Integrated Windows Authentication

[Previous] [Next]

Available in IIS 4?

Yes, but only NTLM was supported; Kerberos is not supported.

What privileges are required?

The Logon Across The Network logon right is required; also, the account must not be marked as sensitive in Active Directory.

Supports delegation?

Yes, if Kerberos is chosen rather than NTLM and the environment is configured to support delegation. No, if NTLM is used.

Delegation capabilities diagram (when Kerberos is used)

click to view at full size

Delegation capabilities diagram (when NTLM is used)

click to view at full size

Requires Active Directory?

If Active Directory is not installed, NTLM will be used. Refer to Chapter 5 for details about what's required for Kerberos to work.

Browser support

All versions of Internet Explorer after version 1 support NTLM. Internet Explorer 5 and later support NTLM and Kerberos.

Works through proxies and firewalls?

Partially. The protocol will work through firewalls so long as the appropriate ports are opened. However, this is discouraged because of the security ramifications of opening specialized authentication ports.

Other notes

Integrated Windows authentication uses a negotiation mechanism to determine the authentication mechanism, NTLM or Kerberos, depending on the capabilities of the Web browser and client operating system as well as the Web server and server operating system.



Designing Secure Web-Based Applications for Microsoft Windows 2000 with CDROM
Designing Secure Web-Based Applications for Microsoft Windows 2000 with CDROM
ISBN: N/A
EAN: N/A
Year: 1999
Pages: 138

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net