HTTP Digest Authentication Problems (K 3.2.3/Apache 2.0.50)

Karsten Künne kuenne at rentec.com
Mon Aug 23 17:19:29 BST 2004


On Saturday 21 August 2004 12:56, Stephen Hildrey wrote:
> On Sat, Aug 21, 2004 at 12:54:40PM -0400, Sean Lynch wrote:
> > When I go here,
> > http://www.marshall.edu/career-services/PTJ/ptjobsmain.asp, and click on
> > any of the Browse Part-Time Jobs links in the box, I get an instant error
> > message "Error: Access is Denied.".  With firefox it prompts for the
> > authentication.  I'm not sure if this is related to the previous example,
> > but wanted to point it out none the less.
>
> That page is sending WWW-Authenticate: Negotiate and
> WWW-Authenticate: NTLM headers, suggesting that it's only going to work
> if your client supports Negotiate or NTLM authentication (I think
> they're both Windows domain-related).
>
> This may be of interest:
> http://lists.kde.org/?l=kfm-devel&m=108935379630563&w=2
>

I don't think this site is going to work with the current "Negotiate" 
implementation in the http kioslave. I have no way of testing against an IIS 
here  so I only made sure that it works with Apache's mod_auth_kerb and with 
GSSAPI. I believe in order to support IIS and SPNEGO some changes are 
required and I'm not sure whether it's possible to make it work at all on a 
non-MS system as this server apparently expects some kind of NTLM 
authentication and just offers "Negotiate" because this is the new 
standardized way of doing it whereas the old "NTLM" method is proprietary.


Karsten.
-- 
/earth is 98% full ... please delete anyone you can.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <https://mail.kde.org/mailman/private/kfm-devel/attachments/20040823/e95f567d/attachment.sig>


More information about the kfm-devel mailing list