Article delegate-en/3995 of [1-5169] on the server localhost:119
  upper oldest olders older1 this newer1 newers latest
search
[Top/Up] [oldest] - [Older+chunk] - [Newer+chunk] - [newest + Check]
[Reference:<_A3994@delegate-en.ML_>]
Newsgroups: mail-lists.delegate-en

[DeleGate-En] Re: Windows Integrated Authentication
06 Jun 2008 08:43:53 GMT feedback@delegate.org (Yutaka Sato)
The DeleGate Project


Hi,

In message <_A3994@delegate-en.ML_> on 06/03/08(21:29:44)
you "Nagel, Willy" <ptihqbdyi-vhnmk2gsygtr.ml@ml.delegate.org> wrote:
 |I have setup a server with IIS 6.0 and enabled Integrated Windows
 |Authentication.
 |
 |I have setup delegate with the following config file:
 |
 |-Pip_to_listen_on:443 
 |ADMIN=admin@address.. 
 |DGROOT="/DeleGate/" 
 |SERVER=https 
 |DELAY=reject:0,unknown:0
 |HTTPCONF=methods:*
 |STLS="fsv,fcl,sslway -cert lib/cert.crt -key lib/cert.key"
 |MOUNT="/* https://mounted_ip/* via=ip_address"
 |REACHABLE=ip_address:443
 |RELIABLE="*"
 |
 |This configuration works with all sites, except with sites that have
 |Integrated Windows Authentication.
 |When I use the same configuration with Basic Authentication, this does
 |work.
 |
 |Usually, when enabling both Integrated Windows Authentication and Basic
 |Authentication on a site in IIS and Integrated Windows Authentication
 |doesn't apply, you're authenticated using Basic Authentication.
 |
 |Is this at all possible with Delegate? Or do you have any suggestions?

Conveying NTLM authentication over HTTP seems be defined in RFC4559 and
the RFC seems requiring proxies to add a magic field

  Proxy-support: Session-Based-Authentication

to the 401 response message asking NTLM Negotiate from the server.
You can add the field for all response messages with an option like folows:

  HTTPCONF="add-rhead:Proxy-support:Session-Based-Authentication"

If this workaround works in your case, I'll support it more neatly in DeleGate.

Cheers,
Yutaka
--
  9 9   Yutaka Sato <y.sato@delegate.org> http://delegate.org/y.sato/
 ( ~ )  National Institute of Advanced Industrial Science and Technology
_<   >_ 1-1-4 Umezono, Tsukuba, Ibaraki, 305-8568 Japan
Do the more with the less -- B. Fuller

  admin search upper oldest olders older1 this newer1 newers latest
[Top/Up] [oldest] - [Older+chunk] - [Newer+chunk] - [newest + Check]
@_@V