<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3 Domains with NTLMSSP Configuration in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002001#M320</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Josh, &lt;BR /&gt;&lt;BR /&gt;   Yup..i was able to make it work.....thanks..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jul 2008 18:20:16 GMT</pubDate>
    <dc:creator>angfeglandagan</dc:creator>
    <dc:date>2008-07-25T18:20:16Z</dc:date>
    <item>
      <title>3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1001999#M318</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;  I successfully configured NTLMSSP using a single domain (abc.com).&lt;BR /&gt;&lt;BR /&gt;   Now, i want to add another 2 domains , both domains are trusted in the same forest...so theres no problem with the query via directory.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;   Is this possible?&lt;BR /&gt;   I can just add another NTLM REALM for those domain..&lt;BR /&gt;&lt;BR /&gt;hope someone can enlighten me.&lt;BR /&gt;&lt;BR /&gt;kira&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2008 16:31:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1001999#M318</guid>
      <dc:creator>angfeglandagan</dc:creator>
      <dc:date>2008-07-18T16:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: 3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002000#M319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kira,&lt;BR /&gt;&lt;BR /&gt;You can only configure a single NTLM realm in the WSA, but as long as there are trusts in your AD forest, users in other domains should still be able to authenticate correctly. &lt;BR /&gt;&lt;BR /&gt;Example: &lt;BR /&gt;&lt;BR /&gt;WSA is configured to join the domain "COMPANY". The COMPANY domain has two way trusts configure with the domain "SECONDARY".&lt;BR /&gt;&lt;BR /&gt;When a user in the SECONDARY domain authenticates to the WSA, it will sends the appropriate credentials (SECONDARY\user1). The WSA will pass these credentials to the AD server we have joined (in the COMPANY domain). &lt;BR /&gt;&lt;BR /&gt;Since the COMPANY AD server trusts the SECONDARY domain, it will contact the other domain controllers and authenticate the client. &lt;BR /&gt;&lt;BR /&gt;You can authenticate to any number of domains as long as the AD server / domain we're joining has the trust setup and is able to authenticate other domain's users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 22:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002000#M319</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-07-18T22:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: 3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002001#M320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Josh, &lt;BR /&gt;&lt;BR /&gt;   Yup..i was able to make it work.....thanks..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2008 18:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002001#M320</guid>
      <dc:creator>angfeglandagan</dc:creator>
      <dc:date>2008-07-25T18:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: 3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002002#M321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great! Everynow and then I'm right about something  :wink:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2008 23:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002002#M321</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-07-25T23:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: 3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002003#M322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem now would be a single sign on using the 3 domains...unfortunately..i can only create 1 ntlmssp....&lt;BR /&gt;&lt;BR /&gt;How do you guys manage to configure SSO with 3 domains..&lt;BR /&gt;&lt;BR /&gt;anyone? &lt;BR /&gt;&lt;BR /&gt;thanks,&lt;BR /&gt;&lt;BR /&gt;kira&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Aug 2008 18:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002003#M322</guid>
      <dc:creator>angfeglandagan</dc:creator>
      <dc:date>2008-08-02T18:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: 3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002004#M323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My understanding is that SSO will work with any of the domains that have 2 way trust setup. You will still have to setup the environment for SSO, such as setting the "Redirect Hostname" to a single word hostname. &lt;BR /&gt;&lt;BR /&gt;You may have to add a trust variable in the Firefox browser.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Aug 2008 23:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002004#M323</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-08-04T23:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: 3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002005#M324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Just curious about LDAP authentcation issue in WSA. If the two domain did not trust each other. The authentication will it works or not? &lt;BR /&gt;&lt;BR /&gt;How to resolve this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2008 22:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002005#M324</guid>
      <dc:creator>cwling2008</dc:creator>
      <dc:date>2008-08-19T22:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: 3 Domains with NTLMSSP Configuration</title>
      <link>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002006#M325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't believe the trusts will have any effect on LDAP. &lt;BR /&gt;&lt;BR /&gt;It's possible that one AD server may use an LDAP referral to query the appropriate AD server (for the other domain you are attempting to auth with), but I'm not sure that is how it works.&lt;BR /&gt;&lt;BR /&gt;Any one else have concrete information? I'm curious as to why you would want to use LDAP with a multi domain environment. NTLM is better in every way (password from the client is secure, Kerberos between the WSA and DC, Single Sign On, Ease with authenticating to multiple domains, so forth.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 23:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/3-domains-with-ntlmssp-configuration/m-p/1002006#M325</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-08-20T23:00:05Z</dc:date>
    </item>
  </channel>
</rss>

