SSO login request is denied by ABE

Discussions about the Application Boundaries Enforcer (ABE) module

SSO login request is denied by ABE

Postby alwayssummer » Mon Jun 18, 2012 2:49 pm

Hi all, I think it's about time I learn how to use ABE correctly instead of just turning it off or switching to IE when it interferes. Here's a problem I was running into today:

[ABE] <LOCAL> Deny on {POST https://sso.from.mydomain.com <<< https://wikisite.we.use.com}
SYSTEM rule:
Site LOCAL
Accept from LOCAL
Deny

On another note, I'm not sure I get the purpose of the USER vs the SYSTEM section. I read the help, but I can't find the explanation. Does USER just mean it only applies when I'm logged in? Does it get processed before system?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0
alwayssummer
 

Re: SSO login request is denied by ABE

Postby alwayssummer » Mon Jun 18, 2012 3:09 pm

I think it is getting picked up by the local rule because I am using VPN to my company.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0
User avatar
alwayssummer
 
Posts: 2
Joined: Mon Jun 18, 2012 2:50 pm

Re: SSO login request is denied by ABE

Postby alwayssummer » Mon Jun 18, 2012 3:13 pm

Added:

Code: Select all
Site LOCAL
Accept from LOCAL .mycompany.com .mycopmpany.int .wikisite.com
Deny


And it loads now, but I'm still concerned about having it in SYSTEM. Should this rule be in USER?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0
User avatar
alwayssummer
 
Posts: 2
Joined: Mon Jun 18, 2012 2:50 pm

Re: SSO login request is denied by ABE

Postby Thrawn » Mon Jun 18, 2012 11:37 pm

Well done! Your rule is correct. My only suggestion is to narrow it down by adding a specific one before the default rule:
Code: Select all
Site https://sso.from.mydomain.com
Accept from .wikisite.we.use.com

Site LOCAL
Accept from LOCAL
Deny

On another note, I'm not sure I get the purpose of the USER vs the SYSTEM section. I read the help, but I can't find the explanation. Does USER just mean it only applies when I'm logged in? Does it get processed before system?

Actually I believe System goes first, but more to the point, both rulesets are processed. So User rules don't override System ones. Within a ruleset, once a rule matches, no more rules are processed for that request, but the other ruleset will still be applied. Most of the time, you should add your own rules to User, unless you need to modify or override the default rule. So in your case, you need System.
======
Thrawn
-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCM/CS/IT/M/S d++(-) s+: C++$ ULS$>++++ P(+) L++ W++
K- w V? PS-(---) PE Y+ PGP->++ t@ X R tv b++>+++ DI+@
!D G>+++ e++>+++ h--- r+++ m?
-----END GEEK CODE BLOCK-----
Mozilla/5.0 (Android; Mobile; rv:15.0) Gecko/15.0 Firefox/15.0a1
User avatar
Thrawn
Senior Member
 
Posts: 959
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia


Return to ABE

Who is online

Users browsing this forum: Google [Bot] and 1 guest