Actually I wish we *could* fall back to Basic Auth instead of NTLM with
our IIS/Negotiate SSO implementation. Android currently does not
support NTLM, so there is no way to authenticate to our Remedy or
Sharepoint site. Any thoughts?
Brien
On 6/30/2011 1:58 PM, John Baker wrote:
Axton,
"We use basic authentication as a fail back in the event SPNEGO fails."
So you're missing SSO for a number of browsers that decide to send an NTLM
token, or an NTLM token buried in an SPNEGO token. That's quite a large piece
of functionality for large BMC clients who may have 20,000+ desktops with some
percentage refusing to do Kerberos for one reason or another. Only an hour ago
did I find myself telling a client that just because SSO Plugin was configured
to perform Kerbeors only, this wouldn't stop NTLM, and the logs confirmed as
much:
18:49:57,372 JSS DEBUG - Browser: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT
5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR
3.5.30729; .NET4.0C; .NET4.0E)
18:49:57,372 JSS DEBUG - Authorisation: Negotiate
TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAFASgKAAAADw==
18:49:57,372 JSS DEBUG - Detected Negotiate header with NTLM token: Negotiate
TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAFASgKAAAADw==
18:49:57,372 JSS DEBUG - Browser tried to pass an NTLM token but authentication
mode set to SPENGO/Kerberos only. Responding with unauthorized and a request
for SPNEGO/Kerberos.
18:49:57,372 JSS DEBUG - Sending WWW-Authenticate: Negotiate
18:49:57,372 JSS DEBUG - Returning HTTP Unauthorised
You will note that this browser decided to send a Negotioate (SPNEGO) header
with an NTLM token.
John
_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"