public marks

PUBLIC MARKS from nhoizey with tags sso & ntlm

25 October 2007

NTLM HTTP Authentication is insecure by design

This write-up discusses a problem inherent to the situation of a connection-oriented authentication - authorization protocol (e.g. NTLM authentication) used with a proxy server that shares TCP connections among several clients

The NTLM Authentication Protocol

This article seeks to describe NTLM at an intermediate to advanced level of detail, suitable as a reference for implementors.

08 October 2007

SPNEGO - JA-SIG Wiki

This is the implementation of an AuthenticationHandler for SPNEGO supports. This Handler support both NTLM and Kerberos. NTLM is disabled by default.

cas-fr - Re: [cas-fr] SSO/CAS authentification sur plusieurs attributs

L'authentification X509 est opérationnelle (mais pas forcément très bien packagée), elle sera normalement dans CAS 3.0.6. On y trouvera également Radius et SPNEGO (donc NTLM).