<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://adopenstatic.com/cs/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IIS and Kerberos. Part 3 - A simple scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx</link><description>In Part 3 of this series we look at setting up Kerberos Authentication in the simplest possible scenario. If you missed Parts 1 ( What is Kerberos and how does it work ) and 2 ( Service Principal Names ) they may be worth reading first. In this scenario,</description><dc:language>en</dc:language><generator>CommunityServer 2.1 (Build: 60809.935)</generator><item><title>IIS and Kerberos. Part 4 - A simple delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#1284</link><pubDate>Sun, 28 Jan 2007 06:04:26 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:1284</guid><dc:creator>Ken Schaefer</dc:creator><description>&lt;p&gt;Delegation is a feature of Kerberos authentication that allows a server to obtain a Kerberos ticket on&lt;/p&gt;
</description></item><item><title>re: IIS and Kerberos. Part 3 - A simple scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#4199</link><pubDate>Wed, 25 Apr 2007 08:43:56 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:4199</guid><dc:creator>ralph emerson</dc:creator><description>&lt;p&gt;I actually managed to find your articles on Friday afternoon and they&lt;/p&gt;&lt;p&gt;explained everything to me quite nicely. Thank you &lt;/p&gt;</description></item><item><title>IIS and Kerberos Part 5 - Procotol Transition, Constrained Delegation, S4U2S and S4U2P</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#8463</link><pubDate>Thu, 19 Jul 2007 12:55:43 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:8463</guid><dc:creator>Ken Schaefer</dc:creator><description>&lt;p&gt;Protocol Transition is a new feature in Windows Server 2003. The Kerberos implementation in Windows Active&lt;/p&gt;
</description></item><item><title>re: IIS and Kerberos. Part 3 - A simple scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#8712</link><pubDate>Wed, 25 Jul 2007 14:57:27 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:8712</guid><dc:creator>Kedar</dc:creator><description>This post overall is pretty good, but I'd like to point out a minor correction that's led to confusion in the past.

Internet Explorer does not support the "WWW-Authenticate: Kerberos" header. It does support "WWW-Authenticate: Negotiate". The setting "Enable Integrated Windows Authentication" controls whether IE responds to the Negotiate headeror not.

This is particularly important because of one shortcoming of IE's authentication. Since the Negotiate SSPI supports both Kerberos and NTLM, IE has the choice when presented with the Negotiate header of which authentication protocol to use. If you've set up your server and client correctly to enable Kerberos auth, it will use Kerberos over Negotiate; if you haven't, you'll get NTLM over Negotiate.

The shortcoming is that there's no mechanism to restrict the Negotiate package to use only Kerberos, never NTLM.</description></item><item><title>re: IIS and Kerberos. Part 3 - A simple scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#8741</link><pubDate>Thu, 26 Jul 2007 03:44:49 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:8741</guid><dc:creator>Ken</dc:creator><description>&lt;p&gt;Hi Kedar,&lt;/p&gt;
&lt;p&gt;Thanks for your comments. I only included the WWW-Authenticate: Kerberos header because ISA Server 2006 returns this header (from memory - I will need to verify this). Perhaps there are other browsers out in the world other than IE that support such a header? :-)&lt;/p&gt;
</description></item><item><title>re: IIS and Kerberos. Part 3 - A simple scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#8760</link><pubDate>Thu, 26 Jul 2007 06:34:31 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:8760</guid><dc:creator>Kedar</dc:creator><description>Certainly there may be other browsers that support the actual Kerberos header (I don't know any offhand, but at least theoretically they could). I see that you've modified the post not to mention IE specifically with it. Thanks. I got asked a question about this at work that referenced this blog post, so I thought I'd comment here.

If my memory serves, ISA server doesn't do WWW-Authenticate: Kerberos, but instead Proxy-Authenticate: Kerberos. Furthermore, again if I remember correctly, that header is used for authentication between two proxies (not between a client and the proxy).</description></item><item><title>re: IIS and Kerberos. Part 3 - A simple scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#9035</link><pubDate>Wed, 01 Aug 2007 07:17:21 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:9035</guid><dc:creator>Ken</dc:creator><description>&lt;p&gt;Hi Kedar,&lt;/p&gt;
&lt;p&gt;I didn't modify my blog post - all I did was respond to your comment. Not sure what you think I may have been doing here :-) If I modify a post (other than spelling mistakes) I put some &amp;quot;Edit:&amp;quot; text in as a change log.&lt;/p&gt;
&lt;p&gt;In terms of ISA Server 2006, I have a packet capture here that shows it is definately sending back a WWW-Authenticate: Kerberos header.&lt;/p&gt;
&lt;p&gt;The three WWW-Authenticate headers that it is sending back in this packet capture are (in order):&lt;/p&gt;
&lt;p&gt;WWW-Authenticate: Negotiate/r/n&lt;/p&gt;
&lt;p&gt;WWW-Authenticate: Kerberos/r/n&lt;/p&gt;
&lt;p&gt;WWW-Authenticate: NTLM/r/n&lt;/p&gt;
&lt;p&gt;I am happy to send your the .cap file if you can send me your contact details. Use the Email link up the top of the page to send me your preferred contact address.&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;p&gt;Ken&lt;/p&gt;
</description></item><item><title>More from that 3 headed dog we know and love - Kerberos &amp;laquo; Jeftek&amp;#8217;s Weblog</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#15773</link><pubDate>Thu, 31 Jan 2008 06:25:39 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:15773</guid><dc:creator>More from that 3 headed dog we know and love - Kerberos « Jeftek’s Weblog</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://jeftek.wordpress.com/2007/09/06/more-from-that-3-headed-dog-we-know-and-love-kerberos/"&gt;http://jeftek.wordpress.com/2007/09/06/more-from-that-3-headed-dog-we-know-and-love-kerberos/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Kerberos przyjacielem mym</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#17877</link><pubDate>Fri, 11 Jul 2008 12:49:47 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:17877</guid><dc:creator>.neting in the free world</dc:creator><description>&lt;p&gt;Coraz częściej w pracy stykam się z koniecznością ustawienia autentykacji poprzez protok&amp;#243;ł Kerberos ,&lt;/p&gt;
</description></item><item><title>Kerberos przyjacielem twym</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#17881</link><pubDate>Fri, 11 Jul 2008 13:21:31 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:17881</guid><dc:creator>.neting in the free world</dc:creator><description>&lt;p&gt;Coraz częściej w pracy stykam się z koniecznością ustawienia autentykacji poprzez protok&amp;#243;ł Kerberos ,&lt;/p&gt;
</description></item><item><title>IIS, Kerberos and anonymous login error | keyongtech</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#20762</link><pubDate>Thu, 22 Jan 2009 06:12:57 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:20762</guid><dc:creator>IIS, Kerberos and anonymous login error | keyongtech</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.keyongtech.com/4369361-iis-kerberos-and-anonymous-login"&gt;http://www.keyongtech.com/4369361-iis-kerberos-and-anonymous-login&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>IIS and Kerberos Part 9 - Cross Forest Delegation scenario with UPN suffix routing</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#21176</link><pubDate>Thu, 26 Feb 2009 12:24:35 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:21176</guid><dc:creator>Ken Schaefer</dc:creator><description>&lt;p&gt;As an extension of the previous article on Cross Forest (or Cross Domain) Kerberos Authentication this&lt;/p&gt;
</description></item><item><title>Vidar's Musings ?? The mother lode for IIS, Kerberos and IWA information</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#21319</link><pubDate>Fri, 06 Mar 2009 09:54:48 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:21319</guid><dc:creator>Vidar's Musings ?? The mother lode for IIS, Kerberos and IWA information</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.kongsli.net/nblog/2009/03/06/the-mother-lode-for-iis-kerberos-and-iwa-information/"&gt;http://www.kongsli.net/nblog/2009/03/06/the-mother-lode-for-iis-kerberos-and-iwa-information/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Constrained Kerberos Delegation &amp;amp; BlueCoat ProxySG &amp;laquo; Dvas0004&amp;#039;s Blog</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2007/01/16/1054.aspx#26715</link><pubDate>Thu, 22 Jul 2010 07:37:43 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:26715</guid><dc:creator>Constrained Kerberos Delegation &amp; BlueCoat ProxySG « Dvas0004's Blog</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://dvas0004.wordpress.com/2010/07/22/constrained-kerberos-delegation-bluecoat-proxysg-2/"&gt;http://dvas0004.wordpress.com/2010/07/22/constrained-kerberos-delegation-bluecoat-proxysg-2/&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>