LDAP / Kerberos Login (SSO)
Directory-based sign-in (LDAP / Active Directory) and optional silent Kerberos SSO for on-premise deployments — and the information we need from you to set it up.
Last updated
Was this helpful?
Directory-based sign-in (LDAP / Active Directory) and optional silent Kerberos SSO for on-premise deployments — and the information we need from you to set it up.
On-premise deployments can authenticate users against your existing directory instead of separate We360 credentials. Two modes are supported:
Directory login — users sign in with their existing directory (LDAP / Active Directory) username and password.
Silent SSO (Kerberos) — on domain-joined Windows machines, users are logged in automatically from their existing Windows session, with no username/password prompt.
Both are optional and are configured per deployment.
We360 performs the configuration. You do not need to set up anything in the application. We only need some details about your directory environment, listed below. The Kerberos (silent SSO) mode is optional — set it up only if you want zero-prompt login.
To enable this, we ask your IT / directory administrator for the following. The downloadable form at the bottom of this page has a fill-in table for each item.
Directory server — type (Active Directory / other LDAP), version, host name(s), port, and whether the connection uses LDAPS/TLS (plus the CA certificate if it is issued by a private CA).
Service (bind) account — a dedicated read-only account we use to look up users: its distinguished name (DN) and password.
Directory structure — the base DN and the specific container(s)/OU where the users who should log in are located, and whether all of them or only a subset (e.g. a group) get access.
User attributes — which fields hold the login username, email, and name, and a stable unique identifier.
Kerberos / SSO (optional) — the Kerberos realm, KDC (domain controller) host names, confirmation that machines are domain-joined, and a service account + SPN + keytab your AD administrator generates for the login service.
Network & environment — connectivity from the We360 server to the directory (and KDC), DNS resolution, and clock synchronization.
Test accounts (optional) — one or two non-critical accounts so we can validate login before rollout.
Handle secrets securely. Passwords, certificates, keytab files, and test credentials must be shared through a secure channel that your We360 contact provides — never by email or inside the form document.
Download, complete the "Your value" column, and return the form to your We360 contact. Items marked (secure) are sent separately via the secure channel.
Last updated
Was this helpful?
Was this helpful?