---
title: Windows Authentication on the KronPAM GUI
slug: kronpam-reference-guide-3-5-0/windows-authentication-on-the-kronpam-gui
description: Learn how to configure Windows Authentication to access the Kron PAM GUI with this helpful document. From adjusting settings on the Domain Controller and Kron PAM Server to configuring browser and system parameters, discover the key steps necessary for su
docTags: 
createdAt: 2022-07-24T14:27:43.000Z
---

Windows Authentication can be used to log in to the KronPAM GUI. The required settings are outlined in this section. The following terms are used in the configuration steps:

**Domain Controller:&#x20;**&#x44;omainControllerFQDN (Ex: krontech-dc.krontech-new\.internal)
**Kron PAM Server**: schostnameFQDN (Ex: testsso.krontech-new\.internal)
**Domain Name**: DomainName (Ex: krontech-new\.internal)

### &#xD;Domain Controller Configuration

The following configurations should be set on the Domain Controller:

1. Create a user (Ex: username: win\_auth, password: 123)
2. Create an SPN (Service Principal Name) for this user, using the following command: setspn -A HTTP/**KronPAMServerHostname** **username**
   (Ex: setspn -A HTTP/testsso.krontech-new\.internal ssotest)
3. Create an “ssotest.keytab” file using the following command:
   ktpass /out c:\\**keytabFileName** /mapuser **username**@**DomainName**/princ HTTP/**KronPAMServerHostname\@DomainName&#x20;**/pass **password** /kvno 0 -ptype KRB5\_NT\_PRINCIPAL
   (Ex: ktpass /out c:\\**ssotest.keytab** /mapuser **ssotest**@**krontech-new\.internal** /princ HTTP/**testsso.krontech-new\.internal**@**krontech-new\.internal** /pass **123** /kvno 0 -ptype KRB5\_NT\_PRINCIPAL )

### Kron PAM Server Configuration

The following configurations should be set on the KronPAM server:

1. Connect to Kron PAM CLI as the **pamuser** user.
2. Move the “ssotest.keytab” file under “$CATALINA\_BASE/conf/”.
   (The default Catalina base directory is “u01/netright-tomcat”)
3. Create the “krb5.ini” file in the Tomcat Server under “$CATALINA\_BASE/conf/” with the following example content:                &#x20;

:::CodeblockTabs
krb5.ini

```ini
[libdefaults]       
default_realm = krontech-new.internal    
default_keytab_name = FILE:/u01/netright-tomcat/conf/ssotest.keytab 
default_tkt_enctypes = rc4-hmac,aes256-cts-hmac-sha1-96,aes128-cts-hmac-sha1-96 
default_tgs_enctypes = rc4-hmac,aes256-cts-hmac-sha1-96,aes128-cts-hmac sha1-96
forwardable=true 
allow_weak_crypto=true
[realms]
krontech-new.internal = { kdc = krontech-dc.krontech-new.internal:88 } 
[domain_realm] 
krontech-new.internal = krontech-new.internal 
.krontech-new.internal = krontech-new.internal 

```
:::

- Add the following lines in pam-gui.service file under /usr/lib/systemd/system/ directory
  -Djava.security.krb5.conf=/u01/netright-tomcat/conf/krb5.ini
  -Djavax.security.auth.useSubjectCredsOnly=false                                                     &#x20;

**Example:**
Environment="JAVA\_OPTS=**-Djava.security.krb5.conf=/u01/netright-tomcat/conf/krb5.ini -Djavax.security.auth.useSubjectCredsOnly=false** -agentlib\:jdwp=transport=dt\_socket,server=y,suspend=n,address=8000 -Xmx2048m -Xms256m -Duser.language=en -Duser.region=US -Duser.timezone=Etc/GMT-3 -Dlog4j2.formatMsgNoLookups=true -Djava.security.properties=/u01/kron/security/java.security -Dlog4j.configurationFile=/u01/netright-tomcat/conf/log4j2.xml -Dlog4j.configurationFile=/u01/netright-tomcat/conf/log4j2.xml -Dlog4j.configurationFile=/u01/netright-tomcat/conf/log4j2.xml -Dlog4j.configurationFile=/u01/netright-tomcat/conf/log4j2.xml -Dlog4j.configurationFile=/u01/netright-tomcat/conf/log4j2.xml -Dlog4j.configurationFile=/u01/netright-tomcat/conf/log4j2.xml&#x20;

### Client Browser Configuration

The following configurations should be set on the client’s browser. Configurations made for Internet Explorer (IE) also activate the Edge and Chrome browsers.

**For Internet Explorer (IE):**

1. Go to **Settings > Internet Options > Security**
2. Select “Local Intranet Zone,” click the “Sites” button, check all three options, and click the “Advanced” button to add the **“KronPAMServerHostname” with HTTPS&#xA0;**&#x74;o this zone. **Ex\:https\://testsso.krontech-new\.internal**
3. Select “Local Intranet Zone,” click the “Custom Level” button, and select “Automatic logon only intranet.”

**For Firefox:**

1. Type **about\:config** on the address bar, accept the warning, and change the **network.negotiate-auth.trusted-uris**” value to “**KronPAMServerHostname&#x20;**&#x77;ith HTTPS                                                                                                                                                           **Ex: https\://testsso.krontech-new\.internal**
2. Restart the computer.
3. Access the application by typing the **Kron PAM Server Hostname** on the address bar, **without the IP**
   **Ex: https\://testsso.krontech-new\.internal**

### Kron PAM GUI Configuration

Add the following parameters in the System Config Manager:

1. Navigate to **Administration > System Config. Man.**
2. Add these parameters:   &#x20;

```none
aioc.auth.windows = true
windows.auth.keytab.path = /u01/netright-tomcat/conf/ssotest.keytab
windows.auth.spn = HTTP/KronPAMServerHostname
Example value: HTTP/testsso.krontech-new.internal
```

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/dZeGxAfmYVw42IihRPDn8_image.png" size="26" width="264" height="463" position="center" caption="Windows Authentication Checkbox on WEB GUI" showCaption="true"}

