# Apache SSO Configuration does not work

**URL:** <https://community.graylog.org/t/apache-sso-configuration-does-not-work/4597>\
**Category:** Graylog Add-ons\
**Created:** [March 16, 2018, 10:44am UTC](https://community.graylog.org/t/apache-sso-configuration-does-not-work/4597 "2018-03-16T10:44:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![krtp](https://avatars.discourse-cdn.com/v4/letter/k/da6949/32.png) [@krtp](https://community.graylog.org/u/krtp)\
**Post date:** [March 16, 2018, 10:44am UTC](https://community.graylog.org/t/apache-sso-configuration-does-not-work/4597/1 "2018-03-16T10:44:05Z")

</div>

Hi everybody,

does anybody here have simple, working sso config for apache here?  
I’m stuck.

I am able to pass the Apache Auth. I see Remote-User Header, but then i see only the standard Graylog Login page.

I appreciate any help!

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [March 16, 2018, 11:24am UTC](https://community.graylog.org/t/apache-sso-configuration-does-not-work/4597/2 "2018-03-16T11:24:23Z")

</div>

A typical mistake is that the IP address of the proxy server (Apache httpd in your case) is missing in the `trusted_proxies` setting in Graylog.

> <https://github.com/Graylog2/graylog2-server/blob/2.4.3/misc/graylog.conf#L121-L123>

---

<div class="post-metadata">

**Author:** ![krtp](https://avatars.discourse-cdn.com/v4/letter/k/da6949/32.png) [@krtp](https://community.graylog.org/u/krtp)\
**Post date:** [March 16, 2018, 11:51am UTC](https://community.graylog.org/t/apache-sso-configuration-does-not-work/4597/3 "2018-03-16T11:51:05Z")

</div>

Thank you for your help already.  
I made this setting, but it’s not working either.

Here is the main snip of the apache config file

> ```
> <Proxy *>
> Order deny,allow
> Allow from all
> </Proxy>
> 
> <Location />
> AuthType Kerberos
> AuthName "DOMAIN LOGIN (HTTPS)"
> KrbMethodNegotiate off
> KrbAuthoritative on
> KrbVerifyKDC off
> KrbAuthRealms DOMAINNAME
> require valid-user
> 
> RequestHeader set X-Graylog-Server-URL "https://192.168.1.1:10443/api/"
> Header set X-Forwarded-User %{REMOTE_USER}s
> ProxyPass http://127.0.0.1:9000/
> ProxyPassReverse http://127.0.0.1:9000/
> </Location>
> 
> ```

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [March 16, 2018, 12:02pm UTC](https://community.graylog.org/t/apache-sso-configuration-does-not-work/4597/4 "2018-03-16T12:02:10Z")

</div>

[https://github.com/Graylog2/graylog-plugin-auth-sso/issues/16](https://github.com/Graylog2/graylog-plugin-auth-sso/issues/16)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 30, 2018, 12:02pm UTC](https://community.graylog.org/t/apache-sso-configuration-does-not-work/4597/5 "2018-03-30T12:02:50Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
