Re: NTLM over the Internet

From: [ MVP ] Sukesh Ashok Kumar (sukesh_at_v4cnet.com)
Date: 11/19/03


Date: Thu, 20 Nov 2003 01:56:24 +0530

hi Marshall,

Answer to 2nd question, If you are using SSL, there is no reason to use
NTLM.

Rgds
Sukesh Ashok Kumar

"Marshall" <mashburnwest@yahoo.com> wrote in message
news:BC737A37-8FC0-4373-9DB9-7F1204346C86@microsoft.com...
> I've read in a couple of Microsoft articles that ntlm should not be used
over the internet for authenticating users. The reason given is that ntlm
relies on 'implicit end-to-end state' so that proxies positioned between the
client and web server can cause unexpected problems (most notably 'Access
Denied'). I have 2 questions related to this:
> 1. Does anyone have any further technical details on exactly what
situations would cause problems? I've setup a test server using ntlm over
the internet, tested from multiple locations (trying to access server
through a different path) but cannot produce the error. What proxy
configuration would cause this?
> 2. If SSL is being used, can ntlm be reliably used (i.e. must proxies
follow different rules for SSL so that 'implicit end-to-end state' would be
accomplished)?
>
> Thanks for any help,
>
> Marshall



Relevant Pages

  • RE: Load balancing with NTLM or Basic authentication.
    ... Microsoft SQL Server Support Professional ... Load balancing with NTLM or Basic authentication. ... >What else would we loss by switching from NTLM to Basic over SSL? ...
    (microsoft.public.inetserver.iis.security)
  • Most users cant connect to our SSL-- help!
    ... I've included all relevant SSL settings from our ... Subject: Large percentage of customers cannot connect to https: ... server, which then grinds indefinitely. ... "2) Your secure order form is not working. ...
    (comp.security.misc)
  • Most users cant connect to our SSL-- help!
    ... I've included all relevant SSL settings from our ... Subject: Large percentage of customers cannot connect to https: ... server, which then grinds indefinitely. ... "2) Your secure order form is not working. ...
    (comp.security.ssh)
  • Most users cant connect to our SSL-- help!
    ... I've included all relevant SSL settings from our ... Subject: Large percentage of customers cannot connect to https: ... server, which then grinds indefinitely. ... "2) Your secure order form is not working. ...
    (comp.security.unix)
  • Re: Antw: Re: LDAP Authentication Problem
    ... TLSv1 und wird auf einen SSL Client Hello Request mit TLSv1 nicht ... antworten anstatt ein SSLv3 Server Hello. ... the LDAP PAM module and the shadow package. ...
    (de.comp.sys.novell)