<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windchill Basic authentication and SSO together in Windchill</title>
    <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896318#M74086</link>
    <description>&lt;P&gt;It can be done... What is the use case?&lt;/P&gt;
&lt;P&gt;Do you have a SAML IdP in your organization already (either internal or third party)?&lt;/P&gt;</description>
    <pubDate>Fri, 25 Aug 2023 14:50:58 GMT</pubDate>
    <dc:creator>jbailey</dc:creator>
    <dc:date>2023-08-25T14:50:58Z</dc:date>
    <item>
      <title>Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896212#M74078</link>
      <description>&lt;P&gt;Has anyone set your WC environment to have some users using Basic Authentication and some users using SSO?&lt;/P&gt;&lt;P&gt;There is a PTC KB article said it is doable, but it did not provide the steps.&lt;/P&gt;&lt;P&gt;Has anyone done ever done with this kind of configuration?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 11:59:02 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896212#M74078</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T11:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896318#M74086</link>
      <description>&lt;P&gt;It can be done... What is the use case?&lt;/P&gt;
&lt;P&gt;Do you have a SAML IdP in your organization already (either internal or third party)?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 14:50:58 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896318#M74086</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T14:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896319#M74087</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.ptcusercommunity.com/t5/user/viewprofilepage/user-id/181838"&gt;@tchao&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is configurable on a HTTP Server (apache) side so I would contact Apache support for that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in another word&amp;gt; I know it is possible but I've never needed it:D&lt;/P&gt;
&lt;P&gt;PetrH&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 14:49:15 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896319#M74087</guid>
      <dc:creator>HelesicPetr</dc:creator>
      <dc:date>2023-08-25T14:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896321#M74088</link>
      <description>&lt;P&gt;It can be done with PTC provided tools as well (PingFederate). I have an entirely SAML authentication policy that allows admins to use secondary accounts for separation of duties.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 14:50:17 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896321#M74088</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T14:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896322#M74089</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.ptcusercommunity.com/t5/user/viewprofilepage/user-id/243660"&gt;@jbailey&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have one use case.&lt;/P&gt;
&lt;P&gt;Users use SSO from client computers and administrator use basic login from Server side not from client computer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PetrH&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 14:51:30 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896322#M74089</guid>
      <dc:creator>HelesicPetr</dc:creator>
      <dc:date>2023-08-25T14:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896324#M74090</link>
      <description>&lt;P&gt;Why would administrators need to use basic login?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 14:53:08 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896324#M74090</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T14:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896326#M74091</link>
      <description>&lt;P&gt;&lt;a href="https://www.ptcusercommunity.com/t5/user/viewprofilepage/user-id/243660"&gt;@jbailey&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because it is demilitarization zone where is not available connection to a server provided the SSO &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&amp;nbsp;for example IBM WebSEAL&lt;/P&gt;
&lt;P&gt;PetrH&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 15:06:45 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896326#M74091</guid>
      <dc:creator>HelesicPetr</dc:creator>
      <dc:date>2023-08-25T15:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896347#M74095</link>
      <description>&lt;P&gt;Yes.&amp;nbsp; We are changing our SSO from ADFS to PingOne with MFA.&lt;/P&gt;&lt;P&gt;Our user cases are like this:&lt;/P&gt;&lt;P&gt;- Regular users will be with PingID + MFA&lt;/P&gt;&lt;P&gt;- Services integration will use Basic authentication (such as middleware and Engineering to Order Configurator tool, etc).&lt;/P&gt;&lt;P&gt;In the second item above works well with LDAP connection, but we are getting authentication fail with LDAPS connection and PTC is not able to provide a solid case where were the root cause of this denial....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any implementation steps high level are very much appreciated!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 15:47:11 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896347#M74095</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T15:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896352#M74097</link>
      <description>&lt;P&gt;In our case, the access with Basic authentication are also internal and we don't have DMZ in our case.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 15:50:01 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896352#M74097</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T15:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896353#M74098</link>
      <description>&lt;P&gt;So with Ping they should be able to set up an auth flow that directs users to the appropriate authentication method.&lt;/P&gt;
&lt;P&gt;What is the error you see when LDAPs fails? if there is anything with PKIX in the error then it is an issue with certificate trust (the LDAP server certificate is not in the offending keystore).&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 15:50:53 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896353#M74098</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T15:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896354#M74099</link>
      <description>&lt;P&gt;Also, I would recommend at some point to consider Oauth for your integration authentications. I know some tools may not support that, however that is a much more secure method.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 15:52:45 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896354#M74099</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T15:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896358#M74100</link>
      <description>&lt;P&gt;Also, from the machine that is trying to connect to your DS via ldaps.... The windchill server will have openssl on it... in a command prompt you can run the following command and see what it returns (should come back with a server cert in pem format along with connection info)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;openssl s_client -connect &amp;lt;ldap server fqdn like: myAD.mycorp.com&amp;gt;:636&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 15:57:36 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896358#M74100</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T15:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896370#M74103</link>
      <description>&lt;P&gt;Try the openssl command, but the command ends there after hitting enter.&lt;/P&gt;&lt;P&gt;It seems that it is being blocked somewhere, but our firewall and NetScaler set it to pass through.&amp;nbsp; Not sure if PTC cloud allows this....&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 16:34:42 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896370#M74103</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T16:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896373#M74104</link>
      <description>&lt;P&gt;After a while, the openssl got this back:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;socket: Bad file descriptor&lt;BR /&gt;connect:errno=9&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 16:38:48 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896373#M74104</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T16:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896374#M74105</link>
      <description>&lt;P&gt;This sounds like the problem. When a user attempts to authenticate, apache (or IIS) sends the username/password to LDAP for verification... which means that your Windchill web server (and the application portion) needs to have outbound access to the Active Directory (or other LDAP v3 DS), and the server where the AD/DS resides needs to have inbound access from the Web/App server. You could potentially have two firewall issues here... inbound and outbound on both sides.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 16:39:35 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896374#M74105</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T16:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896376#M74107</link>
      <description>&lt;P&gt;Not for administrators.&amp;nbsp; All users is getting connection with LDAPS OK, but the middleware failed for unknown reasons.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 16:40:32 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896376#M74107</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T16:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896378#M74109</link>
      <description>&lt;P&gt;So for your middleware... any LDAP certs need to be imported in the middleware keystores as well. Did you try running the openssl command from your server that the middleware is on?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 16:42:58 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896378#M74109</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T16:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896385#M74111</link>
      <description>&lt;P&gt;I thought they should have because this is all internal.&amp;nbsp; But it is worth a try to ask the middleware admin.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 17:10:39 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896385#M74111</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T17:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896386#M74112</link>
      <description>&lt;P&gt;Also what errors are showing up in the logs for the middleware?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 17:12:32 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896386#M74112</guid>
      <dc:creator>jbailey</dc:creator>
      <dc:date>2023-08-25T17:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windchill Basic authentication and SSO together</title>
      <link>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896387#M74113</link>
      <description>&lt;DIV&gt;&lt;P&gt;They are all traffic inside the corp network. I am assuming they should not be any issue, but it is worthy to check it again to make sure.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 25 Aug 2023 17:12:34 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Windchill/Windchill-Basic-authentication-and-SSO-together/m-p/896387#M74113</guid>
      <dc:creator>tchao</dc:creator>
      <dc:date>2023-08-25T17:12:34Z</dc:date>
    </item>
  </channel>
</rss>

