{"id":19425,"date":"2023-07-17T15:20:37","date_gmt":"2023-07-17T19:20:37","guid":{"rendered":"https:\/\/kevinjustin.com\/blog\/?p=19425"},"modified":"2023-07-24T08:11:02","modified_gmt":"2023-07-24T12:11:02","slug":"scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs","status":"publish","type":"post","link":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/","title":{"rendered":"SCOM WebConsole settings for authentication"},"content":{"rendered":"<figure id=\"attachment_19426\" aria-describedby=\"caption-attachment-19426\" style=\"width: 620px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19426\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp\" alt=\"Auto Pilot for SCOM web console\" width=\"620\" height=\"412\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp 620w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2-300x199.webp 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19426\" class=\"wp-caption-text\">Airplane movie &#8211; AutoPilot with SCOM Web Console settings<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Makes me think of the scene from Airplane with the AutoPilot blow-up, similarly parallel to engineer experiences talking about the SCOM Web Console configuration.\u00a0 I&#8217;m ready to dispel some myths to document securing the &#8216;SCOM Web Console for authentication&#8217;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Quick outline<\/strong><\/h1>\n<p>Knowledge Articles to aid with &#8216;SCOM WebConsole settings for authentication&#8217;<\/p>\n<p>Configuring SSL certs and Smart Cards (<a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/\" target=\"_blank\" rel=\"noopener\">this post<\/a>)<\/p>\n<p>Configuring Kerberos and AD delegation (<a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-kerberos-ad-delegation\/\" target=\"_blank\" rel=\"noopener\">next post<\/a>)<\/p>\n<p>Verifying WebConsole functionality blog posts &#8211; <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/20\/scom-webconsole-http-redirect\/\" target=\"_blank\" rel=\"noopener\">ReDirect<\/a>, <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/20\/scom-web-console-authentication-settings\/\" target=\"_blank\" rel=\"noopener\">Authentication<\/a>, <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/20\/v-237434-scom-web-console-ssl-settings\/\" target=\"_blank\" rel=\"noopener\">SSL and Bindings<\/a><\/p>\n<p>Mitigating SCOM vulnerabilities &#8211; <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/04\/20\/acas-scan-for-java-vulns-plugin-ids-170161166316\/\" target=\"_blank\" rel=\"noopener\">Java<\/a>, <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/04\/24\/resolve-hsts-vulnerability-cves-on-iis10\/\" target=\"_blank\" rel=\"noopener\">HSTS<\/a>, <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/14\/security-odbc-vuln-175441\/\" target=\"_blank\" rel=\"noopener\">ODBC<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Knowledge Articles<\/strong><\/h1>\n<p>How to Install Web Console from learn.microsoft.com for SCOM <a href=\"https:\/\/learn.microsoft.com\/en-us\/system-center\/scom\/deploy-install-web-console?view=sc-om-2019\" target=\"_blank\" rel=\"noopener\">2019<\/a>, <a href=\"https:\/\/learn.microsoft.com\/en-us\/system-center\/scom\/deploy-install-web-console?view=sc-om-2022\" target=\"_blank\" rel=\"noopener\">2022<\/a><\/p>\n<p>Holman&#8217;s SCOM quick start install guides for SCOM <a href=\"https:\/\/kevinholman.com\/2019\/03\/14\/scom-2019-quickstart-deployment-guide\/\" target=\"_blank\" rel=\"noopener\">2019<\/a>, <a href=\"https:\/\/kevinholman.com\/2022\/05\/01\/scom-2022-quickstart-deployment-guide\/\" target=\"_blank\" rel=\"noopener\">2022<\/a><\/p>\n<p>IIS Manager Authentication from <a href=\"https:\/\/learn.microsoft.com\/en-us\/iis\/configuration\/system.webserver\/security\/authentication\/iisclientcertificatemappingauthentication\/\" target=\"_blank\" rel=\"noopener\">learn.microsoft.com<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Configuring SSL Certs and Smart Cards<\/strong><\/h1>\n<p>Setup &#8216;SCOM WebConsole settings for secure authentication&#8217;, access, and rendering methods.\u00a0 <span style=\"font-size: 1rem;\">I&#8217;ve setup the web console role with defaults, then come back later.\u00a0 Holman&#8217;s quick start lets you complete the role with default HTTP setup.\u00a0 After that, we add an SSL cert for HTTPS.\u00a0 Thirdly, employ aliases, or F5 load balancers to simplify user experience accessing the console.\u00a0 Fourth, setup SmartCards to help secure, also Kerberos authentication\/delegation.\u00a0 <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Part 1 &#8211; Start with the SSL certificate for https<\/strong><\/h2>\n<p>Setup the &#8216;SCOM WebConsole settings for authentication&#8217;, beginning with a SSL certificate request for the server(s) in question.\u00a0 Add any SAN names\/aliases you want (if not load balanced).<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #ff0000;\">NOTE:<\/span><\/p>\n<p>Use CA Auto-Enrollment templates to simplify SSL request whenever an internal or external SSL certificate is required for your organization.\u00a0 Generally, external certificates require manual effort executing the certreq script.<\/p>\n<p>&nbsp;<\/p>\n<p>Sample SSL certificate<\/p>\n<figure id=\"attachment_19434\" aria-describedby=\"caption-attachment-19434\" style=\"width: 865px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateDetails2.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19434\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateDetails2.jpg\" alt=\"SCOM Web Console SSL Cert details\" width=\"865\" height=\"592\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateDetails2.jpg 865w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateDetails2-300x205.jpg 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateDetails2-768x526.jpg 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-19434\" class=\"wp-caption-text\">SCOM Web Console SSL Cert details<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<h3><strong><span style=\"color: #3366ff;\">Less typing means less typos<\/span><\/strong><\/h3>\n<p><span style=\"color: #3366ff;\">Below <\/span>SSL certificate example with any SAN names\/aliases (if not load balanced).\u00a0 Simplify the SCOM web console link to <span style=\"color: #3366ff;\">https:\/\/SCOM\/<\/span> versus <span style=\"color: #3366ff;\">https:\/\/SCOMSERVERName\/OperationsManager <\/span><\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_19436\" aria-describedby=\"caption-attachment-19436\" style=\"width: 598px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateSAN-Details-1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19436\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateSAN-Details-1.jpg\" alt=\"IIS manager server certificates with SAN DNSName aliases included.\" width=\"598\" height=\"504\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateSAN-Details-1.jpg 598w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISMgrCertificateSAN-Details-1-300x253.jpg 300w\" sizes=\"auto, (max-width: 598px) 85vw, 598px\" \/><\/a><figcaption id=\"caption-attachment-19436\" class=\"wp-caption-text\">IIS manager server certificates with SAN DNSName aliases included.<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1><strong>Part 2 &#8211; Add authentication Smart Card in IIS<\/strong><\/h1>\n<p>Next! &#8211; I will set up SmartCard role in &#8216;SCOM WebConsole settings for authentication&#8217;.\u00a0 Additionally, review the Learn.microsoft.com site for IIS <a href=\"https:\/\/learn.microsoft.com\/en-us\/iis\/configuration\/system.webserver\/security\/authentication\/iisclientcertificatemappingauthentication\/\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<h2>Compatibility<\/h2>\n<table width=\"663\">\n<thead>\n<tr>\n<td><strong>Version<\/strong><\/td>\n<td><strong>Notes<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>IIS 10.0<\/td>\n<td>The\u00a0&lt;iisClientCertificateMappingAuthentication&gt;\u00a0element was not modified in IIS 10.0.<\/td>\n<\/tr>\n<tr>\n<td>IIS 8.5<\/td>\n<td>The\u00a0&lt;iisClientCertificateMappingAuthentication&gt;\u00a0element was not modified in IIS 8.5.<\/td>\n<\/tr>\n<tr>\n<td>IIS 8.0<\/td>\n<td>The\u00a0&lt;iisClientCertificateMappingAuthentication&gt;\u00a0element was not modified in IIS 8.0.<\/td>\n<\/tr>\n<tr>\n<td>IIS 7.5<\/td>\n<td>The\u00a0&lt;iisClientCertificateMappingAuthentication&gt;\u00a0element was not modified in IIS 7.5.<\/td>\n<\/tr>\n<tr>\n<td>IIS 7.0<\/td>\n<td>The\u00a0&lt;iisClientCertificateMappingAuthentication&gt;\u00a0element of the\u00a0&lt;authentication&gt;\u00a0element was introduced in IIS 7.0.<\/td>\n<\/tr>\n<tr>\n<td>IIS 6.0<\/td>\n<td>The\u00a0&lt;iisClientCertificateMappingAuthentication&gt;\u00a0element replaces the IIS 6.0\u00a0<strong>IIsCertMapper<\/strong>\u00a0metabase object.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Add the Client Certificate feature for the SCOM Web Console<\/strong><\/h2>\n<p>Let&#8217;s add SmartCard authentication capability.<\/p>\n<p>&nbsp;<\/p>\n<p>Open Server manager &gt;<\/p>\n<figure id=\"attachment_19443\" aria-describedby=\"caption-attachment-19443\" style=\"width: 359px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19443\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png.jpg\" alt=\"Open Server manager\" width=\"359\" height=\"256\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png.jpg 359w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png-300x214.jpg 300w\" sizes=\"auto, (max-width: 359px) 85vw, 359px\" \/><\/a><figcaption id=\"caption-attachment-19443\" class=\"wp-caption-text\">Open Server manager<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Click on Manage &gt; Add roles\/features (top right)<\/p>\n<figure id=\"attachment_19444\" aria-describedby=\"caption-attachment-19444\" style=\"width: 377px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Manage-Top-Right.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19444\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Manage-Top-Right.jpg\" alt=\"Scroll to the top right, and click on Manage, then 'Add Roles or features'\" width=\"377\" height=\"260\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Manage-Top-Right.jpg 377w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Manage-Top-Right-300x207.jpg 300w\" sizes=\"auto, (max-width: 377px) 85vw, 377px\" \/><\/a><figcaption id=\"caption-attachment-19444\" class=\"wp-caption-text\">Scroll to the top right, and click on Manage, then &#8216;Add Roles or features&#8217;<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Click Next twice to get to the Server Roles<\/p>\n<p><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Role-Based-installation.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-19447\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Role-Based-installation.jpg\" alt=\"\" width=\"785\" height=\"560\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Role-Based-installation.jpg 785w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Role-Based-installation-300x214.jpg 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Role-Based-installation-768x548.jpg 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Server Manager &gt; Server Roles tab output<\/p>\n<figure id=\"attachment_19445\" aria-describedby=\"caption-attachment-19445\" style=\"width: 579px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19445\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles.jpg\" alt=\"Server Manager &gt; Server Roles\" width=\"579\" height=\"562\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles.jpg 579w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles-300x291.jpg 300w\" sizes=\"auto, (max-width: 579px) 85vw, 579px\" \/><\/a><figcaption id=\"caption-attachment-19445\" class=\"wp-caption-text\">Server Manager &gt; Server Roles<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Expand Web Server drop down<\/strong><\/p>\n<p>SCOM Web Console Authentication installing Client Certificate Mapping role<\/p>\n<p>Click the box to check &#8216;Client Certificate Mapping Authentication (Installed)&#8217; and click Next twice (2) [ two times ]<\/p>\n<p><a style=\"font-weight: bold; font-size: 0.8125rem; font-style: italic;\" href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles-Web-Server-Expanded.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19446\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles-Web-Server-Expanded.jpg\" alt=\"Expand Server Manager &gt; Web Server &gt; Client Certificate Mapping Authentication\" width=\"823\" height=\"560\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles-Web-Server-Expanded.jpg 823w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles-Web-Server-Expanded-300x204.jpg 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/IISManager-Server-Roles-Web-Server-Expanded-768x523.jpg 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>Expand Server Manager &gt; Web Server &gt; Client Certificate Mapping Authentication<\/p>\n<p>Click Install (mine is greyed out as it&#8217;s enabled)<\/p>\n<figure id=\"attachment_19441\" aria-describedby=\"caption-attachment-19441\" style=\"width: 785px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Features-Install.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19441\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Features-Install.jpg\" alt=\"Server Manager Features Install\" width=\"785\" height=\"561\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Features-Install.jpg 785w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Features-Install-300x214.jpg 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-Features-Install-768x549.jpg 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19441\" class=\"wp-caption-text\">Server Manager Features Install<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Allow install to complete, server will prompt if reboot required.<\/p>\n<p><span style=\"color: #ff0000;\"><strong>NOTE: Either way, reboot is required to apply new authentication method.<\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>Validate IISManager after reboot<\/p>\n<p>Click on Authentication to verify &#8216;Active Directory Client Certificate Authentication&#8217; is present and enabled.<\/p>\n<figure id=\"attachment_19440\" aria-describedby=\"caption-attachment-19440\" style=\"width: 775px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19440\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png\" alt=\"IIS Authentication with Client Certificate Authentication (after role installed)\" width=\"775\" height=\"334\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png 775w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-300x129.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-768x331.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19440\" class=\"wp-caption-text\">IIS Authentication with Client Certificate Authentication (after role installed)<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>After reboot, verify &#8216;AD Client Certificate authentication&#8217; method is enabled and visible.<\/p>\n<p>&nbsp;<\/p>\n<p>From IISManager &gt; Server &gt; Authentication &gt; Verify method is there and enabled<\/p>\n<figure id=\"attachment_19440\" aria-describedby=\"caption-attachment-19440\" style=\"width: 775px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-19440 size-full\" title=\"IIS Authentication with Client Certificate Authentication (after role installed)\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png\" alt=\"IIS Authentication with Client Certificate Authentication (after role installed)\" width=\"775\" height=\"334\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager.png 775w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-300x129.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/Server-Manager-768x331.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19440\" class=\"wp-caption-text\">IIS Authentication with Client Certificate Authentication (after role installed)<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Verify Default Web Site Authentication setup<\/strong><\/h3>\n<p>Verify Default Web site has Windows Authentication enabled.<\/p>\n<p>&nbsp;<\/p>\n<p>Navigation steps:<\/p>\n<p>IIS Manager &gt; Expand Sites &gt; Default Web Site &gt; Authentication<\/p>\n<p>Windows Authentication should be enabled, others disabled<\/p>\n<figure id=\"attachment_19528\" aria-describedby=\"caption-attachment-19528\" style=\"width: 721px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/DefaultWebSite-Authentication.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19528\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/DefaultWebSite-Authentication.png\" alt=\"Default Web Site Authentication showing Windows Authentication ONLY enabled\" width=\"721\" height=\"296\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/DefaultWebSite-Authentication.png 721w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/DefaultWebSite-Authentication-300x123.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-19528\" class=\"wp-caption-text\">Default Web Site Authentication showing Windows Authentication ONLY enabled<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Makes me think of the scene from Airplane with the AutoPilot blow-up, similarly parallel to engineer experiences talking about the SCOM Web Console configuration.\u00a0 I&#8217;m ready to dispel some myths to document securing the &#8216;SCOM Web Console for authentication&#8217; &nbsp; &nbsp; Quick outline Knowledge Articles to aid with &#8216;SCOM WebConsole settings for authentication&#8217; Configuring &hellip; <a href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;SCOM WebConsole settings for authentication&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,5,530,502],"tags":[631,632,613,611,635,600,342,601,633,634,630,445,536],"class_list":["post-19425","post","type-post","status-publish","format-standard","hentry","category-administration","category-best-practice","category-scom","category-security","tag-ad-delegation","tag-how-to-setup","tag-hsts","tag-iis","tag-iismanager","tag-kerberos","tag-scom","tag-scom-web-console","tag-smart-card","tag-smartcard","tag-ssl","tag-tls","tag-web-console"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SCOM WebConsole settings for authentication - Kevin Justin&#039;s Blog<\/title>\n<meta name=\"description\" content=\"SCOM WebConsole settings for authentication helps setup the web console with SSL certs, SmartCards, IIS, and AD delegation for Kerberos Auth\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SCOM WebConsole settings for authentication - Kevin Justin&#039;s Blog\" \/>\n<meta property=\"og:description\" content=\"SCOM WebConsole settings for authentication helps setup the web console with SSL certs, SmartCards, IIS, and AD delegation for Kerberos Auth\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/\" \/>\n<meta property=\"og:site_name\" content=\"Kevin Justin&#039;s Blog\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-17T19:20:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-07-24T12:11:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp\" \/>\n<meta name=\"author\" content=\"WordPress Administrator\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"WordPress Administrator\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/\"},\"author\":{\"name\":\"WordPress Administrator\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"headline\":\"SCOM WebConsole settings for authentication\",\"datePublished\":\"2023-07-17T19:20:37+00:00\",\"dateModified\":\"2023-07-24T12:11:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/\"},\"wordCount\":778,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/airplane_autopilot-2.webp\",\"keywords\":[\"AD Delegation\",\"how to setup\",\"HSTS\",\"IIS\",\"iisManager\",\"kerberos\",\"SCOM\",\"SCOM Web console\",\"smart card\",\"smartcard\",\"SSL\",\"tls\",\"web console\"],\"articleSection\":[\"Administration\",\"Best Practice\",\"SCOM\",\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/\",\"name\":\"SCOM WebConsole settings for authentication - Kevin Justin&#039;s Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/airplane_autopilot-2.webp\",\"datePublished\":\"2023-07-17T19:20:37+00:00\",\"dateModified\":\"2023-07-24T12:11:02+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"description\":\"SCOM WebConsole settings for authentication helps setup the web console with SSL certs, SmartCards, IIS, and AD delegation for Kerberos Auth\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/airplane_autopilot-2.webp\",\"contentUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/airplane_autopilot-2.webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2023\\\/07\\\/17\\\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SCOM WebConsole settings for authentication\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\",\"name\":\"Kevin Justin&#039;s Blog\",\"description\":\"Operational monitoring tools including System Center, Azure Monitor\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\",\"name\":\"WordPress Administrator\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"caption\":\"WordPress Administrator\"},\"sameAs\":[\"https:\\\/\\\/kevinjustin.com\"],\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/author\\\/wordpress_admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SCOM WebConsole settings for authentication - Kevin Justin&#039;s Blog","description":"SCOM WebConsole settings for authentication helps setup the web console with SSL certs, SmartCards, IIS, and AD delegation for Kerberos Auth","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/","og_locale":"en_US","og_type":"article","og_title":"SCOM WebConsole settings for authentication - Kevin Justin&#039;s Blog","og_description":"SCOM WebConsole settings for authentication helps setup the web console with SSL certs, SmartCards, IIS, and AD delegation for Kerberos Auth","og_url":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/","og_site_name":"Kevin Justin&#039;s Blog","article_published_time":"2023-07-17T19:20:37+00:00","article_modified_time":"2023-07-24T12:11:02+00:00","og_image":[{"url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp","type":"","width":"","height":""}],"author":"WordPress Administrator","twitter_card":"summary_large_image","twitter_misc":{"Written by":"WordPress Administrator","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#article","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/"},"author":{"name":"WordPress Administrator","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"headline":"SCOM WebConsole settings for authentication","datePublished":"2023-07-17T19:20:37+00:00","dateModified":"2023-07-24T12:11:02+00:00","mainEntityOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/"},"wordCount":778,"commentCount":0,"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp","keywords":["AD Delegation","how to setup","HSTS","IIS","iisManager","kerberos","SCOM","SCOM Web console","smart card","smartcard","SSL","tls","web console"],"articleSection":["Administration","Best Practice","SCOM","Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/","url":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/","name":"SCOM WebConsole settings for authentication - Kevin Justin&#039;s Blog","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#primaryimage"},"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp","datePublished":"2023-07-17T19:20:37+00:00","dateModified":"2023-07-24T12:11:02+00:00","author":{"@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"description":"SCOM WebConsole settings for authentication helps setup the web console with SSL certs, SmartCards, IIS, and AD delegation for Kerberos Auth","breadcrumb":{"@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#primaryimage","url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp","contentUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2023\/07\/airplane_autopilot-2.webp"},{"@type":"BreadcrumbList","@id":"https:\/\/kevinjustin.com\/blog\/2023\/07\/17\/scom-webconsole-settings-for-authentication-in-iis-configuration-and-leveraging-smart-cards-and-kerberos-auth-ssl-certs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kevinjustin.com\/blog\/"},{"@type":"ListItem","position":2,"name":"SCOM WebConsole settings for authentication"}]},{"@type":"WebSite","@id":"https:\/\/kevinjustin.com\/blog\/#website","url":"https:\/\/kevinjustin.com\/blog\/","name":"Kevin Justin&#039;s Blog","description":"Operational monitoring tools including System Center, Azure Monitor","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kevinjustin.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508","name":"WordPress Administrator","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","caption":"WordPress Administrator"},"sameAs":["https:\/\/kevinjustin.com"],"url":"https:\/\/kevinjustin.com\/blog\/author\/wordpress_admin\/"}]}},"_links":{"self":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19425","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/comments?post=19425"}],"version-history":[{"count":27,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19425\/revisions"}],"predecessor-version":[{"id":19536,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/19425\/revisions\/19536"}],"wp:attachment":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/media?parent=19425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/categories?post=19425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/tags?post=19425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}