[24885] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Fwd: NTLM vs Kerberos again

daemon@ATHENA.MIT.EDU (Sergey Koulik)
Thu Nov 3 00:21:53 2005

Message-ID: <70b7a5810511022121m67020edbi@mail.gmail.com>
Date: Thu, 3 Nov 2005 15:21:12 +1000
From: Sergey Koulik <skoulik@gmail.com>
To: Sung Ho Jee <jee.sung@ansaldo-signal.com.au>
In-Reply-To: <OF56A8CE4A.BEE490E1-ON482570AE.001B7569-482570AE.001BA777@wa>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Disposition: inline
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit

Thank you for your reply. But my problem is that I do not either use Active
Directory or connected to microsoft domain. What I want is to made browser
send kerberos tickets to MIT KDC and not fallback to NTLM authentification.

2005/11/3, Sung Ho Jee <jee.sung@ansaldo-signal.com.au>:
>
>
> Although the page below was written for mod_auth_gss_krb5, I believe the
> IE6 settings remain the same.
>
> - Single Sign-on for your web applications with Apache and Kerberos
> http://www.onlamp.com/pub/a/onlamp/2003/09/11/kerberos.html?page=1
>
>
> Regards,
>
> Sung.
>
>
>
> *Sergey Koulik <skoulik@gmail.com>*
> Sent by: kerberos-bounces@mit.edu
>
> 03/11/2005 12:22 PM
>
> To: kerberos@mit.edu
> cc:
> Subject: Fwd: NTLM vs Kerberos again
>
>
> Hi all,
>
> I am forwarding the message to kerberos mail list, because my problem is
> somehow related with kerberos. I am not sure anyone in the list is
> familiar
> with apache module mod_auth_kerb I am talking about, but I hope anyone is
> and he could help me.
> My problem is that windows client (for exasmple MS IE) chooses to talk
> NTLM
> when it receives WWW-Authentificate: Negotiate HTTP header. I know that IE
> could talk Kerberos as well but for some reason it does not and I don't
> know
> how to configure it to talk Kerberos.
>
>
> ---------- Forwarded message ----------
> From: Sergey Koulik <skoulik@gmail.com>
> Date: 03.11.2005 14:13
> Subject: NTLM vs Kerberos again
> To: modauthkerb-help@lists.sourceforge.net
>
> Hi all,
>
> I have examined mail archive. But I still don't see correct solution.
> I want to force my windows clients to use Kerberos authentification
> instead
> of NTLM when contacting web server kerberized with mod_auth_kerb. I use
> MIT
> kerberos KDC located at lunux machine. My windows XP machine is not
> connected to any domain.
> Did anyone get it work?
> Does anyone have step-by-step documentation how to configure MIT KDC,
> mod_auth_kerb and clients to use Kerberos instead of NTLM?
>
> --
> Sincerely,
> Sergey Koulik
>
> --
> Sincerely,
> Sergey Koulik
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>
>
>


--
Sincerely,
Sergey Koulik
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post