Fwd: NTLM vs Kerberos again

Sung Ho Jee jee.sung at ansaldo-signal.com.au
Thu Nov 3 00:03:33 EST 2005


Although the page below was written for mod_auth_gss_krb5, I believe the 
IE6 settings remain the same.

- Single Sign-on for your web applications with Apache and Kerberos
http://www.onlamp.com/pub/a/onlamp/2003/09/11/kerberos.html?page=1


Regards,

Sung.




Sergey Koulik <skoulik at gmail.com>
Sent by: kerberos-bounces at mit.edu
03/11/2005 12:22 PM

 
        To:     kerberos at mit.edu
        cc: 
        Subject:        Fwd: NTLM vs Kerberos again


Hi all,

I am forwarding the message to kerberos mail list, because my problem is
somehow related with kerberos. I am not sure anyone in the list is 
familiar
with apache module mod_auth_kerb I am talking about, but I hope anyone is
and he could help me.
My problem is that windows client (for exasmple MS IE) chooses to talk 
NTLM
when it receives WWW-Authentificate: Negotiate HTTP header. I know that IE
could talk Kerberos as well but for some reason it does not and I don't 
know
how to configure it to talk Kerberos.


---------- Forwarded message ----------
From: Sergey Koulik <skoulik at gmail.com>
Date: 03.11.2005 14:13
Subject: NTLM vs Kerberos again
To: modauthkerb-help at lists.sourceforge.net

Hi all,

I have examined mail archive. But I still don't see correct solution.
I want to force my windows clients to use Kerberos authentification 
instead
of NTLM when contacting web server kerberized with mod_auth_kerb. I use 
MIT
kerberos KDC located at lunux machine. My windows XP machine is not
connected to any domain.
Did anyone get it work?
Does anyone have step-by-step documentation how to configure MIT KDC,
mod_auth_kerb and clients to use Kerberos instead of NTLM?

--
Sincerely,
Sergey Koulik

--
Sincerely,
Sergey Koulik
________________________________________________
Kerberos mailing list           Kerberos at mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos




More information about the Kerberos mailing list