Hello all,
is it possible to avoid the signon screen entirely for users which are authenticated against the Windows Domain Controllers or any other authentication provider (Kerberos LDAP PAM ...).
This would mean either Tomcat or an Apache reverse proxy is configured to perform NTLM authentication directly between browser and AD. The credentials are passed on to Jira (on success). If not authenticated, the normal login screen appears.
This is what "real" single signon would be all about.
Best regards
Maba