        AuthLDAPBindPassword *************
        AuthLDAPGroupAttributeIsDN on
        require ldap-group CN=confluence-users@yourdomain.com,OU=security-groups,DC=yourdomain,DC=com
 
        RequestHeader set X-REMOTE-USER %{REMOTE_USER}s
</Location>
```