NTLM authentication to AD FS for non-IE browser without 'Extended Protection' switched off?

后端 未结 2 1091
面向向阳花
面向向阳花 2021-01-05 12:18

When using NTLM authentication to AD FS 2.0, from Google Chrome or Firefox 3.5+ running on Windows, then this results in a repeated sign-in dialog and finally sign-in failur

2条回答
  •  逝去的感伤
    2021-01-05 13:15

    According to

    • http://technet.microsoft.com/en-us/library/hh237448(v=ws.10).aspx
    • http://support.microsoft.com/kb/2461628/en-us

    this is a Chrome / Firefox / Safari implementation restriction if

    • the client is running Windows 7 and the server has ExtendedProtectionTokenCheck set to Require or Allow
    • the client is running Windows XP or Vista - without appropriate updates(!) and the server has ExtendedProtectionTokenCheck set to Require

    Maybe you can suppress Extended Protection on your clients with this: http://support.microsoft.com/kb/976918/en-us

    [...]
    To control the extended protection behavior, create the following registry subkey:
    Key Name: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA
    Value Name: SuppressExtendedProtection
    Type: DWORD

    For Windows clients that support channel binding that are failing to be authenticated by non-Windows Kerberos servers that do not handle the CBT correctly:
    1. Set the registry entry value to “0x01.”
    This will configure Kerberos not to emit CBT tokens for unpatched applications.
    2. If that does not resolve the problem, then set the registry entry value to “0x03.”
    This will configure Kerberos never to emit CBT tokens.

    [...]

提交回复
热议问题