<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ldap Authentication Transparency in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ldap-authentication-transparency/m-p/211422#M2769</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, basically the answer is Internet Explorer supports the use of pass through NTLM from the base operating system (XP/2000), no such method exists for LDAP (ADS) as it relies on the Kerberos tokens being issues and recognised by the the proxy device which the CE's currently don't support. You can do LDAP/ADS authentication if your using websense on box by relying on the Websense LDAP/ADS authentication which does work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a fare amount of digging on this before I recieved confirmation that its not supported. The other potential gotcha is 2003 Server uses NTLMv2 by default if you plan on using that root. In the end my customer was happy to stick with the popup box as a potential security measure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Mar 2004 14:28:27 GMT</pubDate>
    <dc:creator>mark.duffy</dc:creator>
    <dc:date>2004-03-31T14:28:27Z</dc:date>
    <item>
      <title>ldap Authentication Transparency</title>
      <link>https://community.cisco.com/t5/application-networking/ldap-authentication-transparency/m-p/211421#M2768</link>
      <description>&lt;P&gt;Hi does anyone know if the content engine allows users to transparently authenticate using ldap through the browser.  The NTLM method states that you can log onto a domain and web requests willbe authenticated without popup windows.  Can you get the same to work with LDAP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have LDAP working at the moment as it authenticates users all the time.  But I would like it only to popup a window if a user has not logged onto the domain.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2004 12:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ldap-authentication-transparency/m-p/211421#M2768</guid>
      <dc:creator>adrian.watmough</dc:creator>
      <dc:date>2004-03-29T12:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: ldap Authentication Transparency</title>
      <link>https://community.cisco.com/t5/application-networking/ldap-authentication-transparency/m-p/211422#M2769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, basically the answer is Internet Explorer supports the use of pass through NTLM from the base operating system (XP/2000), no such method exists for LDAP (ADS) as it relies on the Kerberos tokens being issues and recognised by the the proxy device which the CE's currently don't support. You can do LDAP/ADS authentication if your using websense on box by relying on the Websense LDAP/ADS authentication which does work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a fare amount of digging on this before I recieved confirmation that its not supported. The other potential gotcha is 2003 Server uses NTLMv2 by default if you plan on using that root. In the end my customer was happy to stick with the popup box as a potential security measure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Mar 2004 14:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ldap-authentication-transparency/m-p/211422#M2769</guid>
      <dc:creator>mark.duffy</dc:creator>
      <dc:date>2004-03-31T14:28:27Z</dc:date>
    </item>
  </channel>
</rss>

