Does anybody have any advice on what is the best way to configure Crowd so that it can be used by internal applications as well as custom external applications?
Here is our current configuration
- Confluence and JIRA are currently installed on the same (Windows) server and running behind an Apache HTTP Server using mod_proxy and SSL. i.e.
- Crowd is installed on a second server, and configured to work with an SSL certificate using a custom port. However, Crowd is not currently running behind an Apache HTTP Server. i.e.
- The user directories in Confluence and JIRA are configured to use Crowd via the external URL
- The external firewall currently only allow traffic to access the Crowd server/url from the server running Confluence and JIRA.
Firstly, is this configuration correct or are there any recommendations to improve it.
Secondly, we would now like to use Crowd as a centralised user management server for externally hosted applications and potentially Google Apps.
Aside from the custom development required to allow the externally hosted applications to "talk" to Crowd via the Crowd REST API, what is the best approach to exposing Crowd externally?
It seems that it simply a case of creating additional applications in Crowd for each externally host application and permitting access to the Crowd server/url from those locations.
Should I also consider removing the 'crowd' Context from the Application URL?
Are there any other configurations that should be considered to improve security or apply best practise?
Sorry for all the questions, and thanks in advance for all help and comments
Ian