Re: Integrated Windows Authentication



Yes you are correct. I found it here as well that Mozilla supports
NTLM:
http://www.mozilla.org/status/2003-11-24.html

On 30 Jan, 11:20, Dominick Baier
<dbaier@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Basic Auth sends passwords in clear text, integrated sends them hashed (this
is only slightly better).

In any case you need SSL to protect the credentials on the wire.

Integrated auth is really 2 protocols - NTLM and Kerberos.

Some browsers like FF support NTLM - thats probably the reason why you could
log on...

-----
Dominick Baier (http://www.leastprivilege.com)



I have read somewhere that Basic Authentication should be avoided
because it sends passwords in clear text and that Integrated Windows
Authentication only works with Internet Explorer on a Windows
computer. I have a website in IIS with only Integrated Windows
Authentication enabled and not anonymous or Basic Authentication
enabled. I have installed Mozilla on the computed and could log on
with no problem. I then booted from a Knoppix Live CD on another
computer and again logged on using Firefox with no problem. I then did
a TCP/IP trace of the network traffic while I logged onto the site in
Knoppix and could not find any password. Why is this?- Dölj citerad text -- Visa citerad text -

.



Relevant Pages

  • RE: ADS Password Storage Protection
    ... In Windows it is LM or NT (sometimes called NTLM) hashes. ... NTLMv2 refers to the authenication protocol that exchanges the hash ... between the client and server authentication database. ...
    (Security-Basics)
  • Re: Integrated Windows Authentication Timeout?
    ... Is it possible that a different host name is being used for one of the subsequent requests that would break Kerberos auth? ... If you have "Negotiate" authentication set in the metabase, then this can still negotiate down to NTLM if for some reason the protocol thinks that Kerberos is unavailable. ... server. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: HttpWebRequest over Https Via Proxy Fails using NTLM
    ... The proxy authentication header returns Basic, NTLM, and Negotiate. ... A network trace shows that the https request handshake is as follows: ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Outlook 2000 issue with EXCH 2003
    ... It is related to DNS, the GC utilize DNS to find NTLM ... we have tested outlook 2k3 with NTLM only ... the LAN MAN authentication set to ...
    (microsoft.public.exchange.admin)
  • Re: Event log shows NTLM not Kerberos
    ... it needs those SIDs, which is what authentication gives. ... Authentication Package: NTLM ... Authentication Package NTLM not Kerberos? ...
    (microsoft.public.security)