Basic authentication delegation with TMG


Is there someone here using TMG as reverse proxy for access to Confluence?

I can access Confluence through TMG, but delegation of credentials does not work, so I get asked for creds. two times. Once for TMG and once for Confluence. Team Calendar subscription from Outlook does not work because of this.

The listener is set to provide HTTP Authentication Basic, and authentication delegation is set to basic authentication. Somehow TMG is unable to pass credentials to Confluence. I have not done any configuration changes to Confluence with regards to this as I do not know what to do.

Some hints would be appreciated :)

1 answer

Well,  a bit late maybe...

But this is how it works:

Client -> (TMG) -> (IIS on Confluence Server) -> Confluence (via AJP)

Confluence uses a custom authenticator which enables it to use the remote-user header (and trusting it fully).

The IIS is for authentication of the user (kerberos or NTLM). The TMG will act as a proxy and thus have the users NTLM or kerberos Session (that is why the user only has to authenticate at the TMG).


A different setup would be:

  1. Using Apache or an other kerberos enabled web server
  2. Using Plugins to enable Confluence to use kerberos directly. (There is at least one provider, because we use this solution for Jira)

Other solutions are, of course, possible.

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Mar 12, 2019 in Confluence

Confluence Admin Certification now $150 for Community Members

More and more people are building their careers with Atlassian, and we want you to be at the front of this wave! Important Dates Start the Certification Prep Course by 2 April 2019 Take your e...

420 views 2 13
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you