cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
507
Views
0
Helpful
1
Replies

ldap Authentication Transparency

adrian.watmough
Level 1
Level 1

Hi does anyone know if the content engine allows users to transparently authenticate using ldap through the browser. The NTLM method states that you can log onto a domain and web requests willbe authenticated without popup windows. Can you get the same to work with LDAP?

I have LDAP working at the moment as it authenticates users all the time. But I would like it only to popup a window if a user has not logged onto the domain.

1 Reply 1

mark.duffy
Level 1
Level 1

No, basically the answer is Internet Explorer supports the use of pass through NTLM from the base operating system (XP/2000), no such method exists for LDAP (ADS) as it relies on the Kerberos tokens being issues and recognised by the the proxy device which the CE's currently don't support. You can do LDAP/ADS authentication if your using websense on box by relying on the Websense LDAP/ADS authentication which does work.

I did a fare amount of digging on this before I recieved confirmation that its not supported. The other potential gotcha is 2003 Server uses NTLMv2 by default if you plan on using that root. In the end my customer was happy to stick with the popup box as a potential security measure.

Mark

Review Cisco Networking for a $25 gift card