Win2k Kerberos authentication through a web proxy
Ange
garbage at random.net.nz
Fri Jul 11 06:48:35 EDT 2003
Hi All,
Has anyone had any success using Windows 2000 kerberos authenticated
web applications through proxy servers? I have the following
situation
Web App Server: Win2k IIS set to authenticate requests via "Windows
Intergrated Authentication Only". The IIS Metabase has been set to
only allow Kerberos authentication, not NTLM.
Client: Internet Explorer 6.
Problem: The authentication works fine without a proxy, but if IE is
set to use a proxy it simply gives a HTTP 401 Unauthorised response.
If I get the proxy to add the HTTP header line ->
Proxy-Support: Session-Based-Authentication to each reponse I get
slightly further, in that I can get IE to respond to IIS's inital 401
with a new request with an Authorisation header. But then IIS
responds with another 401 and IE displays a "Page can not be
Displayed" error. I'm assuming that the Proxy-Support header is
really only intended for use with NTLM not Kerberos(?).
Any thoughts appreciated.
GAR
More information about the Kerberos
mailing list