# Endpoint security (HTTP-IN) IWA, NA

**URL:** <https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152>\
**Category:** General\
**Tags:** http-request, security\
**Created:** [24 November 2023 15:38 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152 "2023-11-24T15:38:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![LucianR](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lucianr/32/85185_2.png) [@LucianR](https://discourse.nodered.org/u/LucianR)\
**Post date:** [24 November 2023 15:38 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152/1 "2023-11-24T15:38:42Z")

</div>

Hello,

I'm running some node-red application under a corporate environment, that mostly use Windows PCs and Active Directory integration.  
The Node-Red runs on linux dockers.

In this particular example i want to use the node-red to create some secured endpoints (restAPIs - http in)

How do i seamlessly pass the windows identity to node-red node?  
Something similar with what IIS is doing by default, or Apache is doing through SSPI module.

I don't want to auth the user and check the user/pass against the AD, but i just want to pass the browser "identity" to the call.

Integrated Windows Authentication (IWA) or Negotiate Authentication

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [24 November 2023 15:42 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152/2 "2023-11-24T15:42:24Z")

</div>

This was talked about sometime ago on another thread - I cant remember the outcome, but do re-call it was extremely tacky, given its not natively possible to pass the Windows session into the Node/express process.

You are better off putting NGINX in front of Node RED, as I believe NGINX supports NTLM and others out of the box.

I'm sure others can advise also

**EDIT**  
I have moved this thread out of feature requests, as I don't believe this is a request to add features, apologies if it is

---

<div class="post-metadata">

**Author:** ![LucianR](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lucianr/32/85185_2.png) [@LucianR](https://discourse.nodered.org/u/LucianR)\
**Post date:** [24 November 2023 15:51 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152/3 "2023-11-24T15:51:23Z")

</div>

Well, this is a missing feature in the end 🙃 but i do see your point, so it's ok.

Can you by any chance help me find that thread? I searched and searched, and googled ...

Thanks

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [24 November 2023 16:04 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152/4 "2023-11-24T16:04:58Z")

</div>

I think this was it

> [@IIS proxy: username in Node-RED](https://discourse.nodered.org/t/iis-proxy-username-in-node-red/77514):
>
> Hi, I am using an IIS proxy server with Windows Authentication to enable access to my Node-RED Dashboard UI for a defined AD user group. While this in itself works perfectly, I would like to know which AD user is logged in to the browser session so I can log this information with the Node-RED flow that is triggered. Is there any way I can do this? Or is there any other way to achieve the (basically same) result? Any help is greatly appreciated! Thanks very much, DenW

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [24 November 2023 17:28 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152/5 "2023-11-24T17:28:39Z")

</div>

> [@LucianR](#):
>
> Well, this is a missing feature in the end

It isn't a missing feature of Node-RED though. It is up to the edge web server and the OS to provide the data if they can. As you are working with IIS, you have to have some additional features plugged-in and/or configured as you would with any other web server (NGINX for example) that is acting as the edge proxy for your microservice.

So IIS has to be configured to pass the data from the OS to upstream microservices like Node-RED. You will probably have to configure Node-RED to trust IIS as a proxy as well. This can be done in settings.js.

---

<div class="post-metadata">

**Author:** ![SynoUser-NL](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/synouser-nl/32/85195_2.png) [@SynoUser-NL](https://discourse.nodered.org/u/SynoUser-NL)\
**Post date:** [24 November 2023 18:14 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152/6 "2023-11-24T18:14:00Z")

</div>

Hi,

I am the starter of the "other"thread.

For us, this was "solved" by using FlowFuse Enterprise Edition, and working with the very helpfull team over there to achieve what we wanted to do. FlowFuse is essentially management software for NodeRED instances.

In vanilla NodeRED & with IIS, my request as initially posted is still not possible afaik.

DenW

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [23 January 2024 18:14 UTC](https://discourse.nodered.org/t/endpoint-security-http-in-iwa-na/83152/7 "2024-01-23T18:14:36Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
